Reporting obligations under NIS2

Dr Lukas Kalkbrenner LL.M.

Laura Emmeluth

Since December 6, 2025, the European NIS2 Directive has been implemented in Germany in the Act on the Federal Office for Information Security (BSIG). The so-called BSIG introduces binding obligations in the area of IT and cybersecurity for many companies in affected sectors for the first time. A key point here is the reporting obligations for significant security incidents under Section 32 BSIG. The BSIG distinguishes - similar to NIS2 - between “important” and “particularly important” institutions. To qualify, companies must be subject to certain specified sectors and also exceed certain thresholds (in terms of employees and annual turnover). The range of sectors affected extends from medical device manufacturers to so-called managed service providers that provide IT services (including within their own group).

What is considered a security incident under the BSIG – and when is it “significant”?

A security incident occurs when the availability, integrity, or confidentiality of data or IT-supported services is compromised - the decisive factor is therefore the connection to the IT infrastructure. A security incident is significant if it causes or could cause serious operational disruptions to services or financial losses for the affected institution, or if it has caused or could cause significant material or immaterial damage to other persons. For digital services, EU Implementing Regulation 2024/2690 specifies the assessment of when an incident is considered significant.

Reporting process and deadlines according to Section 32 BSIG

Der Meldeprozess ist mehrstufig und beginnt mit der Kenntniserlangung über einen erheblichen Sicherheitsvorfall (The reporting process is multi-stage and begins with the discovery of a significant security incident (triggering a deadline).

  • The initial report must be made immediately, at the latest within 24 hours of discovery. In particular, it must be stated whether the incident could be attributed to illegal or malicious acts or could have cross-border implications.
  • This must be followed by an assessment report without delay, at the latest within 72 hours. This is a confirmation or update of the initial report and contains an initial assessment of the severity and impact.
  • A final report must be submitted no later than one month after the assessment report has been submitted. It contains, among other things, a detailed description, severity, cause, threat, remedial measures, and any cross-border implications.

Companies and organizations report the incident using the portal provided by the BSI; prior registration on the BSI portal is required for this.

What does the NIS2 reporting obligation have to do with reporting under the GDPR?

A reportable data protection incident is not automatically a significant security incident under Section 32 BSIG; the thresholds differ significantly: A data protection incident that is likely to pose a risk to the rights and freedoms of natural persons triggers a report to the data protection supervisory authority under Article 33 GDPR. The materiality threshold for reports under the BSIG is higher because it depends, among other things, on serious operational disruptions/financial losses or significant damage.

Depending on the incident, both reporting obligations may apply in parallel (e.g., IT security incident involving personal data) to different authorities - companies should have appropriate processes in place.

Anyone who fails to report, reports incorrectly, incompletely, or late, contrary to Section 32 (1) BSIG, is acting unlawfully. The BSIG provides heavy fines for this.

Practical tips for companies

  • Be prepared internally for the very short reporting deadlines and clarify responsibilities internally. Checklists can help here. Even trivial questions must be clarified at all times: Who reports to the BSI via the portal, who coordinates parallel reports (e.g., GDPR) if necessary?
  • Familiarize yourself with the criteria (such as the extent of service disruption) for the reporting obligation.
  • Take industry specifics into account: Additional criteria apply to digital services (EU Implementing Regulation 2024/2690). 

The NIS2 reporting obligation under Section 32 BSIG requires a rapid, structured response to significant security incidents with clear deadlines, content, and a multi-stage process. Affected companies should now make their incident response and reporting processes “BSIG-compliant” in order to act in a legally compliant manner and avoid significant penalties.

IT and Telecommunications