Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity services — Germany

Command of the German regulatory framework — BSI, IT-Grundschutz, NIS2UmsuCG — for industrial and financial companies and critical infrastructure operators.

Last updatedAugust 22, 2026

The local regulatory framework

Germany's cybersecurity framework is overseen by the Bundesamt für Sicherheit in der Informationstechnik (BSI), the federal reference authority for information systems security. The IT-Grundschutz framework, developed by the BSI, is the national reference methodology for information security management, structured around catalogs of organizational and technical measures applicable according to the required protection level. The NIS2 transposition law, the NIS2UmsuCG, substantially broadens the scope of essential and important entities subject to risk management and incident notification obligations. GDPR also applies to any processing of personal data.

Concrete obligations

Application of the BSI's IT-Grundschutz methodology for information security management

Anticipation of obligations arising from the NIS2UmsuCG for essential and important entities

GDPR compliance for any processing of personal data

Alignment of security practices with the BSI's catalogs of measures and technical recommendations

Priority sectors

Industry & manufacturingFinanceEnergy

Delivery modalities

Engagement model

Direct engagement

Methodology

Aligned with IT-Grundschutz (BSI)

Languages

German, English, French

Local FAQ

What is the reference cybersecurity authority in Germany?

The Bundesamt für Sicherheit in der Informationstechnik (BSI), the federal authority responsible for information systems security.

What is IT-Grundschutz?

A methodology developed by the BSI, structured around catalogs of organizational and technical measures used to build and demonstrate an information security level suited to the criticality of the systems concerned.

What is the NIS2UmsuCG?

Germany's law transposing the NIS2 directive, which broadens the scope of essential and important entities subject to risk management and incident notification obligations. This topic has its own dedicated page on this site.

Why is the industrial sector a priority in Germany?

Given the weight of the manufacturing and industrial sector in the German economy, often exposed to industrial control systems (OT) requiring a specific security approach.

What services are most requested in Germany?

Security audits aligned with IT-Grundschutz, industrial systems audits, and GRC compliance for entities subject to the NIS2UmsuCG.

How does an engagement in Germany typically start?

With an initial scoping phase to determine the entity's status under the NIS2UmsuCG and the targeted IT-Grundschutz protection level.

Get in touch