On 24 July 2024, the German government passed the NIS-2 Implementation and Cyber Security Strengthening Act (NIS2UmsuCG). Around 30,000 companies in Germany will thus be subject to stricter IT security precautions.
The Directive on measures for a high common level of cybersecurity across the EU (Network and Information Security 2, or NIS-2 for short) came into force on 16 January 2023. As this is a directive, it must be transposed into national law; this will be done in Germany by the NIS2UmsuCG. According to the German government, this will comprehensively modernise and restructure German IT security law. The two categories of "important organisations" and "particularly important organisations" will be introduced, which will be accompanied by a significant expansion of the scope of application previously limited to operators of critical infrastructures, providers of digital services and companies in the special public interest. This includes a catalogue of minimum security requirements, including mandatory risk analysis concepts, measures to maintain operations, backup management and concepts for the use of encryption. The previous one-stage reporting obligation for cyber security incidents will be replaced by a three-stage reporting system; an initial report is to be submitted within 24 hours, an update within 72 hours and a final report within one month. Section 38 NIS2UmsuCG harbours particular risks. According to this, the management of companies must approve the specific measures to be taken as suitable and continuously monitor their implementation; even if auxiliary persons are involved, the management body remains ultimately responsible and can be held personally liable for breaches of duty.
In order to inform potentially affected companies, the Federal Office for Information Security (BSI) has published support services. An impact assessment contains specific yes/no questions based on NIS-2 in order to categorise companies into four categories: Critical Infrastructure Operators, Particularly Important Organisations, Important Organisations and Unaffected Companies. A FAQ catalogue was also presented; it includes questions and answers on the most important NIS-2 topics, such as affectedness, contact points and legal obligations. "The threat level in the area of cyber security remains high," said Federal Minister of the Interior Nancy Faeser. "With our law, we are increasing protection against cyber attacks, regardless of whether they are state-directed or criminally motivated. In future, more companies in more sectors will have to fulfil minimum requirements for cyber security and reporting obligations in the event of cyber incidents." According to BSI President Claudia Plattner, around 29,500 companies in Germany will be obliged to implement cyber security measures in future. "They guarantee the security of supply for the population and form the backbone of Germany as a cyber nation. The BSI will therefore provide them with the best possible support and make the implementation of the legal requirements as smooth as possible." However, the NIS2UmsuCG will not be a sure-fire success within the traffic light government. According to heise.de, Konstantin von Notz, deputy leader of the Green parliamentary group, criticised the draft and announced that parliament would now deal with the law "very intensively" in the further process.
Meanwhile, the lawyer Fabricio Vayra from the international law firm Perkins Coie LLP called on the internet administration ICANN once again to harmonise the WHOIS system with Article 28 of NIS-2. Although the provisions of NIS-2 will come into force in most EU member states on 18 October 2024, it is still unclear what is required of registries and registrars. However, it is time to tackle the implementation of Article 28 with the same passion with which ICANN drove the harmonisation of the GDPR and WHOIS in 2018. It is not enough to place the responsibility solely on the registries and registrars.
You can find the federal government's draft law at:
https://www.bmi.bund.de/SharedDocs/gese ... onFile&v=1
You can find the article by Fabricio Vayra at:
https://circleid.com/posts/20240725-har ... article-28