The NIS2 directive widens the circle of companies that must demonstrably answer for their cyber security. This article explains what it covers, how to assess whether it applies to you, and which technical and organisational steps come first.
NIS2 is the European Union's second directive on network and information security. It replaces the first NIS directive from 2016 and raises the required security level noticeably. In Germany it does not apply directly but through the NIS2 implementing act, which recast the BSI Act. What governs a German company is therefore the BSI Act of 2 December 2025, not the text of the directive.
The core is simple to state. Entities in scope must know their risks, take appropriate measures, report significant security incidents within tight deadlines and document all of it traceably. What is new above all is that management itself owns the implementation. It must put the measures in place, monitor that they are in place and undergo training regularly, and it is liable to its own entity for damage it culpably causes.
NIS2 asks for four things in essence:
How tight those deadlines are is written into the law itself. Under § 32 of the BSI Act an early warning goes to the Federal Office within 24 hours of becoming aware, the incident notification within 72 hours, and the final report no later than one month after that notification. The Federal Office may request an interim report at any point. Article 23 of the directive sets out the same chain.
NIS2 is therefore not a one-off project but a standing state. Anyone who meets the requirements runs their systems so that an outage or attack is noticed early and the recovery has been rehearsed. That operational view is why we carry the topic from the analysis all the way into operations.
NIS2 distinguishes two groups. The directive calls them essential and important entities, the German BSI Act calls them particularly important and important entities. The first group sits under the stricter supervision, the second under a somewhat lighter one. Whether you fall into either group depends on three questions: which sector you operate in, how large your company is, and what role you play in other organisations' supply chains.
Covered are, among others, energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, providers of IT services and parts of public administration. Further areas follow, such as postal and courier services, waste management, chemicals, food, manufacturing, providers of digital services and research. What binds are Annexes 1 and 2 to the BSI Act, not this list.
A rule of thumb circulates here that falls short. You often read that NIS2 applies from fifty employees or from an annual turnover in the tens of millions. The first is right, the second is not. Under § 28 of the BSI Act turnover alone does not suffice. An important entity exists from fifty employees upwards, or where annual turnover and annual balance sheet total each exceed ten million euro. Particularly important entities start at two hundred and fifty employees, or at an annual turnover above fifty million euro together with a balance sheet total above forty-three million euro.
For operators of critical installations, qualified trust service providers and certain other entity types the duties apply regardless of size. Exemptions in the individual case belong in the legal assessment.
Even those not directly covered are frequently affected indirectly. Customers in scope pass their requirements on to suppliers and service providers, because § 30 of the BSI Act counts supply chain security among the risk management measures explicitly, including the security-related aspects of the relationships with immediate suppliers. A short, honest look at your own technical position helps to gauge the starting point. A first indication is our system audit self-check.
For the question of scope alone, the Federal Office itself provides a scope check. It works from self-declared answers and states that its result is not legally binding, but it sorts the question out in a few minutes.
One important distinction: assessing scope has a technical side and a legal one. We take on the technical and organisational preparation. The legally binding judgement of whether you are in scope within the meaning of the law stays with your lawyers, with whom we work on this.
You do not have to wait for the final legal clarification to start preparing. Most measures are worth doing anyway and pay into stable operations. Technically, these points come first:
Organisationally, these belong with it:
None of this list is invented. § 30 of the BSI Act names, among others, supply chain security, backup management and recovery after an emergency, policies for access control and personnel, the use of multi-factor authentication, and procedures by which the effectiveness of the measures is itself assessed. That last point is readily overlooked. Having measures is not enough, their effect has to be verifiable.
This is exactly where we come in. In the NIS2 and operational security position we assess scope technically, find the gaps, plan the measures and produce the evidence. The legal judgement stays deliberately out of it and sits with your lawyers.
NIS2 catches more companies than many assume, often indirectly through the supply chain. The entry is manageable if you separate technology from organisation and start with a clear picture of your own current state. Starting early spreads the effort and improves day-to-day operations along the way. Further answers on pricing, contracts and where data is held sit under Knowledge. If you want to place your own situation concretely, a first call is the fastest route.
A reply within two working days, with a concrete scoping proposal.