KNOWLEDGE · NIS2

NIS2: are you in scope?

The NIS2 directive widens the circle of companies that must demonstrably answer for their cyber security. This article explains what it covers, how to assess whether it applies to you, and which technical and organisational steps come first.

01 ARTICLE · COMPLIANCE
01FOUNDATIONEU DIRECTIVE 2022/2555

What NIS2 is.

NIS2 is the European Union's second directive on network and information security. It replaces the first NIS directive from 2016 and raises the required security level noticeably. In Germany it does not apply directly but through the NIS2 implementing act, which recast the BSI Act. What governs a German company is therefore the BSI Act of 2 December 2025, not the text of the directive.

The core is simple to state. Entities in scope must know their risks, take appropriate measures, report significant security incidents within tight deadlines and document all of it traceably. What is new above all is that management itself owns the implementation. It must put the measures in place, monitor that they are in place and undergo training regularly, and it is liable to its own entity for damage it culpably causes.

NIS2 asks for four things in essence:

  • Risk management that is actually practised, for your own systems and for the supply chain.
  • Technical and organisational measures that match the risk and are effective.
  • Reporting of significant incidents to the competent authority within short deadlines.
  • Evidence, and a management team that owns and oversees the implementation.

How tight those deadlines are is written into the law itself. Under § 32 of the BSI Act an early warning goes to the Federal Office within 24 hours of becoming aware, the incident notification within 72 hours, and the final report no later than one month after that notification. The Federal Office may request an interim report at any point. Article 23 of the directive sets out the same chain.

The NIS2 reporting chain. Early warning within 24 hours of becoming aware, incident notification within 72 hours, final report no later than one month after the notification. 01 24 HOURS EARLY WARNING 02 72 HOURS NOTIFICATION 03 1 MONTH FINAL REPORT T0 · BECOMING AWARE 03 RUNS FROM 02
Fig. 01The reporting chain under § 32 of the BSI Act and Article 23 of the directive. The axis is not to scale. The first two deadlines run from the moment of becoming aware, the third only from the notification.

NIS2 is therefore not a one-off project but a standing state. Anyone who meets the requirements runs their systems so that an outage or attack is noticed early and the recovery has been rehearsed. That operational view is why we carry the topic from the analysis all the way into operations.

02SCOPESECTOR, SIZE, ROLE

Who is in scope.

NIS2 distinguishes two groups. The directive calls them essential and important entities, the German BSI Act calls them particularly important and important entities. The first group sits under the stricter supervision, the second under a somewhat lighter one. Whether you fall into either group depends on three questions: which sector you operate in, how large your company is, and what role you play in other organisations' supply chains.

Three checks for NIS2 scope. First the sector, then the size thresholds under section 28 of the BSI Act, then the role in the supply chain. 01 SECTOR Does your activity fall under an entity type in Annex 1 or Annex 2 of the BSI Act? 02 SIZE Is either line in the block reached? The thresholds sit in § 28 of the BSI Act. IMPORTANT ENTITY 50 EMPLOYEES OR MORE OR 10 M EURO TURNOVER AND BALANCE SHEET TOTAL EACH PARTICULARLY IMPORTANT ENTITY 250 EMPLOYEES OR MORE OR 50 / 43 MILLION EURO TURNOVER OVER 50 AND SHEET OVER 43 03 SUPPLY CHAIN Is a customer in scope passing supply chain security down to you? § 30 requires it.
Fig. 02The three checks in order. On the monetary criterion, turnover and balance sheet total must both sit above the threshold. For operators of critical installations and certain other entity types the duties apply regardless of size.

The sectors

Covered are, among others, energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, providers of IT services and parts of public administration. Further areas follow, such as postal and courier services, waste management, chemicals, food, manufacturing, providers of digital services and research. What binds are Annexes 1 and 2 to the BSI Act, not this list.

The size

A rule of thumb circulates here that falls short. You often read that NIS2 applies from fifty employees or from an annual turnover in the tens of millions. The first is right, the second is not. Under § 28 of the BSI Act turnover alone does not suffice. An important entity exists from fifty employees upwards, or where annual turnover and annual balance sheet total each exceed ten million euro. Particularly important entities start at two hundred and fifty employees, or at an annual turnover above fifty million euro together with a balance sheet total above forty-three million euro.

For operators of critical installations, qualified trust service providers and certain other entity types the duties apply regardless of size. Exemptions in the individual case belong in the legal assessment.

The role in the supply chain

Even those not directly covered are frequently affected indirectly. Customers in scope pass their requirements on to suppliers and service providers, because § 30 of the BSI Act counts supply chain security among the risk management measures explicitly, including the security-related aspects of the relationships with immediate suppliers. A short, honest look at your own technical position helps to gauge the starting point. A first indication is our system audit self-check.

For the question of scope alone, the Federal Office itself provides a scope check. It works from self-declared answers and states that its result is not legally binding, but it sorts the question out in a few minutes.

One important distinction: assessing scope has a technical side and a legal one. We take on the technical and organisational preparation. The legally binding judgement of whether you are in scope within the meaning of the law stays with your lawyers, with whom we work on this.

03FIRST STEPSTECHNOLOGY AND ORGANISATION

The first steps.

You do not have to wait for the final legal clarification to start preparing. Most measures are worth doing anyway and pay into stable operations. Technically, these points come first:

  • A current inventory of all systems, services and access paths, because what is unknown cannot be protected.
  • Separating and securing access, with least privilege and a second authentication step.
  • Logging and monitoring, so an incident surfaces early rather than only in the damage.
  • Setting up backups and actually rehearsing the recovery, not merely describing it.
  • Closing known weaknesses and evidencing the attack surface with a penetration test.

Organisationally, these belong with it:

  • Clear responsibilities for security, anchored up into management.
  • A rehearsed reporting process that can hold the short deadlines.
  • A review of the most important service providers, because their security is part of yours.
  • Regular awareness training for staff on the most common attack routes.

None of this list is invented. § 30 of the BSI Act names, among others, supply chain security, backup management and recovery after an emergency, policies for access control and personnel, the use of multi-factor authentication, and procedures by which the effectiveness of the measures is itself assessed. That last point is readily overlooked. Having measures is not enough, their effect has to be verifiable.

This is exactly where we come in. In the NIS2 and operational security position we assess scope technically, find the gaps, plan the measures and produce the evidence. The legal judgement stays deliberately out of it and sits with your lawyers.

In closing

NIS2 catches more companies than many assume, often indirectly through the supply chain. The entry is manageable if you separate technology from organisation and start with a clear picture of your own current state. Starting early spreads the effort and improves day-to-day operations along the way. Further answers on pricing, contracts and where data is held sit under Knowledge. If you want to place your own situation concretely, a first call is the fastest route.

04SOURCESPRIMARY SOURCES

What this rests on.

01 Directive (EU) 2022/2555 (NIS2)EUR-Lex · Official Journal L 333 Article 2 ties the scope to the medium-sized enterprises of Recommendation 2003/361/EC. Article 23(4) sets the early warning, the incident notification and the final report. Article 41 names 17 October 2024 as the transposition deadline. 02 § 28 BSI Act (German)Federal Ministry of Justice The size thresholds verbatim. Important entities from fifty employees, or with turnover and balance sheet total each above ten million euro. Particularly important entities from two hundred and fifty employees, or above fifty and forty-three million. Basis for chapter 02 and figure 02. 03 § 30 BSI Act (German)Federal Ministry of Justice The catalogue of risk management measures. Names supply chain security, backup management and recovery after an emergency, access control, multi-factor authentication and procedures for assessing effectiveness. Basis for the lists in chapter 03. 04 § 32 BSI Act (German)Federal Ministry of Justice The reporting duties with the deadlines of 24 hours, 72 hours and one month after the notification, plus the interim report on request by the Federal Office. Basis for figure 01. 05 § 38 BSI Act (German)Federal Ministry of Justice The duty of management to implement the measures, monitor their implementation and undergo training, and its liability towards its own entity for damage culpably caused. Basis for the statement on management responsibility in chapter 01. 06 NIS-2 scope check (German)Federal Office for Information Security The Federal Office's own questionnaire for a first assessment. It works from self-declared answers and states that its result is not legally binding. Basis for the note in chapter 02.
05FURTHER READING04 ARTICLES

More articles.

06CONTACTMUNICH

Have your NIS2
position assessed.

A reply within two working days, with a concrete scoping proposal.

START A MANDATE MANDATE REVIEW