Germany’s NIS2 Transport Rules: What DB InfraGO, the Port of Hamburg, and ERA’s CCS Standard Mean for Your BSIG Compliance
A regional rail operator in Germany can be a "wichtige Einrichtung" under one paragraph of the BSI-Gesetz and, a few lines later, fall under a completely separate registration track as a KRITIS-Betreiber — with two different authorities, two different deadlines, and two different obligation sets running at the same time. Most transport compliance teams size themselves against NIS2’s general thresholds and stop there, missing the second track entirely. Germany’s transport sector runs on three interlocking classification tiers, not one, and the technical rulebook that governs rail signalling — ERA’s Control-Command and Signalling TSI — is routinely, and incorrectly, assumed to double as the sector’s cybersecurity law. It doesn’t. This guide separates what BSIG actually requires from what the signalling and interoperability rules actually say, using Germany’s own named entities and thresholds.
Does Germany’s NIS2 Transport Sector Apply to You?
NIS2 treats transport as a "high criticality" sector under Annex I, which means qualifying operators are assessed for essential-entity status first and important-entity status second — there is no low-obligation default for this sector. Annex I names the entity types directly: air transport (air carriers, airport managing bodies, traffic management control operators), rail transport (infrastructure managers, railway undertakings), water transport (inland, sea and coastal passenger and freight companies, port managing bodies), and road transport (traffic-management road authorities, intelligent transport system operators) [1]. Germany’s BSIG (BSI-Gesetz) transposes this into five operative sub-sectors, plus two adjacent categories the German framework adds on top of the EU baseline.
| Sub-sector | Typical entities | German threshold basis |
|---|---|---|
| Rail | Infrastructure managers, railway undertakings, freight yards | TEN-V core network segment; ~23,000 outgoing trains/year for yards |
| Water / Ports | Port managing bodies, facilities operating within ports | 50 million tonnes of cargo/year |
| Road | Federal motorway (Bundesautobahn) traffic authorities, ITS operators | Network-wide system, not per-operator |
| Air | Airport managing bodies, air carriers, reservation systems | 20 million passengers or bookings/year |
| Logistics | Freight/parcel centres and control operations | 17.55 million tonnes or 53.2 million shipments/year |
These sub-sector thresholds, drawn from the KRITIS-Verordnung, decide whether an operator crosses into the third and strictest classification tier — not just whether it counts as essential or important [2][3]. A useful first test: does your organisation own or operate the physical asset (track, terminal, motorway control system), or does it merely use it as a customer? NIS2’s transport entity list targets operators and infrastructure managers, not general freight customers or individual carriers below the relevant size thresholds. See our broader NIS2 scope guide and essential vs. important entity breakdown if you’re still establishing baseline applicability before working through the transport-specific detail below.
Germany’s Three-Tier Classification: How BSIG Stacks Obligations for Transport Operators
Where most EU member states run a two-tier essential/important system, Germany’s BSIG effectively runs three. Under §28 BSIG, operators of critical facilities (Betreiber kritischer Anlagen) are automatically classified as "besonders wichtige Einrichtungen" (especially important entities) regardless of headcount or revenue — size thresholds never enter the analysis for this group [4]. Everyone else in a transport sub-sector is sorted by conventional size criteria into either the especially-important or important tier.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
| Tier | Who qualifies | Trigger |
|---|---|---|
| Critical facility operator (KRITIS-Betreiber) | Any operator crossing a sector-specific KRITIS-Verordnung threshold | Asset-based, no size test |
| Especially important entity | ≥250 FTE, or >€50M revenue and >€43M balance sheet, in an Annex I sector | Size-based |
| Important entity | ≥50 FTE, or >€10M revenue/balance sheet, in an Annex I or II sector | Size-based |
The part competing guides consistently miss: these tiers stack rather than substitute for one another. A large rail infrastructure manager that also crosses a KRITIS-Verordnung threshold is simultaneously an "especially important entity" under §28(1) BSIG (BSI registration, Article 21(2)-equivalent risk-management duties, 24-hour incident reporting) and a KRITIS-Betreiber under the separate KRITIS-Dachgesetz, Germany’s critical-facilities framework that entered into force on 17 March 2026 [5]. That second track brings its own registration requirement with the BBK (Federal Office of Civil Protection and Disaster Assistance) and physical-resilience obligations that sit outside BSIG entirely. Treating the BSI registration as the finish line is the single most common gap we see in transport-sector self-assessments.
DB InfraGO and Rail: Infrastructure Manager vs. Railway Undertaking
Annex I’s rail category splits "infrastructure managers" from "railway undertakings" as two separate entity types [1] — and Germany’s own corporate structure makes that split concrete rather than abstract. Since 1 January 2024, DB Netz AG and DB Station&Service AG merged into DB InfraGO AG, a Deutsche Bahn subsidiary that now holds the infrastructure-manager role for roughly 33,400km of network route length [6]. DB InfraGO, not the Deutsche Bahn group as a whole, is the entity assessed against the rail infrastructure-manager thresholds — principally whether its network includes the German portion of the TEN-V core network and its associated control system.
Railway undertakings — the operating companies running passenger and freight services on that infrastructure, such as DB Fernverkehr, DB Cargo, and regional concession holders — are assessed separately, typically against the general BSIG size thresholds rather than a rail-specific asset test. Freight yards face their own operational threshold, cited by German KRITIS guidance at roughly 23,000 outgoing trains per year [2]. For any group with a separated infrastructure/operations structure — increasingly the norm following EU rail-liberalisation rules — this means a single corporate group can carry two, three, or more distinct BSIG classifications across its subsidiaries, each requiring its own scope determination rather than one group-wide answer.
ERA’s CCS TSI vs. NIS2 Article 21(2): Where Signalling Rules and Cybersecurity Law Actually Meet
A specific and recurring error in vendor content on this topic: describing ERA’s Control-Command and Signalling TSI as if it were itself a cybersecurity regulation. It isn’t. The CCS TSI — currently Commission Implementing Regulation (EU) 2023/1695, amended by Regulation (EU) 2026/693 — governs the technical interoperability of on-board and trackside signalling subsystems (ERTMS/ETCS): compatibility between baselines, migration rules, and application guidance for manufacturers and infrastructure managers [7]. Reviewing ERA’s own published TSI material turns up no embedded cybersecurity risk-management clauses and no cross-reference to NIS2 [7].
The actual legal cybersecurity obligation for a rail infrastructure manager’s signalling systems comes from NIS2 Article 21(2), not the TSI. Germany’s especially-important and important rail entities must apply all ten Article 21(2) measure categories to their network and information systems — which, for an infrastructure manager, includes the CCS/ERTMS estate [8]. In practice, the bridge between that legal obligation and a signalling engineer’s day-to-day work is CENELEC TS 50701, a railway-specific cybersecurity standard built on the IEC 62443 industrial-security series, covering the same RAMS lifecycle the CCS TSI’s own compatibility rules run alongside [9]. Treat TS 50701 as the practical implementation reference and Article 21(2) as the binding legal requirement; the CCS TSI stays in its own lane as a pure interoperability standard.
| Article 21(2) measure | What it looks like for CCS/signalling in practice |
|---|---|
| (e) Secure development, vulnerability handling | Vulnerability disclosure process for ERTMS component suppliers, patch-testing against the safety case |
| (i) Access control, asset management | Asset inventory covering trackside CCS equipment, not just corporate IT |
| (d) Supply chain security | Cybersecurity clauses in signalling-supplier and integrator contracts |
This mapping is our own analysis applying Article 21(2)’s categories to CCS-specific practice — it is not language taken from the TSI or from ERA guidance, since neither source makes this mapping explicit.
Hamburg, Bremen, and Kiel: Ports as Essential Entities
Germany’s water-transport threshold is set at 50 million tonnes of cargo per year for a port’s managing body, and it extends to entities operating facilities and equipment located within the port, not just the harbour authority itself [2]. The Hamburg Port Authority (HPA) is the clearest documented case: HPA is responsible for a 7,145-hectare port area that includes roughly 320km of harbour railway, 140km of public roads, 160km of waterfront, three tunnels, and 147 bridges — and its security lead has described implementing NIS2 and the KRITIS-Dachgesetz’s physical-resilience rules across that combined IT/OT/physical footprint simultaneously as a genuine operational challenge, noting that the legislative drafting doesn’t always anticipate infrastructure this complex [10].
The same cargo-tonnage threshold applies uniformly across Germany’s other major seaports rather than singling out named authorities in the statute itself. Bremen/Bremerhaven’s port system and the Port of Kiel operate at a scale that plausibly brings their own managing bodies into scope on the same basis as Hamburg, but — unlike HPA, where a named implementation case is publicly documented — we did not find a published source confirming a specific classification for those two authorities individually. Any port operator, named here or not, should run its own tonnage figures against the 50-million-tonne threshold rather than relying on a peer authority’s public statements as proof of its own status. See our dedicated maritime cybersecurity compliance guide for the vessel-traffic-service and terminal-operating-system detail this article doesn’t repeat.
Registration, Deadlines, and Penalties: What Transport Operators Must Do Next
Germany’s NIS2UmsuCG entered into force on 6 December 2025 with no transition period, and the BSI registration deadline for in-scope entities was 6 March 2026 [11]. Critical-facility operators face a second, separate registration with the BBK under the KRITIS-Dachgesetz, which itself entered into force on 17 March 2026 [5].
| Step | Effort | Deadline / status |
|---|---|---|
| Determine BSIG tier per entity/subsidiary | Medium | Immediate — underpins every later step |
| BSI registration (MUK/ELSTER + BSI portal) | Low | 6 March 2026 (passed — register now if not done) |
| BBK registration (KRITIS-Betreiber only) | Low | Within 3 months of KRITIS-Dachgesetz obligations applying |
| Implement Article 21(2) measures across IT/OT/signalling | High | No grace period under NIS2UmsuCG |
Penalty exposure follows the standard NIS2 structure once a violation of the Article 21 or 23 obligations is established, and the ceiling is whichever figure is higher in each case [12]. Board and C-suite readers should note this liability attaches to the management body directly and cannot be delegated to a CISO or outsourced provider.
| Tier | Fine ceiling | Trigger | Enforcement body |
|---|---|---|---|
| Especially important entity | €10,000,000 or 2% of worldwide turnover, whichever is higher | Article 21/23 violations | BSI |
| Important entity | €7,000,000 or 1.4% of worldwide turnover, whichever is higher | Article 21/23 violations | BSI |
| KRITIS-Betreiber (registration/physical-resilience) | Separate KRITIS-Dachgesetz penalty track | Failure to register or meet resilience duties | BBK |
For the incident-reporting timeline itself, see our Article 23 notification guide; for country-level enforcement patterns, our Germany penalties and enforcement guide covers how the BSI has approached fines to date.
Frequently Asked Questions
Is a small regional rail operator automatically an essential entity? Not on size alone. A regional operator below the 50-FTE/€10M threshold and not tied to a KRITIS-Verordnung asset (such as a TEN-V core segment) may fall outside BSIG scope entirely, or land in the important-entity tier if it crosses the lower size threshold. Run the sub-sector threshold test in the scope table above before assuming either outcome.
Does a port terminal operator need to register separately from the port authority? Potentially, yes. BSIG’s port threshold extends to "entities operating facilities and equipment within ports," which can include terminal operators distinct from the harbour authority itself [2]. Each legal entity should be assessed against its own activity and size, not assumed to inherit the port authority’s classification.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- [1] "NIS2 Annex I.2: Transport Sector Cybersecurity Requirements" — AuditFront
- [2] "Sektor Transport und Verkehr in NIS2 und KRITIS" — OpenKRITIS
- [3] "KRITIS-Verordnung 2.0 und kritische Anlagen" (2026 draft figures) — OpenKRITIS
- [4] "§ 28 BSIG — Besonders wichtige Einrichtungen und wichtige Einrichtungen" — gesetze-im-internet.de
- [5] "Flipping the NIS2 Switch: What Germany’s Implementation Means for 2026 Compliance" — Morrison Foerster
- [6] "DB InfraGO" — corporate-structure reference, Wikipedia
- [7] "Control Command and Signalling TSI" — European Union Agency for Railways
- [8] "NIS 2 Directive, Article 21: Cybersecurity risk-management measures" — nis-2-directive.com
- [9] "PD CLC/TS 50701:2023 — Railway applications. Cybersecurity" — en-standard.eu
- [10] "Cyber- und Informationssicherheit: Herausforderungen für KRITIS-Häfen durch die Umsetzungsgesetze NIS 2.0 und CER" — Protekt
- [11] "Germany Implements NIS2: Immediate Effect, Broad Scope, Near-Term Registration" — Reed Smith
- [12] "NIS 2 Directive, Article 34: Penalties" — nis-2-directive.com
- "NIS2 Implementation in Germany (DE NIS2)" (background reference on the §28 tier structure) — OpenKRITIS
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
