Basics & Compliance
BSI registration step by step in the BSI portal (MUK + ELSTER)
NIS2 registration runs through the BSI portal at portal.bsi.bund.de, with sign-in via "Mein Unternehmenskonto" (MUK) and an ELSTER organisation certificate. This guide walks through the complete process, all mandatory fields, and the most common mistakes.
10 min read · Published 18 February 2026
Essential and important entities are required under Section 33 BSIG to register with the BSI. Since 6 January 2026, registration runs through the BSI portal at portal.bsi.bund.de. Authentication does not use a dedicated BSI account – it runs through the federal "Mein Unternehmenskonto" (MUK) platform with an ELSTER organisation certificate. This article walks through the full process step by step – from preparing the mandatory information through authentication to submission and ongoing maintenance.
Section 33 BSIG: Essential and important entities must register with the BSI and update their registration data without undue delay, at the latest within two weeks.
Who Must Register?
The registration obligation applies to all essential entities under Section 28 BSIG and all important entities under Section 29 BSIG. Operators of critical facilities register via the same form with an additional checkbox and provide their Institution ID under the BSI Critical Infrastructure Ordinance. If your entity provides services in multiple sectors, you can add each assignment via "Add another entity type" in the form.
- Essential entities (Section 28 BSIG): energy, water, health, transport, finance, digital infrastructure, space, ICT service management, public administration, Annex I sectors
- Important entities (Section 29 BSIG): postal and courier services, waste management, chemicals, food, manufacturing, digital services, research, Annex II sectors
- KRITIS operators: registration in the same form, plus Institution ID from the BSI Critical Infrastructure Ordinance
- Federal bodies: a separate flow with agency name, abbreviation, and a dropdown selection of the supervisory authority
If you have not yet formally determined your affected status, start with the KaitoSec Pre-Check – the gap analysis produces the self-classification you need for the registration form.
Which Deadlines Apply?
The registration obligation is tied to three distinct deadlines that must not be confused:
- Transition deadline for existing entities: The NIS2UmsuCG entered into force on 6 December 2025; the BSI portal went live on 6 January 2026. The registration deadline for entities already in scope expired on 6 March 2026. Entities that have not yet registered should do so immediately.
- Newly affected entities: Entities that become affected after the law enters into force (new incorporation, crossing size thresholds, new line of business) have three months from becoming aware of their affected status to register.
- Changes to registration data: Changes must be updated in the BSI portal without undue delay, at the latest within two weeks (Section 33 para. 5 BSIG). This is significantly shorter than commonly assumed.
Practical tip: Document the date on which you determined your affected status, signed off by management. This document serves as the anchor for deadline calculations during a later BSI review.
The Two Systems: MUK and BSI Portal
BSI registration runs through two distinct systems that are often confused. Anyone unfamiliar with the distinction will end up looking in the wrong place.
- Mein Unternehmenskonto (MUK): a federal eGovernment platform for digital authentication of companies vis-à-vis public authorities. MUK is not a BSI system. The platform accepts ELSTER organisation certificates as proof of identity and forwards the authenticated data to the requesting authority.
- BSI portal: accessible at portal.bsi.bund.de. This is the actual NIS2 registration and notification platform of the BSI. Login does not use a dedicated BSI account – you click "Sign in with MUK".
Authentication uses the ELSTER organisation certificate (.pfx file) plus its password. There is no separate BSI account creation, no email verification, and no additional two-factor step inside the BSI portal. If you do not yet have an ELSTER organisation certificate, apply for one at mein.elster.de – the activation code arrives by mail and the lead time is typically one to two weeks.
Step 1: Prepare the Mandatory Information
Before signing in, all mandatory information should be ready. The BSI portal allows saving work in progress, but a full preparation shortens the process considerably and reduces errors. Collect the following:
- Valid ELSTER organisation certificate and certificate password
- Company size for the last completed financial year: number of employees, annual turnover, annual balance sheet total
- Sector and industry under Annex I or II of the NIS2 Directive (Annexes 1 and 2 BSIG) – for multi-sector entities, all applicable sectors
- Entity type: essential or important (the portal proposes automatic classification in clear cases; borderline cases are entered manually)
- List of all EU Member States in which your entity provides services
- All competent federal and state supervisory authorities – explicitly emphasised by the BSI; in regulated sectors there are frequently several (BNetzA, BaFin, state data protection authorities)
- Contact point: organisational unit, postal address, telephone number, functional email address (not a personal mailbox)
- One or more NIS-2 contact persons: name, role, function – at least one must be able to speak to NIS2 and BSIG regulation substantively
- Public IP address ranges in CIDR notation (IPv4 and IPv6) with a short label per range – or an explicit statement that none exist
- For KRITIS operators: Institution ID under the BSI Critical Infrastructure Ordinance
Important note on size calculation: The calculation basis is the legal entity to which the ELSTER organisation certificate is issued. For affiliated entities under the EU SME definition (Recommendation 2003/361/EC), partner and linked enterprises must in principle be included – unless the entities are legally, economically, and operationally independent. In group structures, this means each legal entity that itself falls under Section 28 or Section 29 BSIG registers separately.
ELSTER pre-filling: The BSI portal automatically populates master data from the organisation certificate (company name, address, contact details). These pre-filled values cannot be changed directly in the portal – corrections must be made via "Mein ELSTER" (mein.elster.de). Check that the data held in ELSTER is current before beginning the registration.
Step 2: Sign In to the BSI Portal via MUK
Sign-in is the first touchpoint with the actual portal. The sequence has five steps:
- Open the portal: navigate to portal.bsi.bund.de in your browser
- Select "Sign in with MUK"
- Upload your ELSTER organisation certificate (.pfx file) and enter the certificate password
- Confirm that the master data held in ELSTER may be forwarded to the BSI
- Once authenticated, navigate via "Specialist procedures" → "To NIS-2" → "To NIS-2 registration"
Every subsequent sign-in follows the same process. The certificate is not stored once and for all – it is used on every login. Anyone who loses the certificate or lets it expire loses access to the portal, including the ability to make the legally required updates within the two-week window.
Step 3: Enter Entity Type and Classification
The registration form walks you through a series of dropdowns and input fields. The classification logic is partly automated:
- State whether you are a federal body. Supreme and higher federal authorities select themselves from a dropdown list.
- KRITIS checkbox: if your entity is a critical facility, activate the checkbox and enter the Institution ID from the BSI Critical Infrastructure Ordinance
- Enter company size: number of employees, annual turnover, annual balance sheet total
- Select sector, industry, and entity type from the dropdowns. For multi-sector entities, use "Add another entity type" to add each additional assignment
- Enter the EU Member States in which services are provided, and list all competent federal and state supervisory authorities
- Confirm classification as essential or important entity – the portal proposes automatic classification in clear cases; borderline cases must be selected manually
Step 4: Designate the Contact Point and Contact Persons
The BSI communicates exclusively via the stored contact details in a crisis. The contact point is therefore the most critical part of the registration – incorrect or outdated entries mean you will miss warnings and situation reports.
- Contact point: organisational unit (e.g., "IT Security" or "Security Operations"), postal address, telephone number, and a functional email address. A personal mailbox is explicitly unsuitable, because annual leave, illness, or departure interrupts the channel.
- NIS-2 contact persons: name, role, and function. At least one person must be able to speak substantively to NIS2 and BSIG regulation. Multiple persons can be entered, and that is advisable: if one person is unavailable, the BSI remains in contact.
Practical note on 24/7 reachability: KRITIS operators face additional requirements under Section 39 BSIG, including a permanently reachable contact point. For plain NIS2 entities without KRITIS status, Section 33 BSIG does not mandate 24/7 reachability – but it requires a contact point that can act in a crisis. Monitoring the functional mailbox plus a clear internal escalation chain does not replace a 24/7 on-call arrangement, but it is the pragmatic standard for regulated entities without KRITIS status.
Step 5: Enter IP Address Ranges
The registration form requires the public network ranges through which your essential services are reachable. This field cannot be left empty:
- IPv4 ranges in CIDR notation (e.g., 192.0.2.0/24)
- IPv6 ranges in CIDR notation (e.g., 2001:db8::/32)
- A short label per range (e.g., "DC Frankfurt external perimeter", "SaaS gateway")
- If no public IP ranges exist (e.g., pure SaaS usage without own infrastructure), non-existence must be confirmed explicitly in the form
The operational background: the BSI uses the IP data to notify affected entities about new vulnerabilities, compromised systems, or active attacks. Incomplete or outdated IP data directly reduces this early-warning benefit.
Step 6: Submit and Keep Up to Date
After entering all fields, you complete the registration via "Finish registration". The submitted data then appears in the portal under the "Your registration" tab – where you can review and update it at any time.
Keeping the data current is a legal obligation: Section 33 para. 5 BSIG requires updates to be made without undue delay, at the latest within two weeks. This deadline is frequently underestimated in practice. Events requiring an update include:
- Change of contact point or of a contact person
- Change of address, company name, or legal form
- Mergers, acquisitions, or corporate splits
- New or discontinued essential services or facilities
- Material changes in company size affecting the classification
- Loss of affected status (e.g., permanently falling below thresholds)
Document the evidence: Archive a screenshot or PDF export of the completed registration form and the portal confirmation. For the personal liability of management under Section 38 BSIG, evidence of timely registration is a central exonerating document. Set an internal follow-up (twelve months) for routine data review.
Common Mistakes in BSI Registration
- Confusing MUK and the BSI portal: MUK is not a BSI system, it is the federal eGovernment authentication. The entry point is portal.bsi.bund.de, not a non-existent "muk.bsi.bund.de"
- Applying for the ELSTER organisation certificate too late: without a valid certificate there is no registration. The activation code arrives by mail – plan one to two weeks lead time
- Personal email address as contact: annual leave or departure breaks the channel. Use functional mailboxes exclusively
- Incomplete list of supervisory authorities: entities in regulated sectors frequently face several parallel supervisors. List all of them in the form
- Group structure modelled incorrectly: what is registered is the legal entity of the ELSTER certificate. In groups, every legal entity that itself falls under Section 28 or Section 29 BSIG must be registered separately
- Underestimating the update deadline: two weeks, not three months. A contact person change without a portal update is a breach that can be fined under Section 60 BSIG
- Leaving IP ranges blank: the field requires either CIDR ranges or an explicit statement of non-existence
- Ignoring ELSTER pre-filling: if you see outdated master data in the portal, the correction must be made via mein.elster.de, not in the BSI portal
What Happens After Registration?
With the registration complete, your entity is known to the BSI and part of the operational situation picture. In practice, this means:
- The BSI can contact you via the functional mailbox about vulnerabilities, compromised systems, or active attacks – particularly when the reported IP ranges are affected
- Security incidents under Section 32 BSIG are reported through the same BSI portal, following the 24-hour early warning, 72-hour interim report, and 30-day final report cycle
- KRITIS operators face additional obligations under Section 39 BSIG, including evidence duties and permanent reachability
- Vulnerability reports (e.g., from external security researchers) can be submitted anonymously and without registration via the portal, as long as no actual incident is at stake
Checklist: BSI Portal Registration
- ☐ Affected status formally determined and dated (deadline anchor)
- ☐ Sector and entity type assignment under Annex 1 or 2 BSIG determined
- ☐ ELSTER organisation certificate available or applied for (account for lead time)
- ☐ Company size calculated under the EU SME definition (including affiliated enterprises)
- ☐ Master data in "Mein ELSTER" checked for currency
- ☐ Contact point defined with a functional mailbox
- ☐ One or more NIS-2 contact persons designated
- ☐ IP address ranges collected in CIDR notation (or non-existence confirmed)
- ☐ Federal and state supervisory authorities listed in full
- ☐ EU Member States of service provision compiled
- ☐ KRITIS Institution ID (if applicable) available
- ☐ Registration in the BSI portal completed and screenshot archived
- ☐ Internal follow-up reminder for data maintenance set
Sources: BSI guidance on registration in the BSI portal (https://www.bsi.bund.de/dok/anleitung-portal-registrierung), Sections 33, 28, 29, 38, and 60 BSIG, BSI Critical Infrastructure Ordinance (https://www.gesetze-im-internet.de/bsi-kritisv/), EU Recommendation 2003/361/EC on the SME definition.
This article is for orientation and does not constitute legal advice within the meaning of the German Legal Services Act (RDG). For the legal classification of your specific situation, please consult a lawyer specialising in IT law or information security law.
This article is orientation, not legal advice. Verify scope, deadlines and notification routes against the rules in force for your organisation.
More in Basics & Compliance