Cybersecurity
The BSI Act as amended by the NIS2UmsuCG
Germany's NIS2 implementation act (NIS2UmsuCG) took effect on 6 December 2025 and fundamentally restructured and renumbered the BSI Act. Since then, operators of critical facilities are always classed as 'especially important entities' under Section 28 BSIG and must fulfil every NIS2 baseline obligation: risk management measures to the state of the art (Sections 30 and 31 BSIG), tiered reporting duties for significant security incidents (Section 32 BSIG), and regular evidence submission to the BSI (Section 39 BSIG).