With the NIS2 implementation act, the European NIS2 Directive has been binding law in Germany since December 2025. The number of companies in scope has grown considerably: the BSI expects around 29,000 entities – many of them medium-sized businesses that never had to deal with the Federal Office for Information Security before. This article summarises who is affected, what is required and what a realistic start looks like.

Who is affected

Applicability depends on two factors: the sector and the company size. The law distinguishes sectors of high criticality (Annex I of the Directive, such as energy, transport, health, water, digital infrastructure, ICT service providers) and other critical sectors (Annex II, such as postal services, waste, chemicals, food, manufacturing, digital providers, research).

ClassificationSectorSize
Essential entityAnnex I250 or more employees, or turnover above EUR 50 million and balance sheet total above EUR 43 million
Important entityAnnex I50 or more employees, or turnover and balance sheet total above EUR 10 million
Important entityAnnex II50 or more employees, or turnover and balance sheet total above EUR 10 million

Regardless of size, the law covers among others operators of critical installations (KRITIS), qualified trust service providers, DNS service providers, TLD registries and providers of public telecommunications networks. Important: size is determined according to the EU SME recommendation – linked and partner enterprises are counted proportionally. A 40-person company that belongs to a larger group may therefore be in scope.

You can check whether your company is affected in two minutes with our NIS2 self-check.

The five core obligations

  1. Registration. Entities in scope must register with the BSI within three months – with contact details, sector and IP ranges.
  2. Risk management. The law requires appropriate, proportionate and effective technical and organisational measures according to the state of the art. Explicitly listed are, among others, risk analysis, incident handling, backup and business continuity management, supply-chain security, secure development and procurement, training, cryptography, access control and multi-factor authentication.
  3. Reporting. Significant incidents must be reported in three stages: early warning within 24 hours, incident notification within 72 hours, final report no later than one month after the notification.
  4. Management duties. Managing directors and board members must approve the risk management measures, oversee their implementation and regularly attend training themselves. Violations can lead to personal liability.
  5. Evidence and supervision. Essential entities are subject to active supervision, important entities to event-driven supervision. KRITIS operators must regularly prove implementation.

What this means for management

NIS2 is not purely an IT topic. Responsibility explicitly lies with the management, and the requirements affect procurement, HR, contract design and emergency organisation as much as firewalls and backups. Delegating implementation entirely to the IT department or the system integrator does not fulfil the obligations.

The good news: companies already working according to ISO 27001 or BSI IT-Grundschutz have covered most of the requirements. For everyone else, NIS2 is an occasion to finally approach information security systematically – with measures that would make sense even without a law.

Where to start

  • Clarify applicability and document it in writing – a well-founded “not affected” is a result too.
  • Prepare registration if affected: name contacts, determine sector and entity type.
  • Assess the current state: which measures already exist? Where are the gaps against the legal requirements?
  • Set up the reporting process: who detects an incident, who decides, who reports within 24 hours – even on a weekend?
  • Prioritise: backups, multi-factor authentication, patch management and awareness reduce risk fastest. Policies and documentation follow.

Conclusion

NIS2 does not demand the impossible, but it demands structure. Companies that start now can meet the requirements within three to twelve months – and along the way reach a security level that customers, insurers and banks increasingly expect anyway. We support you with a gap analysis, a prioritised action plan and, on request, as your external information security officer.