Country guide

Rail cyber security regulations in Germany

Germany has brought its NIS2 implementation law into force. Rail organisations need to assess their classification under the updated BSI framework, while recognising that critical-infrastructure obligations and NIS2 entity categories are not interchangeable. The practical task is to connect the legal entity, essential rail services and supporting systems to a documented security programme.

Official sources checked

Who needs to consider these requirements?

For a German rail group, assess the operating and infrastructure entities separately before combining evidence at group level. Suppliers should understand which operator requirements affect product support, maintenance connections and incident escalation. A shared security tool can support several contracts, but does not by itself establish that each regulated entity has met its duties.

Key regulations and frameworks

German NIS2 implementation law

Law — in force from 6 December 2025

The official federal gazette publishes Germany's NIS2 implementation legislation. The revised framework introduces requirements for covered important and particularly important entities. Rail applicability should be assessed against the transport categories and the law's size, activity and special-case provisions. Do not use an old KRITIS threshold assessment as the sole test of whether the updated regime applies.

Official source: German NIS2 implementation law

BSI registration and reporting route

Official implementation instructions

BSI confirms that the implementation law entered into force on 6 December 2025. Its instructions direct NIS2 registration and incident reporting to the BSI Portal. The older MIP service remains relevant for specified transitional uses; teams should follow BSI's instructions for their category rather than assuming their previous reporting account covers the new process.

Official source: BSI registration and reporting route

Practical steps for rail teams

Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.

  1. Document the entity's classification and registration owner, then verify that the responsible team can access the correct BSI reporting service before an incident occurs.
  2. Create an evidence trail from operational risk to controls on train, wayside and maintenance networks. Record justified exceptions for legacy systems and the compensating measures used.
  3. Align supplier escalation with the operator's reporting process. Rehearse collecting a useful initial incident assessment while engineering teams continue safe service recovery.

Using this guide

This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.