This text was generated using artificial intelligence (AI).
The NIS2 Directive requires significantly more companies than before to implement cybersecurity measures, follow reporting procedures, and register with the BSI. The German NIS2 Implementation Act (NIS2UmsuCG) has been in effect since December 6, 2025, with no general transition periods. This overview explains who is affected, what obligations apply, what fines may be imposed, and what deadlines you should be aware of. As of August 2026.
Key Points at a Glance
The NIS2 Directive (EU) 2022/2555 has been in effect since January 16, 2023. Germany has implemented it through the NIS2 Implementation Act (NIS2UmsuCG), which has been in effect since December 6, 2025.
According to the BSI, the number of regulated entities is rising from about 4,500 to approximately 29,500. This affects companies in 18 sectors with 50 or more employees or annual revenue and total assets of 10 million euros.
These obligations include risk management in accordance with Section 30 of the BSIG, registration with the BSI, and reporting significant security incidents within 24 hours.
Fines can reach up to 10 million euros; for organizations with annual revenue exceeding 500 million euros, fines can amount to up to 2 percent of global revenue. Management must personally oversee implementation and is liable for culpable breaches of duty.
The law does not provide for any general transition periods. Anyone affected who has not yet registered should do so now.
What is the NIS2 Directive?
NIS2 stands for the second EU Directive on Network and Information Security. Directive (EU) 2022/2555 entered into force on January 16, 2023, and replaces the first NIS Directive from 2016. Its goal is to ensure a uniformly high level of cybersecurity throughout the European Union.
Compared to the previous directive, NIS2 significantly expands its scope. It covers more sectors, lowers the size thresholds, and standardizes reporting requirements, oversight, and sanctions. Another new feature is the explicit responsibility of management bodies: executive boards and management teams must approve cybersecurity measures, monitor their implementation, and undergo regular training.
Member States were required to transpose the directive into national law by October 17, 2024. Germany missed this deadline and did not complete implementation until the end of 2025. Since then, the German implementing law has been the sole source of law for affected companies, as the directive itself does not impose any direct obligations on companies.
NIS2UmsuCG: The German Implementation Act has been in effect since December 2025
On November 13, 2025, the Bundestag passed the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG). According to the BSI, following its publication in the Federal Law Gazette on December 5, 2025, the law has been in effect since December 6, 2025. At the heart of the law is a comprehensive revision of the BSI Act (BSIG), which governs requirements, reporting channels, and oversight.
Important for practical implementation: The law does not provide for any general transition periods. The obligations regarding risk management, registration, and reporting have been in effect since the law took effect. The BSI is the central supervisory authority and provides a dedicated portal as well as a tool for assessing whether an organization is affected.
The BSIG distinguishes between two new categories: particularly important facilities and important facilities. Operators of critical infrastructure (KRITIS) remain a separate group subject to additional requirements, such as regular compliance audits. According to the BSI, this will expand the number of supervised facilities from around 4,500 to approximately 29,500.
Who is affected? Sectors and size thresholds
Whether a company falls under the scope of the BSIG depends on two factors: the sector and the company’s size. Annexes 1 and 2 of the BSIG list a total of 18 sectors. These include, among others, energy, transportation and traffic, finance, healthcare, drinking water and wastewater, digital infrastructure, public administration, postal and courier services, waste management, chemicals, food, the manufacturing industry, as well as digital service providers and research institutions.
Category
Criteria under Section 28 of the BSIG
Range of Fines Under Section 65 of the BSIG
Particularly Important Facilities
Sectors in Annex 1 with at least 250 employees or annual revenue exceeding 50 million euros and total assets exceeding 43 million euros
Up to 10 million euros; for annual revenue exceeding 500 million euros, up to 2 percent of global revenue
Important Facilities
Sectors of Plants 1 and 2 with at least 50 employees or annual revenue and total assets exceeding 10 million euros
Up to 7 million euros; for annual revenue exceeding 500 million euros, up to 1.4 percent of global revenue
Operators of Critical Infrastructure (KRITIS)
Facilities that exceed the thresholds set by the BSI Critical Infrastructure Regulation, regardless of company size
Like particularly important institutions, they also have their own reporting obligations
Some organizations are subject to the law regardless of their size, including qualified trust service providers, top-level domain registries, and DNS service providers. Different thresholds apply to providers of public telecommunications services. The BSI offers a free compliance assessment on its website that allows you to determine your classification by answering a series of questions.
Overview of Obligations: Risk Management, Registration, Reporting
The centerpiece is Section 30 of the BSIG. It requires affected organizations to implement appropriate, proportionate, and effective technical and organizational measures. The law specifies a minimum set of requirements for this purpose:
Risk Analysis and Security Concepts for Information Systems
Security Incident Response
Backup Management, Recovery, and Crisis Management
Supply chain security, including direct suppliers and service providers
Security in the Acquisition, Development, and Maintenance of Systems
Approaches for Evaluating the Effectiveness of the Measures
Cyber Hygiene and Training
Cryptography and Encryption
Personnel Security, Access Control, and Facility Management
Multi-factor authentication and secure communication
You can find a detailed breakdown of all the measures in our article on the NIS2 Requirements and Mandatory Measures. The article on the requirements for service providers and suppliers discusses NIS2 Supply Chain Security. In addition, there is the requirement to register with the BSI and the multi-tiered reporting requirement for significant security incidents under Section 32 of the BSIG:
Announcement
Deadline
Contents
Initial Report
Immediately, no later than 24 hours after becoming aware of it
Suspicion of an unlawful act or potential cross-border implications
Follow-up Report
No later than 72 hours after becoming aware
Initial Assessment Including Severity, Impact, and Indicators of Compromise
Final Report
No later than one month after the follow-up report
Final report; if the incident is ongoing, provide an initial update
Fines and Executive Liability
The schedule of fines in Section 65 of the BSIG grades penalties according to the category and severity of the violation. For particularly important facilities, the range extends up to 10 million euros; for important facilities, up to 7 million euros. If global annual revenue exceeds 500 million euros, fines of up to 2 percent or 1.4 percent of that revenue may be imposed. Violations of registration and reporting requirements are also subject to fines.
Section 38 of the BSIG holds management personally accountable. Management must implement the risk management measures specified in Section 30 of the BSIG and oversee their implementation. Specialized departments and service providers may carry out the operational work, but oversight remains the responsibility of management. If members of management culpably violate these duties, they are liable to the institution for damages in accordance with the applicable rules of corporate law.
In addition, there is a personal training requirement: Members of management must regularly participate in cybersecurity training in order to assess risks and evaluate measures. Cybersecurity is thus a legally mandated management responsibility. In practice, this means that management needs a robust, transparent data foundation regarding its own risk profile in order to fulfill its monitoring obligation.
Schedule and Deadlines: Do Not Delay BSI Registration
Affected organizations must register with the BSI within three months of meeting the criteria. For companies that were already subject to the law when it took effect, this deadline expired on March 6, 2026. Registration is carried out via the BSI portal in conjunction with the organizational account „My Company Account,“ which requires an ELSTER certificate.
The response fell short of expectations. The BSI had granted a generous extension until July 31, 2026. According to heise online, 18,845 organizations had registered by that date—6,490 of which were classified as “particularly important” and 12,355 as “important”—while approximately 29,500 had been expected. Anyone affected who has not yet registered should do so immediately, as the requirement remains in effect and violations can be punished as administrative offenses.
Regardless of registration, the substantive obligations already apply. The BSI may conduct audits of compliance at any time for particularly important entities, and on an ad hoc basis for important entities. It is therefore advisable to maintain a documented record of the status of implementation even without a specific notice of an upcoming audit.
How Companies Are Responding Now
A pragmatic approach involves four steps. First: Determine whether you are affected—for example, using the BSI’s impact assessment—and complete the registration. Second: Assess the current state. This includes a risk analysis of your own IT infrastructure, as Section 30 of the BSIG mandates that a risk analysis be the first step in any action plan. Third: Prioritize and close gaps, ranging from backup strategies to encryption and multi-factor authentication. Fourth: Define reporting channels and responsibilities so that the 24-hour deadline can be met in the event of an emergency.
For the second step, External Attack Surface Management (EASM) A fact-based overview from an external perspective: Without requiring the installation of any agents, it shows which of your company’s systems, services, and software components are accessible from the Internet and where vulnerabilities exist. A KPI-Based Security Rating makes the status measurable and transparent to management, and also serves as recurring evidence to fulfill the monitoring obligation under § 38 BSIG.
When prioritizing new vulnerabilities, the recency of the data is also a factor. With Preemptive Intelligence LocateRisk cross-checks alerts from multiple sources against the visible attack surface even before a final NVD assessment is conducted. Such alerts supplement the risk analysis but do not replace technical verification on the affected system.
To put this in context: An external analysis is no substitute for an information security management system and does not always identify whether a specific software version in use is vulnerable. However, it does highlight which systems are exposed and where a more in-depth review should be conducted. To address the supply chain obligations under Section 30 of the BSIG, a Vendor Risk Management, which systematically evaluates service providers and suppliers.
Generally, not directly. Exceptions apply, among others, to qualified trust service providers, TLD registries, and DNS service providers, which are covered regardless of their size. Indirectly, however, NIS2 affects many smaller companies: Regulated customers must assess the security of their supply chain and pass on requirements to their service providers.
The registration requirement under Section 33 of the BSIG remains in effect even after the deadlines have passed. A violation may be punished as an administrative offense subject to a fine. In addition, the company will miss out on information from the BSI—such as warnings and situation reports—that is sent via the contact information on file.
ISO 27001 certification structurally addresses many of the requirements of Section 30 of the BSIG and serves as a solid foundation. However, it does not replace either the registration requirement or the reporting obligations, including their specific deadlines. Check the scope of the certificate: It must actually cover the relevant systems and processes.
The BSI provides an online compliance check featuring a questionnaire based on Section 28 of the BSIG and Annexes 1 and 2. The key factors are the sector, number of employees, annual revenue, and total assets. For corporate group structures and borderline cases, a supplementary legal assessment is recommended.
You must report significant security incidents to the BSI immediately, no later than 24 hours after becoming aware of them. A report containing an initial assessment must be submitted within 72 hours, and a final report must be submitted no later than one month afterward. If the incident is ongoing, a progress report will be submitted in its place for the time being.
Conclusion: Get a Clear Picture of Your Own Risk Profile Now
NIS2 is now law in Germany, with no general transition periods and with personal accountability resting with senior management. The first concrete step is to conduct an honest assessment of your organization’s attack surface. LocateRisk analyzes your externally visible IT infrastructure without requiring agent installation and delivers a KPI-based assessment within 48 hours—GDPR-compliant and hosted in certified German data centers. Get started with a IT Risk Analysis for Your Company and create the data foundation for your NIS2 implementation.
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.