Legal obligation
Critical/important entity registration (BSIG)
Critical/important entity registration (BSIG) — legal obligation, Germany. It binds entities classed "besonders wichtige Einrichtungen" (especially important) or "wichtige Einrichtungen" (important) — thresholds: 250+ employees and €50m+ turnover with €43m+ balance sheet for the "especially important" tier, 50+ employees and €10m+ turnover/balance sheet for the "important" tier — plus domain-registry providers.
- Jurisdiction
- Germany
- Record class
- Legal obligation
- Instrument
- Registration
- Last verified
Where this applies
This record is scoped to Germany. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.
Instrument
BSI-Gesetz (BSIG), §33; penalty ceilings §65
Who it binds
Entities classed "besonders wichtige Einrichtungen" (especially important) or "wichtige Einrichtungen" (important) — thresholds: 250+ employees and €50m+ turnover with €43m+ balance sheet for the "especially important" tier, 50+ employees and €10m+ turnover/balance sheet for the "important" tier — plus domain-registry providers
What it requires
Covered entities must register with the Federal Office for Information Security (BSI) within 3 months, and notify changes within 2 weeks. The BSIG (Ausfertigung 2 December 2025, BGBl 2025 I Nr. 301, in force 6 December 2025) sets penalty ceilings up to €10 million or, for the more serious tier, up to €7 million, with turnover-based alternative ceilings of 2% and 1.4% of worldwide annual turnover for entities above €500 million turnover; the precise mapping from violation type to ceiling tier is not published in this record.
Route to the authority
Last verified:
This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.