Germany NIS-2 Implementation Act Strengthens Cybersecurity
ID: eb8cdf85-264c-5f9c-891a-1179d20122d7
STIX ID: report--eb8cdf85-264c-5f9c-891a-1179d20122d7
Feed Name: Cyble Blog
Germany's NIS-2 Implementation Act (in force 6 Dec 2025) significantly expands national cybersecurity regulation—raising the number of regulated entities from ~4,500 to ~30,000—and requires registration with the BSI and BBK within three months, mandatory incident reporting (initial within 24 hours, update within 72 hours, final within 30 days), binding security measures (risk and vulnerability management, MFA, supply-chain security, logging), and substantial fines and potential personal liability for management; the law integrates with EU frameworks (DORA, Cyber Resilience Act, CER) and gives organizations until April 2026 to prepare, with the report also including vendor (Cyble) promotional material.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
