Back to Cybersecurity

German IT Security Act 2.0 and NIS2: What SaaS and HealthTech Suppliers Need to Know

German IT Security Act 2.0 illustration: a hospital, power plant and server linked by dashed supply lines beside a shield

Short answer: The German IT Security Act 2.0 (IT-SiG 2.0) is a 2021 law that amended the BSI Act, expanded the powers of the Federal Office for Information Security (BSI) and tightened duties for critical infrastructure (KRITIS) operators. In December 2025, Germany's NIS2 implementation law rewrote the BSI Act on top of that foundation, so today's obligations come from the new BSI Act, not from the 2021 text. SaaS and HealthTech vendors are rarely regulated directly, but their hospital, insurer and utility customers pass these requirements down through contracts and security reviews, and some vendors are now in scope themselves.

Related guides:

Key takeaways

  • IT-SiG 2.0 took effect in 2021. It gave the BSI more powers, added municipal waste management as a critical sector, created the "companies in the special public interest" (UBI) category and raised fines.
  • Germany's NIS2 implementation law was signed on December 2, 2025, published in the Federal Law Gazette (BGBl. 2025 I Nr. 301) on December 5, 2025 and took effect on December 6, 2025. It replaced the old BSI Act structure with a new BSI Act.
  • The current law sorts organizations into particularly important entities and important entities. KRITIS operators automatically count as particularly important entities and carry extra duties, including attack detection systems.
  • The UBI category from IT-SiG 2.0 no longer exists. Former UBI companies must check for themselves whether they fall under the new categories.
  • Regulated entities must register with the BSI within three months of falling into scope and report significant incidents within 24 hours, 72 hours and one month.
  • For the most serious violations, maximum fines are now up to EUR 10 million for particularly important entities and EUR 7 million for important entities. Only above EUR 500 million in annual turnover does the cap become 2% or 1.4% of total annual turnover respectively.
  • Suppliers usually feel the law through procurement: security clauses, questionnaires, audit rights and incident notification duties in the contract. An ISO 27001 certificate or SOC 2 report, plus a clear incident and logging story, answers most of what these buyers ask.

What was the German IT Security Act 2.0?

IT-SiG 2.0 was the second German IT Security Act, an amending law that updated the BSI Act and related laws to raise the security bar for critical infrastructure and other important companies. The original IT Security Act of 2015 created the KRITIS regime: operators of critical facilities in sectors such as energy, water, health, food, IT and telecommunications, transport and finance had to secure their systems according to the state of the art and report significant disruptions to the BSI.

The second act, in force since 2021, kept that structure and made it stricter. It was not a standalone rulebook. Its changes lived inside the BSI Act (BSIG), the law that sets out the BSI's mandate and the duties of regulated organizations.

That matters today because the BSI Act has since been rewritten again. When people say "IT-SiG 2.0" in 2026, they usually mean the German security regime in general. For contracts and compliance work, the relevant text is the current BSI Act as amended by the NIS2 implementation law.

What did IT-SiG 2.0 change in 2021?

IT-SiG 2.0 broadened who was regulated, gave the BSI more tools and made non-compliance more expensive. The table below describes the 2021 regime. The last column shows where each item stands under the current BSI Act.

2021 change What it meant Status today
Expanded BSI powers Stronger BSI roles in detecting threats, consumer protection and supervising regulated organizations Carried forward and extended
New KRITIS sector Municipal waste management added to the critical infrastructure sectors KRITIS operators remain a distinct group
Companies in the special public interest (UBI) A new category outside KRITIS, such as certain defense-related companies, very large companies of economic significance and operators handling hazardous substances Category removed; affected companies must check whether they are now particularly important or important entities
Attack detection systems KRITIS operators had to use systems to detect attacks, with the obligation applying from May 2023 Still required for KRITIS operators under § 31 BSIG
Registration and reporting KRITIS operators registered with the BSI, named a contact point and reported significant disruptions Replaced by new registration and staged reporting rules for all regulated entities
Critical components The government gained a route to review and, in some cases, prohibit certain critical components in critical infrastructure Still part of the BSI Act framework
Higher fines Maximum fines rose sharply, reaching up to EUR 20 million for companies in some cases Replaced by the NIS2 fine framework described below

What does the current BSI Act require after NIS2?

Germany implemented NIS2 through the Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung, often shortened to NIS2UmsuCG. Rather than creating a separate NIS2 statute, it rewrote the BSI Act. According to the BSI, the number of organizations under BSI supervision rose from about 4,500 to roughly 29,500.

The core rules in the current BSI Act are:

Topic Current rule Source
Entity categories Particularly important entities and important entities, based on sector and size. In the general case, particularly important means at least 250 employees, or annual turnover above EUR 50 million and a balance sheet above EUR 43 million. Important means at least 50 employees, or turnover and balance sheet each above EUR 10 million. Special rules apply to some sectors, such as telecoms and trust services. § 28 BSIG
KRITIS operators Operators of critical facilities count as particularly important entities and keep additional duties § 28, § 31 BSIG
Risk management Appropriate, proportionate technical and organizational measures, including supply chain security § 30 BSIG
Management accountability Management must implement and oversee the measures, take part in regular training and can be personally liable § 38 BSIG
Registration Register with the BSI no later than three months after first falling into scope § 33 BSIG
Incident reporting Early warning within 24 hours, incident notification within 72 hours, final report within one month § 32 BSIG
Attack detection KRITIS operators must run attack detection systems for the IT that their critical facilities depend on § 31 BSIG
Proof for KRITIS KRITIS operators prove their measures to the BSI every three years through audits, examinations or certifications § 39 BSIG
Fines Up to EUR 10 million for particularly important entities and EUR 7 million for important entities for the most serious violations. Above EUR 500 million in annual turnover, the cap is up to 2% (particularly important) or 1.4% (important) of total annual turnover. Lower caps apply to other violations. § 65 BSIG

For SaaS vendors, scope is the big change. Sectors listed in the annexes, including digital infrastructure and ICT service management, can bring a mid-sized cloud or managed service provider into scope without it being a KRITIS operator. Read the sector annexes and the BSI's NIS2 FAQ carefully, because sector and size definitions are where companies most often get it wrong.

For the EU-level background, read From NIS to NIS 2. If you already run an ISMS, our guide to ISO 27001 and NIS 2 shows where your existing controls already cover NIS2 and where they do not.

Are hospitals and health insurers in scope?

Many are. Healthcare is a KRITIS sector, and a hospital becomes a KRITIS operator when it exceeds the thresholds set by ordinance, which are based on the scale of care it provides. Under the current BSI Act, hospitals below the KRITIS line can still be particularly important or important entities if they meet the sector and size criteria. German social law separately expects hospitals to maintain appropriate IT security, so even smaller hospitals now ask vendors serious security questions.

Health insurers sit in a more complex position. Depending on the type of insurer, its size and the services it runs, it may fall under KRITIS rules, under other supervisory regimes or under the NIS2 entity categories. Utilities are clearer: energy and water operators above the thresholds are classic KRITIS operators.

What this means for suppliers:

  1. Your product may be part of a critical service. If a hospital's patient admissions, lab results or medication workflows depend on your platform, its auditors will treat you as part of its attack surface.
  2. Security requirements arrive as contract clauses. Expect clauses on state of the art security, incident notification within short windows, cooperation with audits, logging and data location.
  3. Monitoring expectations flow down. Because KRITIS operators must run attack detection, they want to know what logs you keep, how long you keep them and whether you can share relevant security events with them.
  4. Reporting clocks flow down. A customer with a 24-hour early warning duty needs to hear from you well inside that window.

We do not list specific KRITIS threshold figures here because they are set by ordinance and can change. Confirm the current values with the BSI or the customer's compliance team.

Regulated entity vs supplier: who has which obligations?

The regulated entity carries the legal duties, and the supplier carries the contractual ones that make those legal duties achievable. This table summarizes the split.

Area Regulated entity (legal duty under the BSI Act) SaaS or HealthTech supplier (typical contractual expectation)
Registration Register with the BSI within three months of falling into scope Name a security contact and keep it current
Security measures Implement risk management measures according to the state of the art Maintain a documented security program, often evidenced by ISO 27001 or SOC 2
Attack detection KRITIS operators run attack detection systems Provide security logs, alerting and monitoring that support the customer's detection
Incident reporting Report significant incidents to the BSI within 24 hours, 72 hours and one month Notify the customer quickly, often within hours, and support its investigation
Proof of compliance KRITIS operators prove measures to the BSI every three years Share certificates, audit reports and pen test summaries, and accept audit rights
Supply chain Manage risks from suppliers and service providers Manage your own subprocessors and disclose them
Management Management approves, oversees and trains on cybersecurity Show management oversight of your own program
Penalties Regulatory fines and BSI orders Contract penalties, termination or lost renewals

If your company is large enough and operates in a listed sector, you may be a regulated entity yourself. Do not assume supplier status means you are exempt.

Supplier readiness checklist: what evidence do German buyers expect?

German critical infrastructure buyers expect evidence that maps cleanly to their own legal duties, and ISO 27001 or SOC 2 already produces most of it. Use this checklist to prepare before the security review starts.

Buyer expectation ISO 27001 evidence SOC 2 evidence
A managed security program ISMS scope, certificate and Statement of Applicability SOC 2 Type 2 report and system description
Risk management Risk assessment and risk treatment plan Risk assessment documentation tested under the Common Criteria
Logging and attack detection support Logging and monitoring controls, log retention settings Monitoring and anomaly detection controls with test results
Incident notification Incident management procedure with customer notification steps Incident response policy and evidence of tested response
Supply chain security Supplier relationship controls and subprocessor reviews Vendor management controls and subprocessor list
Business continuity Continuity and ICT readiness controls, recovery tests Availability criteria, backup and recovery tests
Access control Access control policy, privileged access reviews Logical access controls and access review evidence
Vulnerability management Technical vulnerability management records, pen test reports Vulnerability scanning and pen test evidence
Management oversight Management review minutes and internal audit Board or management oversight evidence in the report

Then work through these steps:

  1. Map your customers. List German customers that are hospitals, insurers, utilities or other likely KRITIS or NIS2 entities, and note which ones have sent security clauses.
  2. Check your own scope. Assess whether your company could be a particularly important or important entity under the current BSI Act based on sector and size. If so, registration has a three-month deadline.
  3. Standardize your incident clause. Decide what notification window you can reliably meet, keeping your customers' 24-hour early warning duty in mind, and build the process to meet it.
  4. Package your evidence. Keep certificates, reports, policies and pen test summaries in one place that you can share under NDA.
  5. Prepare a German context note. A short document explaining how your controls support the customer's BSI Act duties saves hours of back and forth.
  6. Consider BSI C5. If you host data for German public sector or healthcare buyers, a BSI C5 attestation may be requested alongside ISO 27001.

How SecureSlate helps

SecureSlate helps SaaS and HealthTech teams organize the evidence German buyers ask for. Multi-framework mapping links one control library to ISO 27001, SOC 2 and NIS2, which helps you reuse work across buyer reviews. It does not determine whether you are in scope under the BSI Act or replace legal advice. Continuous control monitoring and automated evidence collection keep logging, access and vulnerability evidence current. Policy templates cover incident response, supplier security and business continuity. Vendor risk management tracks your own subprocessors, and a trust center lets hospital and utility buyers request your certificates and reports without waiting on email threads.

Start your free SecureSlate trial

FAQ

Is the German IT Security Act 2.0 still in force?

IT-SiG 2.0 was an amending law from 2021, so its changes lived inside the BSI Act. Germany's NIS2 implementation law rewrote the BSI Act with effect from December 6, 2025. Some IT-SiG 2.0 ideas, such as attack detection for KRITIS operators, carry forward, while others, such as the UBI category and the old fine levels, were replaced. Today's duties come from the current BSI Act.

Does the German BSI Act apply to SaaS vendors?

Usually not directly, unless the vendor is itself a KRITIS operator or a particularly important or important entity under the current BSI Act, for example as a mid-sized or large provider in a listed digital sector. Most SaaS vendors are affected indirectly, because their regulated customers must manage supplier risk and push security requirements into contracts.

What is the difference between KRITIS and NIS2 in Germany?

KRITIS covers operators of critical facilities above thresholds set by ordinance. The NIS2 implementation widened the BSI Act to many more mid-sized and large organizations across more sectors, grouped as particularly important and important entities. KRITIS operators automatically count as particularly important entities and carry extra duties such as attack detection and three-yearly proof to the BSI.

Do German hospitals require ISO 27001 from their vendors?

There is no single legal rule requiring it, but ISO 27001 is one of the most widely accepted forms of evidence in German healthcare procurement. Some buyers also ask for a SOC 2 report, a BSI C5 attestation for cloud services or answers to their own questionnaire.

What are the fines under the German BSI Act today?

Under § 65 BSIG, the most serious violations can cost particularly important entities up to EUR 10 million and important entities up to EUR 7 million. For entities with annual turnover above EUR 500 million, the cap is up to 2% or 1.4% of total annual turnover respectively. Other violations carry lower caps. The 2021 IT-SiG 2.0 fine levels no longer apply.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.9(409 reviews)

Keep reading

Oct 1, 2026 · Cybersecurity

Minimum Viable Secure Product (MVSP): A Practical Checklist for SaaS and HealthTech Startups

Sep 30, 2026 · Cybersecurity

AWS Foundational Technical Review: FTR Checklist and Prep Guide for SaaS Teams

Sep 30, 2026 · Cybersecurity

BSI C5 compliance checklist: how SaaS and cloud providers prepare for a C5 attestation

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?