With the official enactment of the NIS-2 Implementation Act, Germany has taken a major step toward modernizing its cybersecurity framework. Starting from 6 December 2025, stricter requirements will apply to both federal administration and thousands of private companies. This law revises the BSI Act (BSIG) and introduces comprehensive obligations for IT security and risk management. The NIS2 Directive is the EU’s updated cybersecurity framework. It requires organizations to implement risk management measures, ensure incident reporting within an initial 24-hour timeline, strengthens supply chain security while introducing management accountability, including personal liability for non-compliance.