What Germany BSI Act and IT Security Act 2.0 (IT-SiG 2.0) 2021 requires
Germany's IT Security Act 2.0 (IT-SiG 2.0), which came into force on May 28, 2021, significantly expands the BSI Act by broadening the definition of critical infrastructure operators, mandating attack detection systems for KRITIS operators since May 2023, requiring 72-hour incident reporting to the BSI for critical infrastructure, extending cybersecurity obligations to federal government IT systems, and imposing penalties of up to EUR 20 million for serious non-compliance by critical infrastructure operators.
Pillar: Cybersecurity · Authority: Bundesamt für Sicherheit in der Informationstechnik (BSI) - Federal Office for Information Security · Version: 1.0.0 · Last updated:
Primary source: https://www.bsi.bund.de
SHA-256 integrity: a147053054ac93487de7949a24250047e8776f25fee641b6f34e47533ca05372
Primary Citations — 6 traced to source
- Gesetz über das Bundesamt für Sicherheit in der Informationstechnik (BSIG) - BSI Act - Germany's primary cybersecurity statute establishing the Federal Office for Information Security and its mandate to protect German IT and critical infrastructure
- IT-Sicherheitsgesetz 2.0 (IT-SiG 2.0) - Second IT Security Act - in force May 28, 2021 - significantly amending the BSI Act to expand KRITIS scope, mandate attack detection systems for KRITIS operators (mandatory from May 2023), extend penalties to up to EUR 20,000,000, and expand BSI's powers
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/de-bsig-it-sig-2-2021.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/de-bsig-it-sig-2-2021.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/de-bsig-it-sig-2-2021
- Back to registry: Browse all 10,085 compliance nodes