Particle.news

Bundestag Passes NIS2 Cybersecurity Law, Expanding Coverage and BSI Powers

Next stop is the Bundesrat following Germany’s missed EU transposition deadline.

Overview

  • Lawmakers approved the NIS2 implementation with votes from CDU/CSU and SPD and support from AfD, while the Greens voted against and the Left abstained.
  • The scope widens to roughly 14,500 entities and brings federal authorities under binding standards, including mandatory IT‑Grundschutz modernization by January 1, 2026 and the creation of a federal CISO.
  • Companies face a three‑stage incident reporting regime and must notify the BSI within 24 hours, with tougher oversight and potential fines for serious violations.
  • Amendments empower the BSI to issue orders to smaller telecom providers with 100,000 or fewer customers and allow the Interior Ministry to restrict ‘critical components’ in critical infrastructure after interministerial coordination.
  • The government cites major economic stakes with projected damage reduction for affected firms and notable compliance burdens, while industry groups welcome stronger security but urge clearer, practical rules as the Bundesrat takes up the bill.