Ger­man NIS2 Imple­men­ta­ti­on Act announced

What Com­pa­nies Need to Know and Do Now

Both cham­bers of the Ger­man legis­la­tu­re – the Bun­des­tag (lower house) and Bun­des­rat (upper house repre­sen­ting the fede­ral sta­tes) – have adopted the act imple­men­ting the EU NIS2 Direc­ti­ve. Its core ele­ment is a com­pre­hen­si­ve revi­si­on of the Ger­man Cyber­se­cu­ri­ty Act (“BSI Act”). The law has been in force sin­ce 6 Decem­ber. No tran­si­ti­on peri­ods are planned.

What is the Ger­man NIS2 Imple­men­ta­ti­on Act?

The NIS2 Imple­men­ta­ti­on Act is Germany’s natio­nal law trans­po­sing the EU NIS2 Direc­ti­ve , which sets man­da­to­ry cyber­se­cu­ri­ty requi­re­ments for “essen­ti­al” and “important” enti­ties across 18 sec­tors such as health­ca­re, mobi­li­ty, ener­gy, manu­fac­tu­ring, and digi­tal infrastructure.

Key points:

  • The Ger­man act lar­ge­ly con­sists of a com­ple­te over­haul of the exis­ting BSI Act (BSIG) – Germany’s core cyber­se­cu­ri­ty legislation. 
    • The BSI (Bun­des­amt für Sicher­heit in der Infor­ma­ti­ons­tech­nik) is the Fede­ral Office for Infor­ma­ti­on Secu­ri­ty, Germany’s natio­nal cyber­se­cu­ri­ty authority.
  • The revi­sed BSI Act defines: 
    • which com­pa­nies fall under NIS2,
    • their cyber­se­cu­ri­ty duties,
    • super­vi­so­ry powers, and
    • sanc­tions for non-compliance.
  • On 5 Decem­ber 2025, the law was published in the Fede­ral Law Gazet­te and has been in force sin­ce 6 Decem­ber 2025. No tran­si­ti­on peri­ods are planned.

What are “negli­gi­ble activities”?

A nota­ble fea­ture of the Ger­man imple­men­ta­ti­on is an exemp­ti­on for “negli­gi­ble acti­vi­ties” under Sec­tion 28(3) of the revi­sed BSI Act.

  • What does this mean?
    When deter­mi­ning whe­ther a com­pa­ny qua­li­fies as an “essen­ti­al” or “important” enti­ty under NIS2, minor busi­ness acti­vi­ties can be excluded, if inclu­ding them would dis­pro­por­tio­na­te­ly trig­ger NIS2 obligations.This is rele­vant becau­se Ger­man law defi­nes NIS2 appli­ca­bi­li­ty based on sec­to­ral acti­vi­ties lis­ted in two anne­xes of the BSI Act (e.g., health­ca­re, manu­fac­tu­ring, trans­port, digi­tal ser­vices). The­se defi­ni­ti­ons have not been adjus­ted during the legis­la­ti­ve process.
  • What counts as negligible? 
    • A very small num­ber of employees assi­gned to the activity
    • Mini­mal tur­no­ver gene­ra­ted in that area
  • What does not count as negli­gi­ble?
    Acti­vi­ties expli­cit­ly lis­ted in: 
    • the artic­les of association,
    • share­hol­der agree­ments, or
    • other foun­da­tio­nal com­pa­ny documents.

Tho­se must always be con­side­red relevant.

What should com­pa­nies do now?

  • Update the NIS2 impact assess­ment: Due to the rigid sec­tor defi­ni­ti­ons, some uncer­tain­ties remain. The exemp­ti­on for negli­gi­ble acti­vi­ties gives com­pa­nies more fle­xi­bi­li­ty in eva­lua­ting their own appli­ca­bi­li­ty.
    Howe­ver: Cyber­cri­mi­nals do not limit their attacks based on legal defi­ni­ti­ons. Exclu­ding acti­vi­ties too aggres­si­ve­ly may lea­ve secu­ri­ty vul­nerabi­li­ties unaddressed.
  • Prepa­re for man­da­to­ry regis­tra­ti­on with the BSI: All “important” and “essen­ti­al” enti­ties must regis­ter via a BSI online por­tal. Signi­fi­cant cyber­se­cu­ri­ty inci­dents must be repor­ted to the aut­ho­ri­ty wit­hout delay.
  • Imple­ment the requi­red NIS2 secu­ri­ty mea­su­res: Com­pa­nies should now begin imple­men­ting NIS2-compliant mea­su­res on both the tech­ni­cal and orga­ni­sa­tio­nal level. This includes: 

The EU Cyber Resi­li­ence Act (CRA) should also be con­side­red whe­re rele­vant, as it intro­du­ces product-related cyber­se­cu­ri­ty obligations.

How reusch­law sup­ports NIS2 implementation

reusch­law assists com­pa­nies by:

For tech­ni­cal mea­su­res, reusch­law works with spe­cia­li­sed part­ners, ensu­ring com­pa­nies meet the tigh­ten­ed legal requi­re­ments and are well pre­pared for audits and super­vi­so­ry reviews.

back

Stay up-to-date

We use your email address exclusively for sending our newsletter. You have the right to revoke your consent at any time with effect for the future. For further information, please refer to our privacy policy.