Germany's NIS2 transposition is enacted and in force. The NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (the Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung, NIS2UmsuCG) was enacted 2 December 2025 (BGBl. 2025 I Nr. 301) and, under its own Article 30, entered into force on 6 December 2025 with no transition period.
Its Article 1 wholly replaces the 2009 BSI-Gesetz with a new BSI-Gesetz (BSIG), which is now the operative text.
Sections 28 and 30 bind a besonders wichtige Einrichtung (essential entity) or wichtige Einrichtung (important entity), defined by Anlage 1 and Anlage 2 sector lists that include, alongside critical-facility operators, large telecommunications and digital-infrastructure providers (including cloud computing), and public administration, the digital-service providers Anlage 2 Nummer 6 names expressly: an online marketplace, an online search engine, and a social-networking-platform provider, bound at the wichtige Einrichtung threshold of at least 50 employees or an annual turnover and balance-sheet total each over EUR 10 million.
Section 32 sets a graduated incident-notification clock to a joint reporting office run by the BSI and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe: an early warning within 24 hours of becoming aware of a significant security incident, a full notification within 72 hours, an intermediate report on the BSI's request, and a final report within one month (or a progress report if the incident is still ongoing at that point), transposing NIS2 Articles 21 and 23.
No German instrument reviewed here imposes a mandatory product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here; Section 55 BSIG establishes a Freiwilliges IT-Sicherheitskennzeichen (voluntary IT security label) under which a manufacturer or service provider may seek the BSI's approval to display a label backed by a manufacturer declaration and a BSI security notice, but the section's own heading and text mark participation as voluntary, so it is named here rather than recorded as an instrument.
The pre-NIS2 BSIG obligations on KRITIS operators do not remain in force as a separate regime: the 2025 Act's own publisher note records that it replaces (ersetzt) the 2009 BSI-Gesetz (BGBl. I S. 2821) outright, and a critical-facility operator (Betreiber kritischer Anlagen) is now bound by the new Act's own Sections 30 and 31 risk-management duties as a besonders wichtige Einrichtung; Section 39's transitional rule only lets an operator already compliant under the old Section 8a evidentiary regime keep its existing proof timetable for a period after commencement, rather than preserving the old duty itself.
Which entity counts as a Betreiber kritischer Anlagen is in turn set by the separate KRITIS-Dachgesetz (the CER Directive's physical-resilience transposition), whose own implementing Rechtsverordnung had not yet entered into force as of this review, so Section 66 keeps a narrower pre-existing definition and a narrower Section 33 registration duty in effect until it does; that dependency concerns which operators are designated, not whether the cyber duties documented here apply once designated.
Germany has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, and personal-data breach notification under GDPR Articles 33 and 34 and BDSG Sections 41-43 to the BfDI and the Landesdatenschutzbehörden, both of which sit in the privacy topic rather than here.
Only the digital-provider slice of the essential-and-important-entity class (an online marketplace, an online search engine, a social-networking-platform provider, and a cloud-computing-service provider) is flagged on this jurisdiction's rows; the wider sector classes Sections 28 to 31 also reach (critical-facility operators, telecommunications, energy, health, finance, and public administration) are recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.
The Act's official full citation records it as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), and the consolidated text also carries an amendment by Article 4 of the Act of 11 March 2026 (BGBl. 2026 I Nr. 66); the December 2025 date on each instrument is the Act's commencement, not the date it last changed.