Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Germany Implements NIS2: Registration portal will open on January 6, 2026

By Dr. Annette Demmel & Mareike Lucht on December 5, 2025
Email this postTweet this postLike this postShare this post on LinkedIn

With the official enactment of the NIS-2 Implementation Act, Germany has taken a major step toward modernizing its cybersecurity framework. Starting from 6 December 2025, stricter requirements will apply to both federal administration and thousands of private companies. This law revises the BSI Act (BSIG) and introduces comprehensive obligations for IT security and risk management. The NIS2 Directive  is the EU’s updated cybersecurity framework. It requires organizations to implement risk management measures, ensure incident reporting within an initial 24-hour timeline, strengthens supply chain security while introducing management accountability, including personal liability for non-compliance.

Who Is Affected?

The scope of regulation expands dramatically:

  • Around 29,500 entities will now fall under the supervision of the BSI (Bundesamt für Sicherheit in der Informationstechnik – Federal Office for Information Security), compared to 4,500 previously.
  • Newly regulated organizations include those in critical sectors that meet specific thresholds for staff, revenue, and balance sheet.
  • These entities are classified as “essential” or “important” facilities. Operators of KRITIS (Critical Infrastructure) automatically qualify as “essential.”

Key Obligations

Affected companies must comply with three core requirements:

  1. Register as NIS2 entities within three months.
  2. Report significant security incidents to the BSI within 24 hours at the latest (with an update within 72 hours and a final report within 30 days).
  3. Implement and document risk management measures.

The BSI has issued guidance on the mandatory management training in this regard.

Registration Timeline

The BSI has announced a two-step registration process:

  • Step 1: Create an account on Mein Unternehmenskonto (MUK).
  • Step 2: From January 6, 2026, register via the new BSI portal, which will also serve as the reporting platform for major security incidents.

Call to Action

Non-compliance with NIS2 can not only lead to severe fines up to €10 million or 2% of global annual turnover, andpersonal liability for non-compliance, but in practical terms, it can also pose significant risks to a company’s cybersecurity.

Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

Photo of Dr. Annette Demmel Dr. Annette Demmel
Read more about Dr. Annette DemmelEmail
Photo of Mareike Lucht Mareike Lucht
Read more about Mareike LuchtEmailMareike's Linkedin Profile
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Privacy World
  • Organization:
    Squire Patton Boggs
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo