← All modules and pricing

NIS2

NIS2 in Germany — from the BSIG to your evidence.

Registration, ten minimum measures, reporting channels with deadlines: we guide you through Germany's BSI Act and hand you a document you can put in front of management.

Price

Price on request

Depends on which country or countries you implement NIS2 for — we calculate it together with you.

Request a quote →

All prices plus VAT, flat per company, hosted in Germany, cancel monthly.

See bundles →Questions? Request a demo →

What NIS2 requires of you.

1

Find out whether you're in scope, and at which tier — before anything else gets registered or reported.

2

Register with the competent national authority inside the statutory deadline.

3

Put all ten statutory minimum measures in place — from risk analysis to multi-factor authentication — each backed by dated evidence, not a checkbox.

4

Report incidents through the correct channel, at every stage the law requires: early warning, formal report, and follow-up.

In numbers, from our requirement catalogue

13

Requirements in the catalogue

13

Provisions checked against the statute text and backed by at least one measure in the catalogue

Every requirement carries a source, every one has at least one measure — checked by an automated catalogue test on every change. That's the foundation of our promise: audit-ready.

Germany's BSI Act (BSIG), as amended by the NIS2 transposition act

Competent authority

Bundesamt für Sicherheit in der Informationstechnik (BSI) — Germany's Federal Office for Information Security

Classification: Section 28 BSIG · Registration: Section 33 BSIG — registration with the BSI

Reporting incidents: Section 32 BSIG — reported to the joint reporting office of the BSI and the Federal Office of Civil Protection and Disaster Assistance (BBK) (early warning within 24 hours, report within 72 hours, follow-up report one month after the 72-hour report)

Key dates — all already in force

  • NIS2: the BSI registration grace period has ended — in force since 31/07/2026(§ 33 BSIG)

The ten minimum measures — same duty, your source citation

01

Risk analysis and information security policies

Section 30(2) No. 1 BSIG

02

Incident handling

Section 30(2) No. 2 BSIG

03

Business continuity — backup, disaster recovery, crisis management

Section 30(2) No. 3 BSIG

04

Supply chain security

Section 30(2) No. 4 BSIG

05

Security in acquisition, development and maintenance

Section 30(2) No. 5 BSIG

06

Effectiveness assessment

Section 30(2) No. 6 BSIG

07

Basic training and awareness measures

Section 30(2) No. 7 BSIG

08

Cryptographic procedures

Section 30(2) No. 8 BSIG

09

Personnel security, access control and management of ICT systems

Section 30(2) No. 9 BSIG

10

Multi-factor authentication and secure communications

Section 30(2) No. 10 BSIG

One honest note: There is no official NIS2 certificate. Unlike ISO 27001, NIS2 is a regulatory obligation, not a certification scheme — no accredited body issues a "NIS2-certified" seal, and no vendor can honestly sell you one. What we deliver instead is audit-ready evidence: every requirement met, documented, and dated, so you can show a regulator or a large customer exactly how you meet the law.

NIS2 in Germany: frequently asked questions

What does the NIS2 in Germany module cost at Compliverse?

We don't publish a list price for this module — we calculate it with you, because scope, the number of companies and, for NIS2, the number of countries differ too much. You get a written quote with a fixed amount before anything starts. You can ask for one through the contact form; a sales call is not a precondition.

NIS2 in Germany: legal obligation or voluntary?

An obligation — though not for every company. Sector and size decide whether you are in scope (Section 28 BSIG). No official notice arrives: you assess the classification yourself and register if it applies (Section 33 BSIG). Judging your individual case is a lawyer's job; we supply structure and evidence, not legal advice.

What does NIS2 in Germany actually require of us?

Find out whether you're in scope, and at which tier — before anything else gets registered or reported. Register with the competent national authority inside the statutory deadline. Put all ten statutory minimum measures in place — from risk analysis to multi-factor authentication — each backed by dated evidence, not a checkbox. Report incidents through the correct channel, at every stage the law requires: early warning, formal report, and follow-up.

How completely does Compliverse cover NIS2 in Germany?

Our catalogue holds 13 requirements for this framework. Each carries a legal source and each has at least one measure behind it — checked by an automated test on every change, not by good intentions. That is what "audit-ready" means for us: we do not guarantee that you end up compliant, because nobody can do that honestly. We guarantee that it is provable.

Which authority is responsible in Germany — and where do we report an incident?

Registration and supervision: Bundesamt für Sicherheit in der Informationstechnik (BSI) — Germany's Federal Office for Information Security. Registering: Section 33 BSIG — registration with the BSI. Reporting an incident: to the joint reporting office of the BSI and the Federal Office of Civil Protection and Disaster Assistance (BBK), under Section 32 BSIG (early warning within 24 hours, report within 72 hours, follow-up report one month after the 72-hour report). Note that the supervisory authority and the reporting office are not the same body — the incident assistant takes you to the right one when it matters.

Our promise

We don't say “compliant”. We say audit-ready — and we can prove it.

Nobody can guarantee that a company did everything right in an audit — not even a provider who promises it more confidently. What can be guaranteed is this. Four points, each independently verifiable.

01

Complete against the statute text

Every provision we cover has at least one requirement, every requirement at least one measure — and every one carries its source citation. That's not a promise: an automated test checks the catalogue on every change. If it finds a gap, the module doesn't ship.

→ Verifiable in each framework's requirement catalogue

02

Current, with a date

We re-read the legal texts in the original wording every month and update the product, training and website to match. Every check lands publicly in the change log — even when nothing changed.

→ Public change log on the Legal Landscape page

03

Evidenced, not asserted

Every requirement we mark as met has a document, certificate or log behind it — with a source citation and a legal-status date. What you can't hand an auditor doesn't count as done with us.

→ Evidence package as PDF, exportable at any time

04

Honest about the boundary

We provide structure, documents and evidence — not legal advice for your specific case. Where a question belongs with a lawyer, we say so instead of selling you something.

→ No legal advice — printed on every document

See the change log →

Last checked on 01/09/2026. That's how you get evidence that survives scrutiny — instead of a binder that falls apart at the first follow-up question.

What becomes important next

More modules

Legal status checked on 01/09/2026 · Every statement with a source · No legal advice