+49 6151 6290246

Published: August 6, 2026

NIS2 Requirements: The 10 Mandatory Measures Under Section 30 of the BSIG

This text was generated using artificial intelligence (AI).

The German NIS 2 Implementation Act has been in effect since December 6, 2025. Section 30 of the revised BSI Act (BSIG) requires affected companies to implement ten specific risk management measures. This article explains each measure individually, outlines its practical implementation, and maps the requirements to ISO 27001. As of August 2026.

The requirements are often referred to as NIS2 Requirements, Cybersecurity Risk Management Measures or Measures Pursuant to Section 30 of the BSIG . Section 30 of the BSIG specifies the obligations for particularly important and important facilities in Germany. This section is part of the German implementation and is not equivalent to the European directive itself.

Key Points at a Glance

Legal Framework: Who Is Subject to the NIS2 Requirements

The European NIS 2 Directive tightens cybersecurity requirements in the EU. Germany has transposed it into national law through the NIS 2 Implementation Act. The law took effect on December 6, 2025, and its centerpiece is the revised BSI Act. It distinguishes between particularly important facilities and important facilities. According to the BSI, approximately 29,500 organizations in Germany are subject to the new obligations. Whether your company is among them depends on its sector and size. The BSI’s impact assessment provides an initial, non-legally binding guide.

Important for planning: There is no transition period for the risk management measures required under Section 30 of the BSIG. Affected organizations must also register with the BSI in accordance with Section 33 of the BSIG no later than three months after they meet the criteria. The BSI may impose fines for violations of the mandatory measures under Section 65 of the BSIG: up to 10 million euros for particularly important organizations and up to 7 million euros for important organizations. For organizations with total revenue exceeding 500 million euros, the penalty range increases to up to 2 percent or 1.4 percent of total revenue, respectively. Section 38 of the BSIG also holds senior management personally accountable: They must implement the risk management measures, monitor their implementation, and are liable to the organization for any damage caused through negligence in accordance with the rules of corporate law applicable to its legal form. Our article on NIS2 Directive.

Measures 1 through 3: Risk Analysis, Incident Response, Business Continuity

Section 30(2) of the BSIG lists ten areas of action that the measures taken must at least cover. The list is therefore not exhaustive, but rather sets a mandatory minimum. The first three areas form the foundation of every security program.

Action 1: Risk Analysis and IT Security Strategies

Requirement 1 calls for approaches to risk analysis and information technology security. This refers to a documented security policy and a repeatable process that identifies, assesses, and addresses risks. To implement this, you first need a robust, well-maintained inventory of your systems. In practice, externally accessible assets are often missing from this inventory—such as forgotten subdomains, test systems, or cloud services used by individual departments. External Attack Surface Management provides this external perspective and, as a result, a reliable data foundation for risk analysis. Next, define evaluation criteria, assign responsibilities, and establish a treatment plan, and update the analysis at least once a year.

Action 2: Handling Security Incidents

Requirement 2 calls for processes to manage security incidents. These include an incident response plan with clear roles and escalation procedures, as well as playbooks for typical scenarios such as ransomware or compromised accounts. The plan must be aligned with the reporting requirements under Section 32 of the BSIG: Organizations must report significant security incidents to the BSI immediately, no later than within 24 hours. A follow-up report with an initial assessment must be submitted within 72 hours, and the final report no later than one month after the 72-hour report. Practice this procedure regularly to ensure that responsibilities and communication channels function properly in an emergency.

Measure 3: Maintaining Operations and Crisis Management

Number 3 requires the maintenance of operations. The text of the law explicitly mentions backup management, disaster recovery, and crisis management. In practice, this means: a backup strategy with backups stored separately and protected against modification, documented recovery plans with priorities for critical processes, and a crisis management team with defined communication channels. Test the recovery process regularly under realistic conditions. A backup that has never been tested for restoration remains a risk in the event of an emergency.

Measures 4 and 5: Supply Chain and Secure Procurement

Action 4: Supply Chain Security

Number 4 requires you to ensure supply chain security, including the security-related aspects of your relationships with direct suppliers and service providers. You must know which service providers have access to your systems or data and assess their security levels. Agree on contractual security requirements and continuously review critical suppliers. Our article on NIS2 Supply Chain Security. A Vendor Risk Management It combines questionnaires with an external technical assessment of suppliers and makes it possible to compare their security status.

Action 5: Security in Procurement, Development, and Maintenance

Number 5 concerns security measures for the procurement, development, and maintenance of IT systems, components, and processes. Define security requirements as early as the procurement phase—for example, regarding update delivery and secure default settings. For operations, you need a patch management system with clear deadlines and a process for addressing reported vulnerabilities. If you develop software in-house, you should implement secure development guidelines, code reviews, and testing. Decommissioned systems must be consistently shut down; otherwise, they remain accessible from the Internet as unmaintained legacy systems.

A robust vulnerability management process should not rely solely on final NVD assessments. With Preemptive Intelligence LocateRisk compares alerts from multiple sources with the visible attack surface at an early stage. This supports prioritization in patch and vulnerability management; however, a technical assessment to determine whether a specific system is affected is still required.

Measures 6 and 7: Measure effectiveness, embed cyber hygiene

Action 6: Evaluating the Effectiveness of the Measures

Number 6 calls for strategies and procedures to evaluate the effectiveness of risk management measures. It is not enough to implement measures just once; you must regularly measure their impact. Suitable metrics include patch lifetimes, internal audit results, and technical reviews. A KPI-based Security Rating It continuously monitors the security situation as it appears from the outside and makes changes over time traceable. This also provides management—which is required to oversee implementation in accordance with § 38 BSIG—with a clear basis for decision-making.

Measure 7: Training and Cyber Hygiene

Number 7 calls for comprehensive training and awareness-raising measures in the area of information technology security. Establish a recurring awareness program for all employees, featuring practical content on phishing, passwords, and how to handle suspicious incidents. In addition, cyber hygiene should be part of everyday practice: timely updates, minimal access privileges, and clear rules for mobile devices. Note the separate requirement under Section 38 of the BSIG: Management must regularly participate in training to be able to assess risks and risk management practices. This training requirement applies personally to members of management.

Measures 8 through 10: Cryptography, Personnel, and Authentication

Measure 8: Cryptography and Encryption

Requirement 8 calls for policies and processes for the use of cryptographic methods. Document which data you encrypt at rest and in transit, which methods are permitted, and how you generate, store, and renew keys. Check your externally accessible services for outdated protocols, expiring certificates, and weak TLS configurations. The BSI’s Technical Guideline TR-02102 provides guidance on recommended procedures and key lengths.

Measure 9: Personnel Security, Access Control, and Asset Management

Number 9 covers concepts for staff security, access control, and the management of ICT systems, products, and processes. Regulate employee onboarding, role changes, and departure with clear authorization processes. Grant access according to the need-to-know principle and recertify access rights regularly. The foundation for this is a well-maintained asset inventory: Only those who know which systems exist and who is responsible for them can properly control access.

Action 10: Multi-factor authentication and secure communication

Number 10 requires the use of multi-factor authentication or continuous authentication solutions, as well as secure voice, video, and text communication and, where applicable, secure emergency communication systems. Prioritize MFA for administrator accounts, remote access, and externally accessible login screens. Check your communication tools for transport encryption and access protection. Additionally, plan a communication channel for crisis situations that functions independently of the primary infrastructure, which may have been compromised.

ISO 27001 Mapping: Leveraging Existing Structures

The content of these ten measures overlaps significantly with the requirements of ISO/IEC 27001:2022. Organizations that already operate an information security management system can reuse much of their documentation. The following mapping serves as a guide for a gap analysis. It does not replace a case-by-case review, as Section 30 of the BSIG is, in some respects, more specific than the standard.

No.Measure pursuant to Section 30(2) of the BSIGISO/IEC 27001:2022 (Selection)
1Risk Analysis and IT Security StrategiesChapters 6.1.2 and 8.2, Control 5.1
2Security Incident ResponseControls 5.24 through 5.28
3Business Continuity, Backup, Crisis ManagementControls 5.29, 5.30, 8.13, 8.14
4Supply Chain SecurityControls 5.19 through 5.22
5Acquisition, Development, and MaintenanceControls 8.25 through 8.31, 5.23
6Assessment of EffectivenessChapters 9.1 through 9.3
7Training and Cyber HygieneChapters 7.2 and 7.3, Controls 6.3, 8.7
8Cryptography and EncryptionControl 8.24
9Human Resources, Access Control, Asset ManagementControls 6.1 through 6.5, 5.15 through 5.18, 5.9
10MFA and Secure CommunicationControls 8.5, 5.14, 5.17

An existing certification does not automatically fulfill legal obligations. Registration, reporting requirements, and the obligations of management continue to apply regardless of the management system.

Prioritization Roadmap: Implementation in Three Phases

Legally, all ten measures take effect immediately. In practice, however, companies need to implement them in a specific order. The following roadmap prioritizes the measures based on risk and effort. It is a recommendation, not a legally mandated sequence.

Phase 1 (Months 1 through 3): Transparency and Responsibilities

Phase 2 (Months 4 through 9): Concepts and Processes

Phase 3 (starting in Month 10): Effectiveness and Improvement

Frequently asked questions


No. The obligations under Section 30 of the BSIG have been in effect since the NIS-2 Implementation Act took effect on December 6, 2025. There is no statutory grace period for the technical and organizational measures. Section 33 of the BSIG grants a three-month period for registration with the BSI only after an organization has met the criteria.


Certification covers many requirements in terms of content and serves as a solid foundation. However, it does not automatically replace legal obligations. Registration, reporting requirements, and the obligations of management apply regardless of the management system. A gap analysis shows where your existing ISMS already meets the requirements of Section 30(2) of the BSIG and where gaps remain.


Section 65 of the BSIG provides for fines of up to 10 million euros for particularly important institutions and up to 7 million euros for important institutions. If an institution’s total revenue exceeds 500 million euros, the fine range increases to up to 2 percent or 1.4 percent of total revenue, respectively. The specific amount depends on the circumstances of the individual case, in particular the nature, severity, and duration of the violation. In addition, under § 38 BSIG, management is liable to its own organization if it culpably violates its implementation and monitoring obligations.


According to Section 30(2) of the BSIG, the measures must comply with the state of the art and take into account the relevant European and international standards. The term is intentionally dynamic: What is appropriate today may be outdated in a few years. Guidance is provided by the BSI’s IT-Grundschutz, the BSI’s Technical Guidelines, and the ISO 27001 family of standards. At the same time, Section 30(1) of the BSIG requires proportionate measures: Factors such as the size of the organization, its risk exposure, and implementation costs are taken into account in the assessment.

Conclusion: Start by gaining transparency into your attack surface

The ten mandatory measures under Section 30 of the BSIG are not a one-time project, but rather an ongoing process consisting of analysis, implementation, and monitoring. The most effective first step is to ensure transparency regarding one’s own vulnerabilities, because without a reliable external perspective, the risk analysis lacks important foundational information. A IT Risk Analysis by LocateRisk Within 48 hours, it shows you which of your company's systems and software applications are visible on the Internet and where action is needed—all without installing any agents.


Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!

Your personal consultantLukas BaumannCEO

+49 6151 6290246

Get in Touch Now

en_USEnglish