National Annex — Germany (DE)¶
Status (July 2026): In force. Community-maintained orientation, not legal advice — verify against the official gazette and authority guidance before relying on it. Corrections welcome (see CONTRIBUTING.md).
NIS2 implementation¶
| Field | Value |
|---|---|
| Implementing law | NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), amending the BSIG — in force 6 December 2025 |
| Competent authority | BSI (Bundesamt für Sicherheit in der Informationstechnik) |
| National CSIRT / reporting | CERT-Bund (BSI) |
| Official starting point | https://www.bsi.bund.de/nis-2 |
Country notes for your CDC¶
Registration deadline was 6 March 2026 (BSI signalled leniency to ~31 July 2026 for stragglers — verify). BSI offers a Betroffenheitsprüfung (applicability check) and management training resources; besonders wichtige vs wichtige Einrichtungen mirror essential/important.
Standard checklist (all countries)¶
- [ ] Applicability determined per legal entity and sector; recorded in the regulatory applicability register (GOVERN)
- [ ] Entity registration completed with the national authority where required
- [ ] Incident-reporting procedure drilled against the national channel and the 24 h early-warning clock (RESPOND)
- [ ] Contact established with the national CSIRT before the first incident
- [ ] Data protection authority contact and GDPR Art. 33 flow prepared (runs in parallel with NIS2 reporting)
- [ ] National guidance/frameworks mapped to your control evidence (see note above)
Selector tag¶
de-nat — tick "Germany" in tools/regulatory-profile.html to include this country's references.
Open CDC Framework (CC BY 4.0).