BSI
Federal Office for Information Security (Germany)
Bundesamt für Sicherheit in der Informationstechnik
The BSI is Germany's central authority for cybersecurity, headquartered in Bonn. It shapes information security for the state, the economy and society, issues standards such as IT-Grundschutz, operates national incident coordination via CERT-Bund and is the central supervisory, registration and reporting body for KRITIS and NIS2. For German organisations it is the authoritative governmental reference.
History & facts. The BSI was founded in 1991 and has evolved from a rather technical body into a shaping national cybersecurity authority. It publishes widely used methods and guidelines — from IT-Grundschutz through the IT forensics guideline to minimum standards and technical guidelines — and plays a key role under the reformed BSI Act in implementing NIS2. NIS2 supervision is centralised: unlike under the GDPR, there is a single nationwide point of contact.
Contact & reporting. Service centre: 0800 274 1000 (free from German landline and mobile networks), e-mail service-center@bsi.bund.de, reachable Mon-Thu 08:00-17:00 and Fri 08:00-16:00; headquartered in Bonn. NIS2 registration and the reporting of significant security incidents run through the BSI portal (portal.bsi.bund.de) — access requires an ELSTER organisation certificate via „Mein Unternehmenskonto“ (MUK). In the portal an incident is submitted via the „report security incident“ button; the deadlines of 24-hour early warning, 72-hour notification and one-month final report apply. (Please verify the current state on bsi.bund.de before reporting, as portals and deadlines can change.)
Outlook & recommendation. With the entry into force of the NIS2UmsuCG, the BSI has become, for thousands of newly affected entities, not a distant standard-setter but the direct supervisory and reporting authority. Those not yet registered should remedy this immediately and prepare MUK/ELSTER early. NEOSEC supports clients along these requirements — from applicability and gap analysis to the reporting chain towards the BSI.