Jurisdiction
Region
Requirement
Policy
Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung (NIS-2-Umsetzungsgesetz / NIS2UmsG)
Applies to
Approximately 29,000 entities across NIS2 Annex I (highly critical) and Annex II (other critical) sectors operating in Germany
Provision
§ 30 Absatz 2 Satz 2 Nummer 5 BSIG (as amended by NIS2UmsG) — risk-management measures including "vulnerability handling and disclosure" (transposes NIS2 Directive (EU) 2022/2555 Article 21(2)(e))
Description

Transposes NIS2 Article 21(2)(e): "security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure." The amended BSIG requires "besonders wichtige Einrichtungen" (essential) and "wichtige Einrichtungen" (important) entities to implement appropriate and proportionate technical, operational, and organisational measures, including vulnerability handling and disclosure. The BSI is empowered to coordinate vulnerability disclosure and issue public warnings about IT-product vulnerabilities.

Date
March 6, 2026
Organization
Bundestag; Federal Ministry of the Interior and Community (BMI); Federal Office for Information Security (BSI)
Jurisdiction
Region
Policy
Cyber Security Strategy for Germany 2021
Applies to
Government agencies
Provision
Section 8.1.8
Description
8.1.8 Responding responsibly to vulnerabilities – promoting coordinated vulnerability Our aim is for the Federal Government to develop a framework to ensure that those reporting bugs have legal certainty if they approach companies to inform them that they have become aware of vulnerabilities, with a view to fostering proactive vulnerability governance. There will be reliable points of contact for them to report their findings. These can take the form of internal contact points which companies themselves are obligated to set up, or the BSI as a public liaison office. The legislator will obligate the companies affected to provide points of contact and processes to enable them to fix reported vulnerabilities in a suitable time frame. The extent to which the rights and duties are set out on both sides of the CVD process will be examined. These rights and duties could include a holdback period before making vulnerabilities public or a binding deadline for patches or updates. A coordinated process will be put in place between the BSI and manufacturers which extends beyond the simple exchange of information. This will also apply to vulnerabilities in the IT supply chains of products and services (supply chain security).
Date
2021
Organization
Federal Ministry of the Interior, Building, and Community