Skip to main content
The pilot is open — free for the first cohort. V1 lists on the Microsoft Marketplace Q4 2026.→ Apply
Back to the NIS2 overview
NIS2 · Germany

NIS2 in Germany — transposition status and what’s changed

Germany transposed NIS2 via the NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), which entered into force on 6 December 2025 with no transition period — affected entities had to comply immediately. The law amends the BSI Act (BSIG) and brings cybersecurity governance to a board-level statutory issue. The BSI (Bundesamt für Sicherheit in der Informationstechnik) is the supervisory authority and operates the entity-registration portal that opened on 6 January 2026; the registration deadline passed on 6 March 2026 with only around a third of expected entities registered. Coverage expands the German regulated population from approximately 4,500 entities to around 30,000 — a significant jump that drives mid-market German entities into scope alongside their suppliers.

National competent authority
BSI — NIS-2

Authoritative source for Germany-specific NIS2 guidance, registration, and incident reporting.

1.0 / What German entities face under NIS2

The NIS2UmsuCG expands the German regulated population from roughly 4,500 entities to around 30,000 — one of the largest single-country jumps in the EU. The delta is almost entirely mid-market: the Mittelstand machinery makers, component suppliers, logistics operators, chemical processors, and regional service providers that anchor German industry, most of whom have never operated under BSI supervision before. German law sorts them into three categories — KRITIS operators, particularly important entities (besonders wichtige Einrichtungen, the essential tier), and important entities (wichtige Einrichtungen) — with obligations scaled by category.

Two facts define the current moment. There was no transition period: obligations applied from 6 December 2025, the day the law took effect. And the registration deadline passed on 6 March 2026 with only around a third of the expected 30,000 entities registered — meaning most of the newly regulated population starts 2026 already behind, working out scope, registration, and supplier evidence in the same quarters their customers are asking them for the same things.

2.0 / The NIS2UmsuCG, the BSIG, and what BSI is asking for

The NIS2UmsuCG works by substantially revising the BSI Act (BSIG) rather than creating a standalone statute. The pre-existing KRITIS regime continues for critical-infrastructure operators — with its established proof obligations — while the two new NIS2 categories carry the directive-shaped duties: risk-management measures across the Article 21 areas, registration with BSI, and incident reporting on the 24-hour / 72-hour / one-month ladder. Management accountability is explicit: the law makes cybersecurity oversight a statutory duty of the management body, including training — board-level attention is a legal requirement, not a best practice.

BSI is the operational counterpart: the registration portal (open since 6 January 2026), the incident-reporting channel, and a steady stream of orientation guidance including a self-check for whether your organisation is in scope. German supervisory culture is document-heavy in the IT-Grundschutz tradition — expect evidence requests that favour structured, attributable, dated records over narrative assurances. The binding texts and guidance are German; English summaries are orientation, not authority.

3.0 / Supplier-risk patterns particular to Germany

German supply chains cascade. OEMs and Tier 1s push evidence obligations down through machinery, automotive, and chemical supply networks that reach deep into Czechia, Slovakia, Poland, and Austria — so a German buyer’s supplier inventory is heavily cross-border, and the suppliers inheriting German NIS2 expectations are often working to their own, differently timed national transpositions. Germany’s existing assurance culture cuts both ways: TISAX and ISO 27001 are widespread, which raises the evidence baseline, but a supplier’s certificate is evidence about them — it is not your documented assessment of them, and the NIS2UmsuCG expects the latter.

The registration shortfall is also a supplier-maturity signal: if two-thirds of regulated German entities had not registered by the deadline, the suppliers below them are further behind still. The pattern a buyer meets in a first structured evidence collection is predictable: the large cloud and ICT providers answer quickly with deep sub-processor stacks you must then actually read, while the specialised Mittelstand suppliers that carry the real operational dependency often have nothing prepared and need months of patient, structured chasing.

4.0 / How Vittnor fits the German market

Vittnor — Supply Chain Assurance for the mid-market — produces by default the evidence shape German supervision favours: structured, dated, reviewer-attributed, exportable. One record per supplier, current evidence with provenance, a decision trace that survives staff turnover, machine-readable exports. Hosting matches German data-locality expectations: Microsoft Azure, EU regions only, with customer evidence never leaving the EU. Evidence templates are anchored to the directive and ENISA’s technical implementation guidance rather than to any single national methodology.

For the cross-border chains German buyers actually run, the aim is one supplier file that supports both the German buyer’s questions and the supplier’s own Czech or Slovak obligations — cross-buyer routing is planned for later versions. For mid-market German entities without a dedicated CISO, the one-off NIS2 Supplier Exposure Assessment maps the supplier-risk landscape first, and the platform then carries the ongoing programme the NIS2UmsuCG expects.

5.0 / Next step

Where are you with NIS2 supplier work in Germany?

Two ways to find out fast — a five-minute readiness check, or a practitioner-walked exposure picture in two to three weeks.