Germany’s NIS2 Implementation Act comes into force today, amending the BSI Act and extending cyber security obligations to many more organisations.
Key points
- Applies generally to organisations with 50 or more employees or €10m or more turnover in listed sectors.
- Entities must register with the Federal Office for Information Security (BSI).
- Risk management measures and incident reporting duties apply.
- Management bodies are responsible for approving and overseeing cyber security measures.
UK organisations with German subsidiaries, or supplying in-scope German entities, should confirm whether they are covered and prepare for supply chain security requests.
Source: NIS2UmsuCG, BGBl. 2025 I Nr. 301 (Bundesgesetzblatt)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.