The new BSI-Portal has been live since January 6, 2026. It requires KRITIS companies and public institutions to report security incidents centrally in accordance with NIS2. At the same time, organizations must complete registration within three months – by March 6, 2026, at the latest.
NIS2, DORA, and other legally binding regulations show that security incidents are no longer purely an IT issue. Their relevance extends to the management level as well, affecting responsibilities, operational stability, and controllability. Organizations that take early preventive measures gain confidence, transparency, and control, while others lose time, delay decisions, and take risks in an emergency.
Are you obliged to register, and where are potential pitfalls?
In companies, typical situations arise from factors such as
- Identifying whether you need to register vs. uncertainty about obligations. Example: A medium-sized customer was uncertain whether its organization was considered critical infrastructure. We helped identify the obligations and plan the registration process in a structured manner.
-
Lack of process and document overview. Example: In an emergency, a government agency couldn't quickly prove that all procedures were in place. With Empalis, the processes were structured and evidence was prepared – legal reporting deadlines can now be met without any problems.
-
Backup and emergency plans not coordinated. Example: A company had plans in place, but they weren't aligned with legal reporting requirements. We showed how compliance and operational resilience can be integrated.
-
Undefined responsibilities. Example: In a large organization, the roles of reporting and documentation in an emergency were undefined. Empalis outlined roles and procedures so that decisions could be made quickly, transparently, and in compliance with regulations.
A systematic overview helps identify the current status and address requirements in a targeted manner.
Overview: Deadlines and reporting requirements at a glance
Three-month registration period: March 6, 2026, at the latest
Reporting requirements for security incidents:
- Initial report within 24 hours
- Detailed interim report within 72 hours
- Final report within one month
All information on registration can be found at the BSI-Portal.
After completing the preparation, you can proceed directly to registration here:
Do you have questions about your status regarding the reporting obligation or other concerns regarding registration with the BSI? Please feel free to contact me.
Michael Melcher, Senior Consultant
Phone +4916098526034
How to reduce security risks in an emergency
Early preparation makes the difference between a manageable incident and a critical operational risk. KRITIS companies and public institutions are required to integrate legal requirements, security processes, and resilience measures.
- Structured preparation: Clarity about obligations, deadlines, and reporting processes.
- Confidence in action: Incident response, emergency, and reporting processes are prepared in a practical manner so that organizations can react quickly in an emergency.
- Legally compliant and resilient: Compliance is maintained, liability risks are reduced, and reputation is protected.
Integration of backups and emergency plans: Organizations remain fully operational even in the event of security incidents. - Transparency and control: Responsibilities and processes are clearly defined, facilitating decision-making at the management level.
Conclusion for KRITIS operators
By proactively managing today's risks while strengthening their resilience, organizations gain a holistic level of maturity in terms of cyber and compliance security, clear processes, and their efficient implementation.