Legal Insights
17. February 2026
Dr Lukas Kalkbrenner LL.M.
Laura Emmeluth
Since December 6, 2025, the European NIS2 Directive has been implemented in Germany in the Act on the Federal Office for Information Security (BSIG). The so-called BSIG introduces binding obligations in the area of IT and cybersecurity for many companies in affected sectors for the first time. A key point here is the reporting obligations for significant security incidents under Section 32 BSIG. The BSIG distinguishes - similar to NIS2 - between “important” and “particularly important” institutions. To qualify, companies must be subject to certain specified sectors and also exceed certain thresholds (in terms of employees and annual turnover). The range of sectors affected extends from medical device manufacturers to so-called managed service providers that provide IT services (including within their own group).
A security incident occurs when the availability, integrity, or confidentiality of data or IT-supported services is compromised - the decisive factor is therefore the connection to the IT infrastructure. A security incident is significant if it causes or could cause serious operational disruptions to services or financial losses for the affected institution, or if it has caused or could cause significant material or immaterial damage to other persons. For digital services, EU Implementing Regulation 2024/2690 specifies the assessment of when an incident is considered significant.
Der Meldeprozess ist mehrstufig und beginnt mit der Kenntniserlangung über einen erheblichen Sicherheitsvorfall (The reporting process is multi-stage and begins with the discovery of a significant security incident (triggering a deadline).
Companies and organizations report the incident using the portal provided by the BSI; prior registration on the BSI portal is required for this.
A reportable data protection incident is not automatically a significant security incident under Section 32 BSIG; the thresholds differ significantly: A data protection incident that is likely to pose a risk to the rights and freedoms of natural persons triggers a report to the data protection supervisory authority under Article 33 GDPR. The materiality threshold for reports under the BSIG is higher because it depends, among other things, on serious operational disruptions/financial losses or significant damage.
Depending on the incident, both reporting obligations may apply in parallel (e.g., IT security incident involving personal data) to different authorities - companies should have appropriate processes in place.
Anyone who fails to report, reports incorrectly, incompletely, or late, contrary to Section 32 (1) BSIG, is acting unlawfully. The BSIG provides heavy fines for this.
The NIS2 reporting obligation under Section 32 BSIG requires a rapid, structured response to significant security incidents with clear deadlines, content, and a multi-stage process. Affected companies should now make their incident response and reporting processes “BSIG-compliant” in order to act in a legally compliant manner and avoid significant penalties.
You are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.