Germany prepares firms for NIS-2 cyber‑security rules with BSI webinars and ISMS guidance
From December 2025 the EU NIS‑2 directive is incorporated into German law, imposing new registration, incident‑reporting and risk‑management duties on a wide range of organisations. The Federal Office for Information Security (BSI) is organising two free online seminars in July 2026 – on 8 July and 16 July – with experts from the cybersecurity sector, legal field and BSI itself to explain how companies can meet these obligations and document their measures.
At the same time, German businesses, especially small and medium‑sized firms, are urged to adopt an information‑security‑management system (ISMS) to turn the regulatory requirements into a lasting security culture. Industry experts note that many firms struggle with the resources and clarity needed for effective ISMS implementation, but that a well‑run system can streamline processes, clarify responsibilities and reduce cyber‑risk under the NIS‑2 framework.