Does NIS2 apply to your company?
Answer five questions and receive a first assessment based on the German NIS2 implementation act (BSIG). No sign-up, no data transfer – the assessment runs entirely in your browser.
Your result
Essential entity
Based on your answers, your company is likely to qualify as an essential entity under the German NIS2 implementation act. The full set of obligations applies – including active supervision by the BSI.
What this means for you
- Registration with the BSI within three months
- Risk management measures according to the state of the art: including business continuity, supply-chain security, multi-factor authentication, encryption, training
- Reporting of significant incidents: early warning within 24 hours, incident notification within 72 hours, final report after one month
- Personal implementation and training duty of the management
- Evidence obligations towards the BSI – regularly every three years for KRITIS operators, otherwise on request
Your result
Important entity
Based on your answers, your company is likely to qualify as an important entity under the German NIS2 implementation act. Registration, risk management and reporting obligations apply in full; BSI supervision is event-driven.
What this means for you
- Registration with the BSI within three months
- Risk management measures according to the state of the art: including business continuity, supply-chain security, multi-factor authentication, encryption, training
- Reporting of significant incidents: early warning within 24 hours, incident notification within 72 hours, final report after one month
- Personal implementation and training duty of the management
- Event-driven supervision by the BSI, e.g. after incidents or indications
Your result
Not directly affected – but via the supply chain
Based on your answers, your company is probably not directly subject to NIS2. Since you supply or service NIS2 entities, expect customers to demand security evidence, contractual commitments and defined reporting channels from you.
What this means for you
- Keep security evidence ready for customers, e.g. policies, penetration test report, training records
- Review and meet contractual requirements on reporting channels and response times
- Align your own security level with a recognised standard, e.g. BSI IT-Grundschutz or ISO 27001
Your result
Not directly affected
Based on your answers, your company is probably not subject to the German NIS2 implementation act. This does not exempt you from the GDPR and the general duty of care of the management – and customers may still ask for security evidence.
What this means for you
- Ensure baseline protection: backups, multi-factor authentication, patches, awareness
- Re-check applicability every year – thresholds and sector classifications may change
- Re-check on growth, acquisitions or new business areas
Basis of the assessment
- Your sector belongs to the sectors of high criticality (Annex I).
- Your sector belongs to the other critical sectors (Annex II).
- Your sector is not listed in the NIS2 annexes.
- Your company counts as a large enterprise (250 or more employees, or turnover above EUR 50 million and balance sheet total above EUR 43 million).
- Your company counts as a medium-sized enterprise (50 or more employees, or turnover and balance sheet total above EUR 10 million).
- Your company is below the thresholds for medium-sized enterprises.
- As a KRITIS operator the obligations apply regardless of company size.
- Trust services, TLD registries and DNS providers are covered regardless of size.
- Providers of public telecommunications networks and services are covered regardless of size.
- As the sole provider of an essential service, classification may apply regardless of size – the BSI decides case by case.
- Federal government bodies are subject to their own provisions in the BSIG.
- You supply or service NIS2 entities – requirements are often passed on by contract.
Free initial consultation – we verify the classification and show you the next steps.
This assessment is not legal advice and does not replace a review by the BSI. The BSI Act in its current version, the BSI KRITIS regulation and the classification of your specific activities under the statutory entity types are decisive. Your answers are neither stored nor transmitted.