NIS2UmsuCG (NIS 2 in Germany)
Regulatory structure
- NIS2UmsuCG
- Annex 1: Government Draft Page 72
- Annex 2: Government Draft Page 77
- Article Law ( Artikelgesetz): Indicates where the affected laws need to be amended
- Above all, the BSI Act ( BSI Gesetz) is being amended
- Many other changes are merely changes of references to the correct paragraphs
- EnWG and Telecommunications Act will be extensively expanded with specific regulations
Timeline
- 03 Jul 2023 1. draft bill ( Referentenentwurf)
- 22 Dec 2023 2. draft bill
- 07 May 2024 3. draft bill was submitted to the participation of the states as well as the hearings of associations
- 24 Jul 2024 Government bill ( Regierungsentwurf)
- 29 Nov 2024 Latest draft of government bill
- 23 Feb 2025 Due to early elections in Germany, the bill has to be reintroduced and negotiated when the newly elected parliament is constituted.
For more information see: BSI - Bundesamt für Sicherheit in der Informationstechnik - Archivierte sektorspezifische FAQ zu NIS-2
Affected Companies in Germany
Essential entities (Besonders wichtige Unternehmen)
- Employees: >= 250 - or -
- Annual revenue: > 50 million € and annual balance sheet total > 43 million €
- The size criteria does not apply to operators of critical facilities
- top-level domain name registries, qualified trust service providers, DNS service providers
- central government agencies
- For all other operators of critical facilities: supply of > 500,000 people
Important Companies (Wichtige Unternehmen)
- Employees: >= 50 employees - or -
- Annual balance sheet total and Annual revenue: each > 10 million €
- And listed as sector in Annex 1 or 2 NIS2UmsuCG