German business leaders face personal accountability and potential million-euro fines as the country’s NIS-2 Implementation Act takes effect, making corporate cybersecurity a direct executive responsibility. The legislation, which applies to roughly 29,000 companies across 18 sectors, entered into force on December 6, 2025.
Under the new NIS-2 Directive, responsibility extends beyond IT departments directly to company management. Affected businesses must systematically manage cyber risks, incorporate their leadership immediately, consider supply chain risks, and meet strict reporting deadlines following security incidents. Organizations must submit an early initial report to the Federal Office for Information Security (BSI) within 24 hours of a security-relevant incident, update it within 72 hours, respond ad-hoc upon BSI request, and file a final report within a month.
Pflichten und Bußgelder
Violations of cybersecurity measures carry penalties of up to ten million euros or two percent of the preceding financial year’s total worldwide turnover. Companies that fail to comply with reporting obligations for important entities face fines of up to seven million euros or 1.4 percent of their previous year’s turnover. Prior to these measures, the Bundeskriminalamt (BKA) recorded 335,000 cyberattacks in 2025, compared to 136,865 in 2022, with damages to the German economy reaching 202,4 billion euros. According to the Bundeslagebild Cybercrime 2025 of the Federal Criminal Police Office (BKA), 1,041 ransomware attacks were reported in Germany in 2025, representing a ten percent increase compared to the previous year. The BKA describes the dark figure as substantial, and 66 percent of all spam emails are fraud or extortion attempts. Day after day, specialists from the Federal Office for Information Security (BSI) discover more than a quarter of a million pieces of malware on storage media.
Registrierung und Betroffene Sektoren
The first mandatory requirement under the framework is registration with the joint registration office of the BSI and the Federal Office of Civil Protection and Disaster Assistance (BBK). The rules target highly critical sectors such as energy, health, banking, transport, information technology, drinking water, waste water, space, and public administration. Additional impacted industries include chemical manufacturing, food production, automotive companies, research facilities, and courier services, divided into “particularly important entities” and “important entities” based in part on company size criteria including more than 250 employees, a turnover exceeding 50 million euros, and a balance sheet total above 43 million euros. The BSI assists with a type of online calculator that helps companies orient themselves, and specialized service providers also assist.