
Short answer: The German IT Security Act 2.0 (IT-SiG 2.0) is a 2021 law that amended the BSI Act, expanded the powers of the Federal Office for Information Security (BSI) and tightened duties for critical infrastructure (KRITIS) operators. In December 2025, Germany's NIS2 implementation law rewrote the BSI Act on top of that foundation, so today's obligations come from the new BSI Act, not from the 2021 text. SaaS and HealthTech vendors are rarely regulated directly, but their hospital, insurer and utility customers pass these requirements down through contracts and security reviews, and some vendors are now in scope themselves.
Related guides:
- From NIS to NIS 2: How to navigate the updated directive
- The NIS 2 Compliance Checklist
- BSI C5 compliance checklist
Key takeaways
- IT-SiG 2.0 took effect in 2021. It gave the BSI more powers, added municipal waste management as a critical sector, created the "companies in the special public interest" (UBI) category and raised fines.
- Germany's NIS2 implementation law was signed on December 2, 2025, published in the Federal Law Gazette (BGBl. 2025 I Nr. 301) on December 5, 2025 and took effect on December 6, 2025. It replaced the old BSI Act structure with a new BSI Act.
- The current law sorts organizations into particularly important entities and important entities. KRITIS operators automatically count as particularly important entities and carry extra duties, including attack detection systems.
- The UBI category from IT-SiG 2.0 no longer exists. Former UBI companies must check for themselves whether they fall under the new categories.
- Regulated entities must register with the BSI within three months of falling into scope and report significant incidents within 24 hours, 72 hours and one month.
- For the most serious violations, maximum fines are now up to EUR 10 million for particularly important entities and EUR 7 million for important entities. Only above EUR 500 million in annual turnover does the cap become 2% or 1.4% of total annual turnover respectively.
- Suppliers usually feel the law through procurement: security clauses, questionnaires, audit rights and incident notification duties in the contract. An ISO 27001 certificate or SOC 2 report, plus a clear incident and logging story, answers most of what these buyers ask.
What was the German IT Security Act 2.0?
IT-SiG 2.0 was the second German IT Security Act, an amending law that updated the BSI Act and related laws to raise the security bar for critical infrastructure and other important companies. The original IT Security Act of 2015 created the KRITIS regime: operators of critical facilities in sectors such as energy, water, health, food, IT and telecommunications, transport and finance had to secure their systems according to the state of the art and report significant disruptions to the BSI.
The second act, in force since 2021, kept that structure and made it stricter. It was not a standalone rulebook. Its changes lived inside the BSI Act (BSIG), the law that sets out the BSI's mandate and the duties of regulated organizations.
That matters today because the BSI Act has since been rewritten again. When people say "IT-SiG 2.0" in 2026, they usually mean the German security regime in general. For contracts and compliance work, the relevant text is the current BSI Act as amended by the NIS2 implementation law.
What did IT-SiG 2.0 change in 2021?
IT-SiG 2.0 broadened who was regulated, gave the BSI more tools and made non-compliance more expensive. The table below describes the 2021 regime. The last column shows where each item stands under the current BSI Act.
| 2021 change | What it meant | Status today |
|---|---|---|
| Expanded BSI powers | Stronger BSI roles in detecting threats, consumer protection and supervising regulated organizations | Carried forward and extended |
| New KRITIS sector | Municipal waste management added to the critical infrastructure sectors | KRITIS operators remain a distinct group |
| Companies in the special public interest (UBI) | A new category outside KRITIS, such as certain defense-related companies, very large companies of economic significance and operators handling hazardous substances | Category removed; affected companies must check whether they are now particularly important or important entities |
| Attack detection systems | KRITIS operators had to use systems to detect attacks, with the obligation applying from May 2023 | Still required for KRITIS operators under § 31 BSIG |
| Registration and reporting | KRITIS operators registered with the BSI, named a contact point and reported significant disruptions | Replaced by new registration and staged reporting rules for all regulated entities |
| Critical components | The government gained a route to review and, in some cases, prohibit certain critical components in critical infrastructure | Still part of the BSI Act framework |
| Higher fines | Maximum fines rose sharply, reaching up to EUR 20 million for companies in some cases | Replaced by the NIS2 fine framework described below |
What does the current BSI Act require after NIS2?
Germany implemented NIS2 through the Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung, often shortened to NIS2UmsuCG. Rather than creating a separate NIS2 statute, it rewrote the BSI Act. According to the BSI, the number of organizations under BSI supervision rose from about 4,500 to roughly 29,500.
The core rules in the current BSI Act are:
| Topic | Current rule | Source |
|---|---|---|
| Entity categories | Particularly important entities and important entities, based on sector and size. In the general case, particularly important means at least 250 employees, or annual turnover above EUR 50 million and a balance sheet above EUR 43 million. Important means at least 50 employees, or turnover and balance sheet each above EUR 10 million. Special rules apply to some sectors, such as telecoms and trust services. | § 28 BSIG |
| KRITIS operators | Operators of critical facilities count as particularly important entities and keep additional duties | § 28, § 31 BSIG |
| Risk management | Appropriate, proportionate technical and organizational measures, including supply chain security | § 30 BSIG |
| Management accountability | Management must implement and oversee the measures, take part in regular training and can be personally liable | § 38 BSIG |
| Registration | Register with the BSI no later than three months after first falling into scope | § 33 BSIG |
| Incident reporting | Early warning within 24 hours, incident notification within 72 hours, final report within one month | § 32 BSIG |
| Attack detection | KRITIS operators must run attack detection systems for the IT that their critical facilities depend on | § 31 BSIG |
| Proof for KRITIS | KRITIS operators prove their measures to the BSI every three years through audits, examinations or certifications | § 39 BSIG |
| Fines | Up to EUR 10 million for particularly important entities and EUR 7 million for important entities for the most serious violations. Above EUR 500 million in annual turnover, the cap is up to 2% (particularly important) or 1.4% (important) of total annual turnover. Lower caps apply to other violations. | § 65 BSIG |
For SaaS vendors, scope is the big change. Sectors listed in the annexes, including digital infrastructure and ICT service management, can bring a mid-sized cloud or managed service provider into scope without it being a KRITIS operator. Read the sector annexes and the BSI's NIS2 FAQ carefully, because sector and size definitions are where companies most often get it wrong.
For the EU-level background, read From NIS to NIS 2. If you already run an ISMS, our guide to ISO 27001 and NIS 2 shows where your existing controls already cover NIS2 and where they do not.
Are hospitals and health insurers in scope?
Many are. Healthcare is a KRITIS sector, and a hospital becomes a KRITIS operator when it exceeds the thresholds set by ordinance, which are based on the scale of care it provides. Under the current BSI Act, hospitals below the KRITIS line can still be particularly important or important entities if they meet the sector and size criteria. German social law separately expects hospitals to maintain appropriate IT security, so even smaller hospitals now ask vendors serious security questions.
Health insurers sit in a more complex position. Depending on the type of insurer, its size and the services it runs, it may fall under KRITIS rules, under other supervisory regimes or under the NIS2 entity categories. Utilities are clearer: energy and water operators above the thresholds are classic KRITIS operators.
What this means for suppliers:
- Your product may be part of a critical service. If a hospital's patient admissions, lab results or medication workflows depend on your platform, its auditors will treat you as part of its attack surface.
- Security requirements arrive as contract clauses. Expect clauses on state of the art security, incident notification within short windows, cooperation with audits, logging and data location.
- Monitoring expectations flow down. Because KRITIS operators must run attack detection, they want to know what logs you keep, how long you keep them and whether you can share relevant security events with them.
- Reporting clocks flow down. A customer with a 24-hour early warning duty needs to hear from you well inside that window.
We do not list specific KRITIS threshold figures here because they are set by ordinance and can change. Confirm the current values with the BSI or the customer's compliance team.
Regulated entity vs supplier: who has which obligations?
The regulated entity carries the legal duties, and the supplier carries the contractual ones that make those legal duties achievable. This table summarizes the split.
| Area | Regulated entity (legal duty under the BSI Act) | SaaS or HealthTech supplier (typical contractual expectation) |
|---|---|---|
| Registration | Register with the BSI within three months of falling into scope | Name a security contact and keep it current |
| Security measures | Implement risk management measures according to the state of the art | Maintain a documented security program, often evidenced by ISO 27001 or SOC 2 |
| Attack detection | KRITIS operators run attack detection systems | Provide security logs, alerting and monitoring that support the customer's detection |
| Incident reporting | Report significant incidents to the BSI within 24 hours, 72 hours and one month | Notify the customer quickly, often within hours, and support its investigation |
| Proof of compliance | KRITIS operators prove measures to the BSI every three years | Share certificates, audit reports and pen test summaries, and accept audit rights |
| Supply chain | Manage risks from suppliers and service providers | Manage your own subprocessors and disclose them |
| Management | Management approves, oversees and trains on cybersecurity | Show management oversight of your own program |
| Penalties | Regulatory fines and BSI orders | Contract penalties, termination or lost renewals |
If your company is large enough and operates in a listed sector, you may be a regulated entity yourself. Do not assume supplier status means you are exempt.
Supplier readiness checklist: what evidence do German buyers expect?
German critical infrastructure buyers expect evidence that maps cleanly to their own legal duties, and ISO 27001 or SOC 2 already produces most of it. Use this checklist to prepare before the security review starts.
| Buyer expectation | ISO 27001 evidence | SOC 2 evidence |
|---|---|---|
| A managed security program | ISMS scope, certificate and Statement of Applicability | SOC 2 Type 2 report and system description |
| Risk management | Risk assessment and risk treatment plan | Risk assessment documentation tested under the Common Criteria |
| Logging and attack detection support | Logging and monitoring controls, log retention settings | Monitoring and anomaly detection controls with test results |
| Incident notification | Incident management procedure with customer notification steps | Incident response policy and evidence of tested response |
| Supply chain security | Supplier relationship controls and subprocessor reviews | Vendor management controls and subprocessor list |
| Business continuity | Continuity and ICT readiness controls, recovery tests | Availability criteria, backup and recovery tests |
| Access control | Access control policy, privileged access reviews | Logical access controls and access review evidence |
| Vulnerability management | Technical vulnerability management records, pen test reports | Vulnerability scanning and pen test evidence |
| Management oversight | Management review minutes and internal audit | Board or management oversight evidence in the report |
Then work through these steps:
- Map your customers. List German customers that are hospitals, insurers, utilities or other likely KRITIS or NIS2 entities, and note which ones have sent security clauses.
- Check your own scope. Assess whether your company could be a particularly important or important entity under the current BSI Act based on sector and size. If so, registration has a three-month deadline.
- Standardize your incident clause. Decide what notification window you can reliably meet, keeping your customers' 24-hour early warning duty in mind, and build the process to meet it.
- Package your evidence. Keep certificates, reports, policies and pen test summaries in one place that you can share under NDA.
- Prepare a German context note. A short document explaining how your controls support the customer's BSI Act duties saves hours of back and forth.
- Consider BSI C5. If you host data for German public sector or healthcare buyers, a BSI C5 attestation may be requested alongside ISO 27001.
How SecureSlate helps
SecureSlate helps SaaS and HealthTech teams organize the evidence German buyers ask for. Multi-framework mapping links one control library to ISO 27001, SOC 2 and NIS2, which helps you reuse work across buyer reviews. It does not determine whether you are in scope under the BSI Act or replace legal advice. Continuous control monitoring and automated evidence collection keep logging, access and vulnerability evidence current. Policy templates cover incident response, supplier security and business continuity. Vendor risk management tracks your own subprocessors, and a trust center lets hospital and utility buyers request your certificates and reports without waiting on email threads.
Start your free SecureSlate trial
FAQ
Is the German IT Security Act 2.0 still in force?
IT-SiG 2.0 was an amending law from 2021, so its changes lived inside the BSI Act. Germany's NIS2 implementation law rewrote the BSI Act with effect from December 6, 2025. Some IT-SiG 2.0 ideas, such as attack detection for KRITIS operators, carry forward, while others, such as the UBI category and the old fine levels, were replaced. Today's duties come from the current BSI Act.
Does the German BSI Act apply to SaaS vendors?
Usually not directly, unless the vendor is itself a KRITIS operator or a particularly important or important entity under the current BSI Act, for example as a mid-sized or large provider in a listed digital sector. Most SaaS vendors are affected indirectly, because their regulated customers must manage supplier risk and push security requirements into contracts.
What is the difference between KRITIS and NIS2 in Germany?
KRITIS covers operators of critical facilities above thresholds set by ordinance. The NIS2 implementation widened the BSI Act to many more mid-sized and large organizations across more sectors, grouped as particularly important and important entities. KRITIS operators automatically count as particularly important entities and carry extra duties such as attack detection and three-yearly proof to the BSI.
Do German hospitals require ISO 27001 from their vendors?
There is no single legal rule requiring it, but ISO 27001 is one of the most widely accepted forms of evidence in German healthcare procurement. Some buyers also ask for a SOC 2 report, a BSI C5 attestation for cloud services or answers to their own questionnaire.
What are the fines under the German BSI Act today?
Under § 65 BSIG, the most serious violations can cost particularly important entities up to EUR 10 million and important entities up to EUR 7 million. For entities with annual turnover above EUR 500 million, the cap is up to 2% or 1.4% of total annual turnover respectively. Other violations carry lower caps. The 2021 IT-SiG 2.0 fine levels no longer apply.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds