NIS2
NIS2 in Germany — from the BSIG to your evidence.
Registration, ten minimum measures, reporting channels with deadlines: we guide you through Germany's BSI Act and hand you a document you can put in front of management.
Price
Price on request
Depends on which country or countries you implement NIS2 for — we calculate it together with you.
Request a quote →All prices plus VAT, flat per company, hosted in Germany, cancel monthly.
See bundles →Questions? Request a demo →What NIS2 requires of you.
Find out whether you're in scope, and at which tier — before anything else gets registered or reported.
Register with the competent national authority inside the statutory deadline.
Put all ten statutory minimum measures in place — from risk analysis to multi-factor authentication — each backed by dated evidence, not a checkbox.
Report incidents through the correct channel, at every stage the law requires: early warning, formal report, and follow-up.
In numbers, from our requirement catalogue
13
Requirements in the catalogue
13
Provisions checked against the statute text and backed by at least one measure in the catalogue
Every requirement carries a source, every one has at least one measure — checked by an automated catalogue test on every change. That's the foundation of our promise: audit-ready.
Germany's BSI Act (BSIG), as amended by the NIS2 transposition act
Competent authority
Bundesamt für Sicherheit in der Informationstechnik (BSI) — Germany's Federal Office for Information Security
Classification: Section 28 BSIG · Registration: Section 33 BSIG — registration with the BSI
Reporting incidents: Section 32 BSIG — reported to the joint reporting office of the BSI and the Federal Office of Civil Protection and Disaster Assistance (BBK) (early warning within 24 hours, report within 72 hours, follow-up report one month after the 72-hour report)
Key dates — all already in force
- NIS2: the BSI registration grace period has ended — in force since 31/07/2026(§ 33 BSIG)
The ten minimum measures — same duty, your source citation
Risk analysis and information security policies
Section 30(2) No. 1 BSIG
Incident handling
Section 30(2) No. 2 BSIG
Business continuity — backup, disaster recovery, crisis management
Section 30(2) No. 3 BSIG
Supply chain security
Section 30(2) No. 4 BSIG
Security in acquisition, development and maintenance
Section 30(2) No. 5 BSIG
Effectiveness assessment
Section 30(2) No. 6 BSIG
Basic training and awareness measures
Section 30(2) No. 7 BSIG
Cryptographic procedures
Section 30(2) No. 8 BSIG
Personnel security, access control and management of ICT systems
Section 30(2) No. 9 BSIG
Multi-factor authentication and secure communications
Section 30(2) No. 10 BSIG
One honest note: There is no official NIS2 certificate. Unlike ISO 27001, NIS2 is a regulatory obligation, not a certification scheme — no accredited body issues a "NIS2-certified" seal, and no vendor can honestly sell you one. What we deliver instead is audit-ready evidence: every requirement met, documented, and dated, so you can show a regulator or a large customer exactly how you meet the law.
NIS2 in Germany: frequently asked questions
What does the NIS2 in Germany module cost at Compliverse?
We don't publish a list price for this module — we calculate it with you, because scope, the number of companies and, for NIS2, the number of countries differ too much. You get a written quote with a fixed amount before anything starts. You can ask for one through the contact form; a sales call is not a precondition.
NIS2 in Germany: legal obligation or voluntary?
An obligation — though not for every company. Sector and size decide whether you are in scope (Section 28 BSIG). No official notice arrives: you assess the classification yourself and register if it applies (Section 33 BSIG). Judging your individual case is a lawyer's job; we supply structure and evidence, not legal advice.
What does NIS2 in Germany actually require of us?
Find out whether you're in scope, and at which tier — before anything else gets registered or reported. Register with the competent national authority inside the statutory deadline. Put all ten statutory minimum measures in place — from risk analysis to multi-factor authentication — each backed by dated evidence, not a checkbox. Report incidents through the correct channel, at every stage the law requires: early warning, formal report, and follow-up.
How completely does Compliverse cover NIS2 in Germany?
Our catalogue holds 13 requirements for this framework. Each carries a legal source and each has at least one measure behind it — checked by an automated test on every change, not by good intentions. That is what "audit-ready" means for us: we do not guarantee that you end up compliant, because nobody can do that honestly. We guarantee that it is provable.
Which authority is responsible in Germany — and where do we report an incident?
Registration and supervision: Bundesamt für Sicherheit in der Informationstechnik (BSI) — Germany's Federal Office for Information Security. Registering: Section 33 BSIG — registration with the BSI. Reporting an incident: to the joint reporting office of the BSI and the Federal Office of Civil Protection and Disaster Assistance (BBK), under Section 32 BSIG (early warning within 24 hours, report within 72 hours, follow-up report one month after the 72-hour report). Note that the supervisory authority and the reporting office are not the same body — the incident assistant takes you to the right one when it matters.
Our promise
We don't say “compliant”. We say audit-ready — and we can prove it.
Nobody can guarantee that a company did everything right in an audit — not even a provider who promises it more confidently. What can be guaranteed is this. Four points, each independently verifiable.
01
Complete against the statute text
Every provision we cover has at least one requirement, every requirement at least one measure — and every one carries its source citation. That's not a promise: an automated test checks the catalogue on every change. If it finds a gap, the module doesn't ship.
→ Verifiable in each framework's requirement catalogue
02
Current, with a date
We re-read the legal texts in the original wording every month and update the product, training and website to match. Every check lands publicly in the change log — even when nothing changed.
→ Public change log on the Legal Landscape page
03
Evidenced, not asserted
Every requirement we mark as met has a document, certificate or log behind it — with a source citation and a legal-status date. What you can't hand an auditor doesn't count as done with us.
→ Evidence package as PDF, exportable at any time
04
Honest about the boundary
We provide structure, documents and evidence — not legal advice for your specific case. Where a question belongs with a lawyer, we say so instead of selling you something.
→ No legal advice — printed on every document
Last checked on 01/09/2026. That's how you get evidence that survives scrutiny — instead of a binder that falls apart at the first follow-up question.
What becomes important next
Legal Landscape
Deadline radar and change log — every update with a checked date.
To Legal Landscape →More modules
Legal status checked on 01/09/2026 · Every statement with a source · No legal advice