BSI-Gesetz (BSIG), Incident Notification
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 9 months, effective 6 December 2025.
A vulnerability and incident reporting rule binding public and private bodies.
As of 12 September 2026.
What it requires
- This binds a besonders wichtige Einrichtung or wichtige Einrichtung under Section 28, which names an online marketplace, an online search engine and a social-networking-platform provider among the digital-service providers it reaches expressly; the wider sector classes it also reaches are not separately flagged here, for the reason given on this jurisdiction's companion risk-management row.
- Notify the BSI's and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe's joint reporting office without delay, and in any event within 24 hours of becoming aware of a significant security incident, with an early warning stating whether the incident is suspected to be unlawful or malicious or to have cross-border effect.
- Follow with a full notification within 72 hours of becoming aware, confirming or updating the early warning and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
- Submit an intermediate report on the BSI's request, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it.
- Where you operate a critical facility (Betreiber kritischer Anlagen), additionally report the type of facility and critical service affected and the incident's effect on that service.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Section 65's penalty regime for a Section 32 infringement is an administrative fine (Ordnungswidrigkeit); no provision reviewed here makes a failure to report itself a criminal offence.
Penalty structure
The same Section 65(5) No. 1(a) and (b), Section 65(6) and Section 65(7) tiers that govern a Section 30 infringement govern a Section 32(1) or 32(2) infringement: EUR 10,000,000 or, above EUR 500,000,000 group turnover, up to 2 percent of turnover for an essential entity, and EUR 7,000,000 or up to 1.4 percent of turnover for an important entity.
- Rule
- Higher of
- As of
- 12 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Bundesamt für Sicherheit in der Informationstechnik (BSI), as the zuständige Aufsichtsbehörde (competent supervisory authority) for Part 3 of the BSIG over wichtige and besonders wichtige Einrichtungen established in Germany, Betreiber kritischer Anlagen whose critical facilities lie in Germany, and Einrichtungen der Bundesverwaltung.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/nis-2-regulierte-unternehmen_node.html
- Guidance body
- Bundesamt für Sicherheit in der Informationstechnik (BSI)
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 32 requires a besonders wichtige Einrichtung or wichtige Einrichtung to notify a joint reporting office run by the BSI and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe of a significant security incident on a graduated clock.
It requires an early warning within 24 hours of becoming aware of the incident, stating whether it may be unlawful or malicious or have cross-border effect, followed by a full notification within 72 hours that confirms or updates that assessment with the incident's severity, impact and any indicators of compromise, and an intermediate report on the BSI's request.
A final report is due within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report after its resolution, transposing NIS2 Article 23. A Betreiber kritischer Anlagen must additionally report the type of critical facility and critical service affected and the incident's effect on that service.
When LexLint raises it
operates_social_platform
Read the law
BSI-Gesetz (BSIG), consolidated text, gesetze-im-internet.de, Section 32