The German NIS2 clocks a consultant has to track
BSIG 2025 registration, change and incident deadlines with their section numbers, and the order to put them in place for a German client.
20 September 2026

Germany is the easy one, which is why people get it wrong
Compared with the member states still drafting, Germany is straightforward: the law is enacted, in force, numbered and published in full. NIS2UmsuCG brought the BSIG 2025 into force on 6 December 2025, and most of what a consultant needs sits in three readable sections.
Which is exactly where the errors come from. A German client hears "NIS2" and assumes the directive's headline numbers apply verbatim. Some do. The ones that matter most for planning — registration, change notification, and the German category names — do not travel from any other country.
Every country-level statement below comes from our national NIS2 profile data, checked against primary sources on 17 September 2026. Re-check the source before putting a date into a client deliverable.
The numbers, in one table
| Duty | German requirement | Source |
|---|---|---|
| Law in force | 6 December 2025 | NIS2UmsuCG, BSIG 2025 |
| Registration | Required | §33 BSIG |
| Registration deadline | Within 3 months of first qualifying | §33 BSIG |
| Change notification | Within 2 weeks | §33 BSIG |
| Early warning | 24 hours | §32 BSIG |
| Full notification | 72 hours | §32 BSIG |
| Final report | 30 days — one month after the incident notification | §32 BSIG |
| Competent authority | Federal Office for Information Security (BSI) | — |
| Registration route | Mein Unternehmenskonto, then the BSI portal at portal.bsi.bund.de | — |
| Size thresholds | No national deviation recorded; the directive's size-cap rule applies | §28 BSIG |
Two details in that table are easy to misread.
The registration clock has no calendar date. It runs three months from the moment the entity first qualifies. Belgium, by contrast, ran fixed calendar deadlines. There is no German date to circle; there is a trigger event to detect, which means somebody inside the client has to notice the trigger. An entity that crosses the size test through hiring, or picks up a listed activity through an acquisition, starts its own three-month window on a day nobody announces.
The final report runs from the notification, not from the incident. The profile records 30 days, and the German text puts it at one month after the incident notification (§32 BSIG). If an incident is detected late and notified late, the final report moves with the notification. Do not anchor it to the incident date in a procedure document.
Three categories, and the naming trap
German law does not run the directive's plain two-way split. The BSIG 2025 has three categories:
- besonders wichtige Einrichtungen — essential entities
- wichtige Einrichtungen — important entities
- operators of critical facilities — a separate category
The translation trap costs you credibility in the first meeting. Wichtig means "important". A client who says "wir sind wichtig" has told you they are in the important tier — the lower-supervision one — not that they are significant. Besonders wichtig, "particularly important", is the essential tier. Read a client's own internal memo carefully before building on its self-classification.
The third category matters for older clients. An operator of critical facilities is not an essential entity with a different label; it is its own category in the German statute. If your client was already regulated as a critical-infrastructure operator before NIS2UmsuCG, do not assume the new essential-entity duties simply replace what they had.
§28(3): the lever most clients do not know exists
The German size and scope rules sit in §28 BSIG. The profile records no national deviation from the directive's size-cap rule, which means the standard EU size definitions under Recommendation 2003/361/EC do the work.
But §28(3) BSIG lets negligible business activities be disregarded when classifying. That is the provision worth knowing before you tell a client they are in scope.
The typical case: a manufacturer with a small in-house IT services line, or a logistics group with a marginal energy activity, where the listed-sector activity is a rounding error against the rest of the business. Without §28(3), the sideline drags the whole entity into the regime. With it, there is a genuine argument that the activity is negligible and should be disregarded for classification.
Two cautions. "Negligible" is a judgement that will be tested, not a checkbox — write the case down at the time, with the figures behind it, rather than reconstructing it under supervision two years later. And the judgement is a legal qualification belonging to the consultant who signs the file: propose it with the trigger explained, have the client confirm, record who decided.
The order of work for a German client
This is the sequence I would run, and the sequencing matters because two steps have queueing time inside the client organisation rather than inside your work.
1. Establish scope per entity, and get it confirmed in writing. Sector, headcount, turnover, group structure for the size-cap aggregation, and the §28(3) question if there is a marginal activity. One answer per legal entity, not per group. Finish with a named person confirming the category — essential, important, operator of critical facilities, or out of scope.
2. Start the account onboarding immediately, in parallel with everything else. German registration runs through Mein Unternehmenskonto and then the BSI portal. It is an identity and account step before it is a compliance step, and it is the kind of thing that sits in a client's finance or IT queue for weeks. Start it on day one of the engagement, not in month three when the §33 window is closing.
3. Register within three months of first qualifying (§33). With step 2 already done, this is a data exercise: entity details, sector, contacts. Record the submission date in the client file. That date is what you will be asked for.
4. Name the incident contacts and give them authority. Who is permitted to send an early warning to the BSI, and who is their backup at 2am on a Sunday. A 24-hour clock does not survive an approval chain that needs a director who is on a plane. This is a decision the client makes and you document.
5. Write the incident procedure against 24 / 72 / 30. Detection, the decision that an incident is reportable, the early warning within 24 hours, the fuller notification within 72, and the final report one month after the notification. State plainly in the procedure that the final report runs from the notification. Include what goes in each message and where the record of each is kept.
6. Put change notifications on a tracker (§33, two weeks). This is the duty that rots quietly. The client registers once, then changes its legal name, registered contacts, entity structure or sector activity, and nobody updates anything. Anything that would change a registration field is a trigger, and two weeks is short enough that it needs a standing habit rather than a project.
7. Document management approval of the risk-management measures. The directive puts responsibility for approving those measures on management bodies. Record the approval with a date and a signatory, not as an email thread.
8. Then the document set. Risk-management policy, supply-chain security requirements for critical ICT vendors, business continuity and crisis management, and an asset register built from the client's real vendor list. A supply-chain policy that names no suppliers is not a supply-chain policy.
Steps 1 through 4 are where a missed engagement actually fails. Steps 5 through 8 are the visible deliverables, and they are the part clients think they hired you for.
One thing not to do
Do not reuse the German pack for the client's Austrian, Danish or Belgian entities by swapping the authority name. The registration triggers differ, the change-notification windows differ, and the aggregation rules for partner and linked enterprises differ. The 24 / 72 / 30 reporting clocks are the part that diverges least; everything around them is national.
We keep these national profiles as data rather than prose for exactly that reason — clausebench renders the incident procedure with the right authority and deadlines per country of operation, which speeds up your work on a multi-entity client. It does not make the classification call. That stays with you.
Facts in this post were checked on 17 September 2026 against the sources linked above. German commencement orders and authority guidance move; check them again before you rely on them.