NIS-2
Digitalization affects all value-added processes and makes both companies and government agencies equally vulnerable to cyberattacks if they lack adequate security measures. The European Union has therefore set itself the goal of establishing a higher level of security within member states and increasing the resilience of companies and public authorities against cyberattacks. With this goal in mind, the European Union adopted EU Directive 2022/2555, also known as the NIS 2 Directive, and repealed the NIS Directive 2016/1148. The provisions of the NIS 2 Directive were fully transposed into national law by the German federal government through the Act Implementing the NIS 2 Directive (NIS-2UmsuCG) as of December 6, 2025.
The previous BSI Act was thus comprehensively modernized and expanded. The number of regulated entities was increased from 4,500 to approximately 30,000. In addition to defining heightened requirements for risk management at the affected companies, the BSI was also granted expanded supervisory and enforcement powers.
Objectives of NIS 2
With the NIS 2 Directive, the European Union is pursuing four strategic objectives:
EU-wide harmonization in the form of uniform minimum standards for risk management, technical and organizational security, incident detection, and incident response
Improving cyber resilience within the Union by extending cybersecurity requirements to more sectors
Strengthening governance by stipulating that responsibility for cybersecurity lies with senior management. Senior management must approve cybersecurity risk management measures and oversee their implementation. Additionally, senior management is required to undergo training on cyber risks (Section 38(3) BSIG-E).
Increasing transparency through reporting requirements by establishing a uniform reporting pathway and deadlines to make incidents visible more quickly and enable authorities to respond in a more coordinated manner.
Who is affected by the NIS 2 Directive?
With NIS 2, a much broader range of companies is now subject to regulation. Whereas previously only a few thousand operators of critical infrastructure were affected, the new law now applies to around 30,000 companies.
In the German implementation, there are two categories, each entailing different obligations and levels of regulatory oversight. A distinction is made between “particularly important facilities” and “important facilities”—the main difference being that “important facilities” face lower fines and are subject to reactive oversight by the authorities. “Particularly important facilities,” on the other hand, are subject to proactive oversight.
Critically Important Entities (high criticality) are companies that offer goods or services for a fee and fall under one of the entity types specified in Annex 1 of the BSIG, provided they have either more than 250 employees OR more than 50 million euros in annual revenue and 43 million euros in annual balance sheet total. The company must operate in one of the following sectors:
Energy
Transportation and Traffic
Finance
Healthcare
Water
Digital Infrastructure
Space
Important facilities (other critical infrastructure) are companies with more than 50 employees OR more than 10 million euros in annual revenue and 10 million euros in annual balance sheet total that operate in the following sectors:
Waste Management
Postal and courier services
Chemical products – production and distribution
Food – production and distribution
Manufacturers – computers, electronics, optics, machinery, motor vehicles and trailers, means of transport
Digital service providers – search engines, social networks, online marketplaces
Research institutions
Excluded from the NIS 2 Directive are companies in the fields of national security, defense, public safety, or law enforcement. The judiciary, parliaments, and the central banks of the EU are not subject to NIS 2 for reasons of state sovereignty. However, these sectors are generally subject to their own cybersecurity guidelines.
Obligations for Companies
NIS-2 requires companies to implement a comprehensive security strategy that encompasses technology, processes, and employee management.
Key obligations include establishing a structured risk management system to systematically identify, assess, and document the handling of risks. The obligation to ensure supply chain security also requires companies to be able to demonstrate that service providers and suppliers apply appropriate security standards. In addition, companies are required to implement clear internal processes for handling security incidents and regularly reviewing the effectiveness of the measures taken.
Of particular relevance under NIS-2 are the specified reporting obligations.
Companies affected by NIS-2 must report significant IT security incidents to the BSI. These include, among other things, compromises, disruptions to critical services, outages affecting customers or supply chains, and serious cyberattacks.
The required reporting process is divided into three steps:
Early warning (24 hours) – an initial brief report that must be submitted to the BSI within 24 hours
Detailed report (72 hours) – technical analyses, measures taken, and impacts, which must be communicated within 72 hours
Final report (<30 days) – a final assessment and compilation of findings within 30 days
The report includes an assessment of the incident, including severity, impact, indicators of compromise, and contact information. The BSI acknowledges reports, contacts the entity if necessary, and processes the reports.
All companies affected by NIS-2 were required to register with the BSI by March 6, 2026. Only upon registration with the BSI is a company officially considered a NIS-2 entity and subject to supervision by the BSI.
Management Responsibilities, Sanctions, and Liability Provisions
With the obligation to implement NIS-2, senior management plays a significantly more active role in ensuring information security within their organization. Senior management must demonstrably address security issues, complete training, and ensure that resources, processes, and responsibilities within the organization are clearly defined. Management thus transitions from being an approver to a designer and the party responsible for establishing an appropriate level of security.
To enforce the new requirements, NIS-2 provides for a stricter framework of sanctions modeled after the GDPR’s sanctions framework. The sanctions provisions are divided into tiers, with the classification of whether the company is a critical or very critical infrastructure being a key factor.
The penalty provisions apply in cases of negligence or intentional misconduct.
The fine range for important entities is up to EUR 7 million or 1.4% of the previous year’s global annual turnover. The fine range for critical entities is up to EUR 10 million or 2% of the previous year’s global annual turnover. The higher amount always applies.
The liability risk for management relates, for example, in the event of a cyberattack, to cost items such as potential ransom payments (ransomware), costs for external service providers (e.g., forensics), and fines.
Management’s liability may extend to their personal assets, e.g., in the event of a breach of monitoring obligations. Any waiver by the company of claims for compensation against management or a settlement regarding such claims is invalid. The only exception is insolvency.
Implementing NIS-2 in Practice
For many companies, NIS-2 primarily means establishing structures that not only document security but also put it into practice. An effective approach is to implement an Information Security Management System (ISMS) based on the ISO/IEC 27001:2022 standard.
Here is an overview of the NIS-2 requirements:
Establishment of an effective risk management system, including detailed risk assessments of the IT infrastructure and the implementation of appropriate technical and organizational measures
Development of emergency and business continuity plans to maintain or restore business operations as quickly as possible in the event of a cyberattack
Reporting of security incidents and reporting within strict deadlines
Vetting of suppliers and service providers to strengthen security in the supply chain
Documentation and regular updating of implemented security measures to ensure traceable and reliable evidence
Promotion of risk awareness among employees
Within the framework of the ISMS according to ISO/IEC 27001:2022, many NIS-2 requirements are already addressed due to a common overlap. Furthermore, any remaining specific requirements can be systematically identified and implemented through the structured approach of an ISMS.
Establishing an ISMS is therefore an effective and sustainable method for efficiently meeting both current and future information security requirements. Regardless of this, conducting GAP analyses, robust project planning and organization, supply chain auditing, and the development of standardized processes for handling security incidents are essential prerequisites for the successful implementation of NIS-2.
Conclusion
The NIS 2 Directive improves cybersecurity regulation in the European Union. With a significant expansion of its scope, clearly defined reporting obligations, stronger accountability for senior management, and expanded supervisory and sanctioning powers, the Directive establishes a significantly more binding framework for addressing information security risks.
For the affected companies, it is clear that cybersecurity is no longer merely an IT issue but has become a strategic management task. In particular, the requirements for risk management, supply chain security, incident response, and evidence management make it clear that a systematic and sustainably effective level of security must be established.
An information security management system, e.g., based on the ISO/IEC 27001:2022 standard, provides a solid foundation for meeting the requirements of NIS-2 in a structured, traceable, and sustainable manner. Companies can thus not only reduce regulatory risks but also strengthen their resilience against cyberattacks.
In summary, the NIS-2 Directive thus represents not only a legal obligation but also an impetus to take information security seriously within companies and to implement it as an integral part of corporate culture for responsible and sustainable corporate governance.
Cookie-Settings