Overview and explanation of the reporting points

Alliance for Cyber Security reporting point

Companies and organisations have the opportunity to report a security incident via the reporting form on the website of the Reporting and Information Portal. These reports are used to create a reliable and meaningful picture of the situation, to recognise possible correlations and to be able to initiate appropriate measures or issue warnings on this basis. If you provide contact details, the BSI can get in touch with you on request, subject to availability. However, you are also welcome to submit an anonymous report. In this FAQ list, we explain what a report on an IT security incident should ideally look like.

German Federal reporting point (Bund)

Reports pursuant to Section 4(3) of the BSIG

According to Section 4(3) BSIG (2009), German federal institutions are obliged to inform the BSI immediately if they become aware of information required for the prevention of threats to information technology security. The details of the reporting procedure have been specified in a general administrative regulation. The reporting obligations of the regulation remain in effect until a new administrative regulation is issued pursuant to Section 43(5) of the BSIG (2026).

Baseline data collection pursuant to Section 7 of the BSIG

Pursuant to Section 7 of the BSIG, the BSI is authorized to assess and evaluate the state of information security within the federal administration. In addition to the BSI’s review of federal institutions following the standard revision, Section 7 of the BSIG is implemented through an annual baseline data collection via the MIP.The submitted baseline data survey serves, among other things, as the basis for the planned standard revision and is used to prepare for it in a targeted manner. The results of the annual baseline data survey of all federal institutions are validated by the relevant auditing bodies and are incorporated into the strategic management of information security within the federal administration.

CyberGovSecure Program

CyberGovSecure is the program of measures of the Federal CISO designed to quickly and effectively strengthen information security within the German federal administration. It defines and prioritizes measures, supports their implementation, and ensures transparency regarding progress and effectiveness.

Cyber Security Network reporting point

All registered digital first responders in the cybersecurity network have access to the CSN reporting center. There, they submit digitally anonymized reports on the IT security incidents they have dealt with as part of the CSN. These incident reports are used to create a reliable and comprehensive picture of the situation and are an important indicator of the IT security situation for private individuals in Germany.

KRITIS reporting point

IT Security Act, BSI Act, KRITIS Framework Act and KRITIS Regulation

With the (Act to Increase the Security of Information Technology Systems (IT Security Act)), the federal government has made a regulatory contribution toward making Germany’s critical infrastructures (KRITIS) among the most secure in the world. Particularly in this area—such as electricity and water supply, finance, or food—a failure or disruption of these services would have dramatic consequences for the economy, the government, and society in Germany. In 2026, the regulatory framework was then expanded to include physical protection through the KRITISDachG.

The goal is to improve the resilience and security of operators of critical infrastructure, both in terms of physical security and IT security. To achieve these goals, the responsibilities and authorities of the Federal Office for Civil Protection and Disaster Assistance (BBK) and the Federal Office for Information Security (BSI), among others, have been expanded.

Under current law, facilities are considered critical if they are essential to the provision of a critical service. A service is classified as critical only if it relates to one of the following areas and its failure or disruption would lead to significant supply shortages or a threat to public safety (see Section 2(4) of the KRITISDachG)):

  • Energy
  • Transportation and Traffic
  • Finance
  • Social Security and Basic Income Support for Job Seekers
  • Health Care
  • Water
  • Food
  • Information Technology and Telecommunications
  • Space
  • Municipal Waste Management

The critical services and the relevant facility categories as defined by the KRITISDachG are specified in greater detail by the regulatory ordinance pursuant to Section 4, paragraph 3, and Section 5, paragraph 1, of the KRITISDachG.

Which critical facilities are considered critical facilities within the meaning of the KRITISDachG due to their importance for supplying the population and thus for the functioning of society is defined by the statutory regulation pursuant to § 4(3) and § 5(1) of the KRITISDachG (Kritis Ordinance). Whether a significant level of supply exists depends on whether the thresholds listed in the Kritis Ordinance are met or exceeded. If these thresholds are met or exceeded, operators of critical facilities are subject to the statutory registration, reporting, and documentation requirements of the KRITISDachG and the BSIG.

For more information and FAQs on various topics related to KRITIS, please visit the website of the BSI’s KRITIS Division and the BBK.

Designate a contact point

Operators of critical facilities

Operators of a critical infrastructure facility as defined in Section 2(1) of the KRITISDachG must designate a point of contact in accordance with Section 8(1)(6) of the KRITISDachG. With regard to the measures under the BSIG, this contact point must be reachable at all times. The BSI sends IT security information to this contact point, and the BBK sends relevant follow-up information after incident reports and situation assessments.

Obligation to report

The reporting requirement under Section 32, paragraphs 1–3, of the BSIG and Section 18, paragraph 1, of the KRITISDachG applies to operators of critical facilities whose facilities have been identified as critical facilities within the meaning of the KRITISDachG based on the thresholds set forth in the Kritis regulation.

For detailed information, please refer to the FAQs on the websites of BSI and BBK regarding the reporting requirement.

Registration

As of June 22, 2026: Registration has been suspended until preparations for registration under the KRITISDachG are complete.

If your institution is already registered, you can log in with your user name and password via the Login link. You can start the registration of an institution via the Registration link. You can find the registration manual here. Your registration details will be checked at the BBK and the registered institution will be activated for the KRITIS reporting point in the MIP. After submitting the registration, the BBK will inform you about the progress of your registration by e-mail.

Access to the information area of the MIP is only possible once the registration process has been completed. Only after registration can operators subject to the reporting obligation send reports to the BSI and BBK via the MIP and view (situation) information and products from the BSI and BBK.

If you were already registered with the BSI before July 2026, your access will remain active. However, an updated collection of registration data under your existing operator ID will be required once the registration requirement under Section 8 of the KRITISDachG takes effect.

Submit changes to the registration data to the BBK

If you want to make changes to your registration data, please DO NOT register again in the reporting portal. Instead, please log in to the reporting portal and download the following forms from the Information (Category: KRITIS-Formulare) menu:

  • for changes to institutional or contact information, please use the form „aenderung-kontaktstelle.pdf“
  • for changes to the registered critical facilities or new registrations of critical facilities the form „Anlage KRITIS“
  • for deregistration of a critical facilities the form „antrag-deregistrierung-kritis.pdf“

You can fill out the forms electronically and send them to kritis-info@bbk.bund.de.

Meldestelle Luftsicherheit

Companies subject to the Aviation Security Act (LuftSiG) can register on the new BSI portal. Registration via MIP is no longer possible. The BSI portal can be found at https://portal.bsi.bund.de. Further information and details on how to register on the BSI portal can be found at https://www.bsi.bund.de/dok/faq-bsi-portal.