Command of the German regulatory framework — BSI, IT-Grundschutz, NIS2UmsuCG — for industrial and financial companies and critical infrastructure operators.
Last updated — August 22, 2026
Germany's cybersecurity framework is overseen by the Bundesamt für Sicherheit in der Informationstechnik (BSI), the federal reference authority for information systems security. The IT-Grundschutz framework, developed by the BSI, is the national reference methodology for information security management, structured around catalogs of organizational and technical measures applicable according to the required protection level. The NIS2 transposition law, the NIS2UmsuCG, substantially broadens the scope of essential and important entities subject to risk management and incident notification obligations. GDPR also applies to any processing of personal data.
Engagement model
Direct engagement
Methodology
Aligned with IT-Grundschutz (BSI)
Languages
German, English, French
The Bundesamt für Sicherheit in der Informationstechnik (BSI), the federal authority responsible for information systems security.
A methodology developed by the BSI, structured around catalogs of organizational and technical measures used to build and demonstrate an information security level suited to the criticality of the systems concerned.
Germany's law transposing the NIS2 directive, which broadens the scope of essential and important entities subject to risk management and incident notification obligations. This topic has its own dedicated page on this site.
Given the weight of the manufacturing and industrial sector in the German economy, often exposed to industrial control systems (OT) requiring a specific security approach.
Security audits aligned with IT-Grundschutz, industrial systems audits, and GRC compliance for entities subject to the NIS2UmsuCG.
With an initial scoping phase to determine the entity's status under the NIS2UmsuCG and the targeted IT-Grundschutz protection level.