Germany
Germany’s NIS2 implementation law entered into force on 6 December 2025.
NIS2 · DACH
Germany and Austria implement NIS2 through national law. Switzerland is outside the EU NIS2 framework and follows its own reporting regime. The key question is therefore not only what applies, but how requirements are managed and evidenced in practice. This overview is for orientation and does not constitute legal advice.
LEGAL CONTEXT
Germany’s NIS2 implementation law entered into force on 6 December 2025.
Austria’s NISG 2026 enters into force on 1 October 2026.
Switzerland is not an EU or NIS2 jurisdiction. Since 1 April 2025, a separate reporting obligation has applied to cyberattacks on critical infrastructure; qualifying incidents must be reported to the NCSC within 24 hours.
ReportAct structures frameworks, controls, evidence, vendor and risk registers, and incident workflows. This creates an operational path from requirement to defensible evidence. I am the commercial point of contact; subject-matter logic and delivery remain with ReportAct.
Explore the ReportAct platform →jan@reportact.comSee the NIS2 workflow in ReportAct ↗OFFICIAL AND PUBLIC SOURCES