Contents
- NIS2 Notification Obligations – What Applies to Companies Since December 2025
- NIS2 Notification – Legal Basis
- What is the NIS2 Directive?
- Who is affected by NIS2 notification obligations?
- The Four NIS2 Notification Stages under Section 32 BSIG
- 1. Early Warning (24 Hours)
- 2. Detailed Report (72 Hours)
- 3. Interim Updates (On Request)
- 4. Final Report (After 1 Month)
- Step by Step to a Verifiable ISMS
- Specifics for Critical Infrastructure Operators (CRITIS)
- Additional Information Requirements
- Joint Reporting Point & Coordination
- Practical Implementation and Reporting Channel
- Joint BSI/BBK Reporting Point
- Support from BSI
- What Companies Should Do Now
- Legal Status and Next Steps
- Conclusion
NIS2 Notification Obligations – What Applies to Companies Since December 2025
Since 6 December 2025, the German NIS2 Implementation Act (NIS2UmsuCG) has been in force, and with it the notification obligations under Section 32 BSIG. They apply to around 29,500 entities supervised by the BSI, far beyond the operators of critical infrastructures (CRITIS) covered so far. According to the BSI, the law provides no general transition period. This article explains the four reporting stages, the reporting channel, and how to prepare.
Key Takeaways
- Four-stage notification process: 24h initial notification, 72h detailed report, interim updates on request, final report after one month
- More companies in scope: What matters is the sector (Annexes 1 and 2 of the BSIG) and the size of the organisation, not headcount or turnover alone
- The obligations already apply: The law has been in force since 6 December 2025, and the BSI portal for reports is available
NIS2 Notification – Legal Basis
What is the NIS2 Directive?
The NIS2 Directive (Network and Information Security Directive 2) is the revised EU directive on network and information security. It entered into force in January 2023, replacing the original NIS Directive (2016). Germany has implemented it with the NIS2UmsuCG (Federal Law Gazette 2025 I No. 301).
Compared to NIS1, NIS2:
- significantly broadens the scope of sectors
- raises security requirements
- and introduces stricter and more detailed reporting duties
Its goal is to establish a high common level of cybersecurity across the EU and to strengthen resilience against cyberattacks.
Who is affected by NIS2 notification obligations?
NIS2 distinguishes between two categories of entities:
-
Essential Entities Traditional critical infrastructures such as energy and water utilities, transport, banks, healthcare
-
Important Entities Newly added and strongly expanding the scope, including sectors such as:
- digital services and cloud operators
- waste management
- postal and courier services
- chemical industry
- food production and distribution
Scope: Not every company above a certain size is affected, only organisations in the sectors listed in Annexes 1 and 2 of the BSIG, from medium size upward. Whether an entity counts as essential or important depends on sector and size; the exact thresholds are set out in Section 28 BSIG (see the statute text). The BSI's applicability check provides a first assessment.
The Four NIS2 Notification Stages under Section 32 BSIG
The core of the rules is a multi-step reporting process for significant security incidents. It is regulated in Section 32 BSIG.
1. Early Warning (24 Hours)
- Deadline: without undue delay, at the latest 24 hours after becoming aware of the incident
- Purpose: rapid alert and initial situational awareness
Content includes:
- indication of unlawful or malicious actions
- potential cross-border impact on other EU Member States
Companies must be able to submit this initial notification even with incomplete information.
2. Detailed Report (72 Hours)
- Deadline: at the latest 72 hours after becoming aware
- Purpose: more detailed initial assessment
The 72-hour report should include:
- confirmation or update of the initial notification
- first assessment of severity and impact
- known Indicators of Compromise (IoCs)
- initial evaluation of affected systems and data
This enables authorities to coordinate response and warn other potentially affected entities.
3. Interim Updates (On Request)
- Trigger: upon request from the Federal Office for Information Security (BSI)
- Purpose: ongoing status updates for complex or long-running incidents
May include:
- progress in incident handling
- new findings regarding root cause or impact
- updated risk assessments
4. Final Report (After 1 Month)
- Deadline: at the latest one month after the 72-hour notification
It must contain a comprehensive documentation of the incident, including:
a) Detailed description of the incident
- full timeline
- concrete business impact
- affected systems, data and individuals
b) Threat type and root cause analysis
- technical attack vector
- exploited vulnerabilities
- likely motivation/origin of the attacker
c) Remediation measures
- immediate response actions
- ongoing remediation activities
- long-term improvements planned
d) Cross-border impact
- confirmed or suspected impact in other Member States
- coordination with foreign authorities
Special case: If the incident is still ongoing after one month, an interim progress report is submitted first, with the final report following once remediation is complete.
Step by Step to a Verifiable ISMS
NIS2 does not require certification, but an ISMS makes implementation verifiable. When an ISO 27001 certificate is still worthwhile is explained in the guide Who needs ISO 27001 certification?. With the fuentis ISMS Tool, you can implement modern standards in an automated and efficient way. Ready-to-use modules, guided workflows and expert support make building an ISMS straightforward, whether you are:
- starting from scratch, or
- modernising existing structures.
Multi-Compliance ISMS
- Complete ISMS tool supporting you in building and operating an ISMS based on ISO 27001
- Supports BSI IT-Grundschutz, TISAX® and NIS2 in parallel
Automated processes
- Workflows that guide you step by step through building the ISMS – even without prior experience
Review questionnaires
- Simple, customisable questionnaires to assess protection needs quickly and clearly
Personal support
- Direct access to experienced consultants – from initial analysis to audit support
Specifics for Critical Infrastructure Operators (CRITIS)
Additional Information Requirements
CRITIS operators must provide additional details beyond the four standard reports, such as:
- Type of critical facility (e.g. power plant, waterworks, hospital IT, traffic control system)
- Critical service affected (e.g. power supply, drinking water, patient care, public transport)
- Impact on the service number of customers affected, regional reach, duration of the disruption
Joint Reporting Point & Coordination
- Joint reporting point of BSI and BBK (Federal Office of Civil Protection and Disaster Assistance)
- Companies submit reports once and the authorities coordinate internally
Benefits:
- no need for parallel reporting to multiple bodies
- automatic forwarding to relevant supervisory authorities
- potential active support from BSI in handling incidents
Practical Implementation and Reporting Channel
Joint BSI/BBK Reporting Point
- Reports are submitted through the BSI portal to the joint reporting point of BSI and BBK
- The portal has been available since the law entered into force
- The reporting obligations have applied since 6 December 2025; there is no general transition period
The BSI publishes information and requirements on the reporting procedure on its website.
Support from BSI
Reporting entities may receive:
- technical support during incident handling
- forensic assistance
- coordinated communication with other authorities and experts
What Companies Should Do Now
-
Review and adapt incident response processes
- Align with 24h / 72h / 1-month deadlines (if not done yet)
- Define escalation paths
- Establish criteria for “significant” security incidents
-
Clarify responsibilities
- Set up an incident response team
- Ensure 24/7 availability
- Define backup roles and decision-making authority
-
Prepare technical capabilities
- Enhance logging and monitoring
- Secure forensic capabilities (in-house or external)
- Test backup and recovery processes
- Define crisis communication channels
-
Create documentation & templates
- Templates for each notification stage
- Checklists for incident handling
- Up-to-date contact lists (internal & external)
-
Run tests and training
- Conduct IR exercises
- Simulate reporting processes
- Raise awareness of NIS2 timelines and obligations
- Train management under Section 38 BSIG
-
Check your registration
- Registration in the BSI portal under Section 33 BSIG (within three months of becoming an entity)
- Follow the BSI's current guidance on registration
Legal Status and Next Steps
- The NIS2UmsuCG has been in force since 6 December 2025 (promulgated on 5 December 2025, Federal Law Gazette 2025 I No. 301). The notification obligations apply without a general transition period.
- Registration under Section 33 BSIG and reports under Section 32 BSIG run through the BSI portal. Violations can be fined; the range is set in Section 65 BSIG (see the statute text).
- Further details will follow from BSI guidance and EU implementing acts.
Conclusion
The NIS2 notification obligations are a binding part of the BSIG. The four-stage process with tight deadlines requires:
- adapted processes
- clear responsibilities
- trained teams
Status: October 2026. The legal basis is the BSIG as amended by the NIS2UmsuCG (Federal Law Gazette 2025 I No. 301). The current statute text is authoritative; check it and BSI publications for changes.
Organisations that set up processes and responsibilities in a structured way now are clearly better positioned when an incident occurs.
Are you affected by NIS2?
TISAX® is a registered trademark of the ENX Association. fuentis has no business affiliation with the ENX Association and is not an audit provider approved by ENX. The fuentis Suite supports preparation for TISAX® assessments.

CEO, fuentis AG
Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI standards and modern risk-analysis methods.