
The sequence is: IT Security Act 2015, NIS-1 in 2016, IT Security Act 2.0 in 2021, NIS-2 in 2022 — implemented in Germany since December 2025. It is often mixed up, which is why the dating comes first.
One addition has come since then that is missing from many comparisons: the KRITIS umbrella act of March 11, 2026 has already amended the BSIG again through its Article 4.
The system change consists in applicability no longer depending on individual critical facilities but on sector and company size. Under NIS-1 and the IT Security Act 2.0, it essentially depended on critical facilities and on thresholds of the BSI KRITIS ordinance. Anyone who did not reach the values was out.
Instead, the new BSIG designates entire entities and is tied to two characteristics: belonging to a sector in Annexes 1 and 2 and company size. This results in two categories — particularly important and important entities —, whose obligations differ above all in the supervisory regime. Operators of critical facilities are still covered but now form only a subset.
For this purpose, Section 28 BSIG works with size thresholds based on the European recommendation on the definition of small and medium-sized enterprises: for the higher category, the number of employees or turnover and balance sheet total are set significantly higher than for the lower one; special rules apply to telecommunications and trust services. The decisive practical difference from the old law lies not in the specific values but in the procedure: there is no longer an authority that informs a company that it is affected. Entities must determine this themselves.
The effect is the most frequently cited comparison of this reform: the BSI puts the regulated group at around 29,500 entities compared with around 4,500 previously (BSI press release of December 5, 2025). Checking one's own applicability has thus become a task that concerns every SME in one of the sectors mentioned; the individual steps of this check are described under NIS-2: Which companies are affected.
What is new compared with both previous generations is active self-registration. Section 33 BSIG requires registration with the Federal Office no later than three months after an entity is affected for the first time or again; changes must be updated without undue delay, at the latest within two weeks. The portal provided for this purpose has been activated since early January 2026; access runs in two stages via the company account.
Important for putting this into context: the BSI now expressly states on its pages that the statutory registration deadline has already expired. Anyone still planning for NIS-2 as an upcoming requirement is planning in disregard of the legal situation.
The catalogs of measures of the three generations are more similar than the debate suggests. What has shifted is how binding they are.
Section 30 BSIG requires appropriate, proportionate, and effective technical and organizational measures and lists a catalog of minimum measures in subsection 2. Its no. 7 names a point that was only indirectly included under NIS-1: basic training and awareness-raising measures in the field of information technology security. Awareness is thus expressly part of the statutory minimum standard — social engineering describes the class of attack behind it, and the article on the security awareness program describes the organizational setup of a program.
Section 32 BSIG replaces the former single-stage report with a cascade: an early initial report without undue delay, at the latest within 24 hours of becoming aware of a significant security incident; a report with an assessment within 72 hours; interim reports at the request of the Federal Office; a final report no later than one month after the 72-hour report. If the incident is still ongoing at that point, a progress report initially takes the place of the final report; the final report then follows once handling has been completed. This is less a new obligation than a new timing — and it requires a practiced process, not a phone number in the emergency folder.
Section 38 BSIG is the point with the greatest organizational impact. Under its subsections 1 to 3, management must implement the risk management measures and monitor their implementation, is liable for breaches of duty under the company law rules of the respective legal form, and must itself regularly take part in training on identifying and assessing risks and risk management practices in the field of information security. There was no equivalent under NIS-1. That management training must therefore in turn be verifiable is a direct consequence; what information a robust record contains is set out in Proving mandatory training.
For particularly important entities, the Federal Office acts proactively and can, among other things, order audits and evidence; for important entities, supervision is event-driven. The range of fines under Section 65 BSIG is tiered and can be based on worldwide annual turnover. This article deliberately does not give specific amounts — they depend on the entity category and the violation and belong in a legal examination of the individual case.
What has remained the same are the state-of-the-art standard, the responsibility of the Federal Office for Information Security (BSI), and the building blocks of an information security management system. In the discussion about NIS-2, this continuity regularly gets lost, even though it is good news for implementation: existing work does not become worthless.
The basic idea remains the state of the art: even the IT Security Act 2015 required appropriate organizational and technical precautions, and even then appropriateness was a moving target. The responsibility of the Federal Office for Information Security as the central body is also unchanged. Anyone who operates an information security management system continues to work with the same building blocks — risk analysis, measures, effectiveness review, documentation. And reporting to the Federal Office also existed in principle before.
Three things have shifted: the group of addressees, the timing of the obligations, and the question of who in the company is personally addressed. The third is the point most likely to get projects rolling.
Four consequences apply regardless of industry: a recurring applicability check, a rehearsed reporting process, documented awareness, and an involved management level.
Since March 17, 2026, there has been a second pillar; the act was published in the Federal Law Gazette on March 16, 2026 and entered into force the following day. The KRITIS umbrella act transposes Directive (EU) 2022/2557 and governs the physical resilience of critical facilities: registration with the Federal Office of Civil Protection and Disaster Assistance, risk analyses, resilience plans, disruption reports.
The distinction is easy to remember: the BSIG governs cybersecurity, the KRITIS umbrella act protection against physical failures and impacts. Operators of critical facilities can be subject to both at the same time; however, registration for this does not take place at two separate bodies but via an option set up jointly by the Federal Office for Information Security and the Federal Office of Civil Protection and Disaster Assistance. Anyone who today draws up a comparison of NIS-1 versus NIS-2 versus the IT Security Act 2.0 and leaves out this second pillar paints an incomplete picture.
Since December 6, 2025. The basis is the NIS-2 implementation act of December 2, 2025, promulgated as BGBl. 2025 I no. 301. Article 4 of the KRITIS umbrella act of March 11, 2026 has already amended the BSI Act again, among other things in connection with the designation of critical facilities. The previous version from 2009 has thus been completely replaced.
Not in the literal sense. The IT Security Act 2.0 was an amending act that in 2021 expanded, among other things, the BSI Act, for example to include attack detection systems. An amending act cannot be repealed. What was replaced was the then version of the BSI Act, which was redrafted in the course of the NIS-2 implementation; the 2021 content has been absorbed into it.
Both categories are tied to sector affiliation under Annexes 1 and 2 of the BSI Act and to size thresholds based on the European definition of small and medium-sized enterprises. The obligations under Section 30 BSIG are largely the same. The most important practical difference lies in the supervisory regime: for particularly important entities, the Federal Office acts proactively; for important entities, on an event-driven basis.
Section 32 BSIG provides for a cascade instead of a single report: an early initial report without undue delay, at the latest within 24 hours of becoming aware of a significant incident; a report with an assessment within 72 hours; interim reports if the Federal Office requests them; a final report no later than one month after the 72-hour report, or initially a progress report if the incident is still ongoing. The first stage does not require a complete analysis but rapid information.
Section 38 BSIG obliges management to implement the risk management measures, to monitor their implementation, and to regularly take part in training on identifying and assessing risks and risk management practices in the field of information security. In the event of breaches of duty, it is liable to the entity under the company law rules of its legal form. Delegation to the IT department expressly does not relieve it of the monitoring duty.
It is the physical complement to cybersecurity. The KRITIS umbrella act transposes Directive (EU) 2022/2557 and addresses resilience against failures and the protection of critical facilities — with its own registration, risk analyses, resilience plans, and disruption reports —, while the BSI Act governs cybersecurity. Operators of critical facilities can fall under both regimes at the same time; registration then runs via a joint option of the Federal Office for Information Security and the Federal Office of Civil Protection and Disaster Assistance.
Yes, if they belong to a sector in Annex 1 or 2 of the BSI Act and reach the size thresholds. This is precisely where the system change lies: what matters is no longer solely whether a critical facility is operated, but the combination of sector and company size. The jump from around 4,500 to around 29,500 entities is the direct consequence of this change.
All sources accessed on 6 Aug 2026 unless otherwise stated in the entry. For provisions on gesetze-im-internet.de, the legal status as of 6 Aug 2026 applies; retrieval there was not technically possible.
Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.
Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.