Law / Germany

BSI-Gesetz (BSIG), Risk-Management Measures for Essential and Important Entities

BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), §§ 28, 30, 38

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 9 months, effective 6 December 2025.

A sector security regimes rule binding public and private bodies.

As of 12 September 2026.

What it requires

  • This binds a besonders wichtige Einrichtung (essential entity) or wichtige Einrichtung (important entity) under Section 28, which names an online marketplace, an online search engine and a social-networking-platform provider (Anlage 2 Nummer 6) among the digital-service providers it reaches expressly, at the wichtige Einrichtung threshold of at least 50 employees or an annual turnover and balance-sheet total each over EUR 10 million; the wider sector classes Section 28 also reaches (critical-facility operators, large telecommunications and digital-infrastructure providers including cloud computing, and public administration) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
  • Adopt technical and organisational measures adequate and proportionate to the risks facing the network and information systems you use to provide your services, and to minimise the impact of a security incident on your services and on others.
  • Cover at least: risk analysis and information-security policy; incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of your systems, including vulnerability management and disclosure; evaluation of your measures' effectiveness; basic cyber-hygiene training; cryptography; personnel security and access control; and multi-factor or continuous authentication.
  • Document your compliance with this duty.
  • Have your management body implement and oversee these measures and attend regular risk-management training; expect it to be liable to your organisation for culpable damage from a breach of that duty under the ordinary rules of company law.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Section 65's penalty regime for a Section 30 infringement is an administrative fine (Ordnungswidrigkeit); no provision reviewed here makes the infringement itself a criminal offence.

Penalty structure

Section 65(5) No. 1(a) sets the standard maximum fine for a besonders wichtige Einrichtung's infringement of Section 30(1) at EUR 10,000,000; Section 65(6) raises that to up to 2 percent of total worldwide annual turnover for an essential entity whose group turnover exceeds EUR 500,000,000, which is mathematically the higher of the two thresholds throughout, mirroring NIS2 Article 34(4). Section 65(5) No. 1(b) and Section 65(7) apply the same mechanism to a wichtige Einrichtung at a EUR 7,000,000 fixed cap or up to 1.4 percent of turnover above the same EUR 500,000,000 group-turnover gate, mirroring NIS2 Article 34(5).

Rule
Higher of
As of
12 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Bundesamt für Sicherheit in der Informationstechnik (BSI), as the zuständige Aufsichtsbehörde (competent supervisory authority) for Part 3 of the BSIG over wichtige and besonders wichtige Einrichtungen established in Germany, Betreiber kritischer Anlagen whose critical facilities lie in Germany, and Einrichtungen der Bundesverwaltung.

Settledness

As of
12 September 2026
Guidance link
https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/nis-2-regulierte-unternehmen_node.html
Guidance body
Bundesamt für Sicherheit in der Informationstechnik (BSI)
Open questions
Does the Bundesministerium des Innern's Rechtsverordnung under Section 30(5), or a still-pending European Commission implementing act under NIS2 Article 21(5), narrow the ten baseline risk-management measure categories in Section 30(2) as they apply specifically to an online marketplace, online search engine or social-networking-platform provider?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 30 requires a besonders wichtige Einrichtung or wichtige Einrichtung, as Section 28 defines them against the Anlage 1 and Anlage 2 sector lists, to adopt appropriate, proportionate and effective technical and organisational measures to avoid disruption to the availability, integrity and confidentiality of the network and information systems it uses to provide its services, and to minimise the impact of a security incident, weighing risk exposure, size, implementation cost, and the likelihood and severity of incidents.

The measures must cover at least ten baseline categories: risk analysis and information-security policy, incident handling, business continuity and crisis management, supply-chain security, security in system acquisition and development including vulnerability management and disclosure, evaluation of measures' effectiveness, basic cyber-hygiene training, cryptography, personnel security and access control, and multi-factor or continuous authentication, transposing NIS2 Article 21.

Anlage 2 Nummer 6 names an online marketplace, an online search engine and a social-networking-platform provider among the digital-service providers this duty reaches expressly. Section 38 places implementation and oversight of these measures on the entity's management body, which is liable to the entity for culpable damage under the ordinary rules of company law and must attend regular training on recognising and assessing risk and risk-management practice.

When LexLint raises it

  • operates_social_platform

Read the law

BSI-Gesetz (BSIG), consolidated text, gesetze-im-internet.de, Section 30

Back to the example  ·  Lint your app