Law / Germany

BSI-Gesetz (BSIG), Incident Notification

BSI-Gesetz (BSIG) vom 2. Dezember 2025, as last amended by Article 8(1) of the Act of 23 July 2026 (BGBl. 2026 I Nr. 226), § 32

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 9 months, effective 6 December 2025.

A vulnerability and incident reporting rule binding public and private bodies.

As of 12 September 2026.

What it requires

  • This binds a besonders wichtige Einrichtung or wichtige Einrichtung under Section 28, which names an online marketplace, an online search engine and a social-networking-platform provider among the digital-service providers it reaches expressly; the wider sector classes it also reaches are not separately flagged here, for the reason given on this jurisdiction's companion risk-management row.
  • Notify the BSI's and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe's joint reporting office without delay, and in any event within 24 hours of becoming aware of a significant security incident, with an early warning stating whether the incident is suspected to be unlawful or malicious or to have cross-border effect.
  • Follow with a full notification within 72 hours of becoming aware, confirming or updating the early warning and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
  • Submit an intermediate report on the BSI's request, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it.
  • Where you operate a critical facility (Betreiber kritischer Anlagen), additionally report the type of facility and critical service affected and the incident's effect on that service.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Section 65's penalty regime for a Section 32 infringement is an administrative fine (Ordnungswidrigkeit); no provision reviewed here makes a failure to report itself a criminal offence.

Penalty structure

The same Section 65(5) No. 1(a) and (b), Section 65(6) and Section 65(7) tiers that govern a Section 30 infringement govern a Section 32(1) or 32(2) infringement: EUR 10,000,000 or, above EUR 500,000,000 group turnover, up to 2 percent of turnover for an essential entity, and EUR 7,000,000 or up to 1.4 percent of turnover for an important entity.

Rule
Higher of
As of
12 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Bundesamt für Sicherheit in der Informationstechnik (BSI), as the zuständige Aufsichtsbehörde (competent supervisory authority) for Part 3 of the BSIG over wichtige and besonders wichtige Einrichtungen established in Germany, Betreiber kritischer Anlagen whose critical facilities lie in Germany, and Einrichtungen der Bundesverwaltung.

Settledness

As of
12 September 2026
Guidance link
https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/nis-2-regulierte-unternehmen_node.html
Guidance body
Bundesamt für Sicherheit in der Informationstechnik (BSI)

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 32 requires a besonders wichtige Einrichtung or wichtige Einrichtung to notify a joint reporting office run by the BSI and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe of a significant security incident on a graduated clock.

It requires an early warning within 24 hours of becoming aware of the incident, stating whether it may be unlawful or malicious or have cross-border effect, followed by a full notification within 72 hours that confirms or updates that assessment with the incident's severity, impact and any indicators of compromise, and an intermediate report on the BSI's request.

A final report is due within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report after its resolution, transposing NIS2 Article 23. A Betreiber kritischer Anlagen must additionally report the type of critical facility and critical service affected and the incident's effect on that service.

When LexLint raises it

  • operates_social_platform

Read the law

BSI-Gesetz (BSIG), consolidated text, gesetze-im-internet.de, Section 32

Back to the example  ·  Lint your app