NIS2 Requirements: The 10 Mandatory Measures Under Section 30 of the BSIG
This text was generated using artificial intelligence (AI).
The German NIS 2 Implementation Act has been in effect since December 6, 2025. Section 30 of the revised BSI Act (BSIG) requires affected companies to implement ten specific risk management measures. This article explains each measure individually, outlines its practical implementation, and maps the requirements to ISO 27001. As of August 2026.
The requirements are often referred to as NIS2 Requirements, Cybersecurity Risk Management Measures or Measures Pursuant to Section 30 of the BSIG . Section 30 of the BSIG specifies the obligations for particularly important and important facilities in Germany. This section is part of the German implementation and is not equivalent to the European directive itself.
Key Points at a Glance
The NIS-2 Implementation Act entered into force on December 6, 2025. Section 30 of the BSIG requires particularly important and important entities to implement ten risk management measures without a transition period.
According to the BSI, approximately 29,500 organizations in Germany are subject to the new requirements.
The ten measures range from risk analysis to supply chain security to multi-factor authentication. The benchmark is the state of the art.
Under Section 65 of the BSIG, the BSI may impose fines of up to 10 million euros for violations involving particularly important institutions and up to 7 million euros for important institutions. For total revenue of 500 million euros or more, the fines may amount to up to 2 percent or 1.4 percent of total revenue, respectively.
Management must implement the measures, monitor their implementation, and participate in training sessions on a regular basis. In the event of a culpable breach of duty, management is liable to its own institution (Section 38 BSIG).
Legal Framework: Who Is Subject to the NIS2 Requirements
The European NIS 2 Directive tightens cybersecurity requirements in the EU. Germany has transposed it into national law through the NIS 2 Implementation Act. The law took effect on December 6, 2025, and its centerpiece is the revised BSI Act. It distinguishes between particularly important facilities and important facilities. According to the BSI, approximately 29,500 organizations in Germany are subject to the new obligations. Whether your company is among them depends on its sector and size. The BSI’s impact assessment provides an initial, non-legally binding guide.
Important for planning: There is no transition period for the risk management measures required under Section 30 of the BSIG. Affected organizations must also register with the BSI in accordance with Section 33 of the BSIG no later than three months after they meet the criteria. The BSI may impose fines for violations of the mandatory measures under Section 65 of the BSIG: up to 10 million euros for particularly important organizations and up to 7 million euros for important organizations. For organizations with total revenue exceeding 500 million euros, the penalty range increases to up to 2 percent or 1.4 percent of total revenue, respectively. Section 38 of the BSIG also holds senior management personally accountable: They must implement the risk management measures, monitor their implementation, and are liable to the organization for any damage caused through negligence in accordance with the rules of corporate law applicable to its legal form. Our article on NIS2 Directive.
Measures 1 through 3: Risk Analysis, Incident Response, Business Continuity
Section 30(2) of the BSIG lists ten areas of action that the measures taken must at least cover. The list is therefore not exhaustive, but rather sets a mandatory minimum. The first three areas form the foundation of every security program.
Action 1: Risk Analysis and IT Security Strategies
Requirement 1 calls for approaches to risk analysis and information technology security. This refers to a documented security policy and a repeatable process that identifies, assesses, and addresses risks. To implement this, you first need a robust, well-maintained inventory of your systems. In practice, externally accessible assets are often missing from this inventory—such as forgotten subdomains, test systems, or cloud services used by individual departments. External Attack Surface Management provides this external perspective and, as a result, a reliable data foundation for risk analysis. Next, define evaluation criteria, assign responsibilities, and establish a treatment plan, and update the analysis at least once a year.
Action 2: Handling Security Incidents
Requirement 2 calls for processes to manage security incidents. These include an incident response plan with clear roles and escalation procedures, as well as playbooks for typical scenarios such as ransomware or compromised accounts. The plan must be aligned with the reporting requirements under Section 32 of the BSIG: Organizations must report significant security incidents to the BSI immediately, no later than within 24 hours. A follow-up report with an initial assessment must be submitted within 72 hours, and the final report no later than one month after the 72-hour report. Practice this procedure regularly to ensure that responsibilities and communication channels function properly in an emergency.
Measure 3: Maintaining Operations and Crisis Management
Number 3 requires the maintenance of operations. The text of the law explicitly mentions backup management, disaster recovery, and crisis management. In practice, this means: a backup strategy with backups stored separately and protected against modification, documented recovery plans with priorities for critical processes, and a crisis management team with defined communication channels. Test the recovery process regularly under realistic conditions. A backup that has never been tested for restoration remains a risk in the event of an emergency.
Measures 4 and 5: Supply Chain and Secure Procurement
Action 4: Supply Chain Security
Number 4 requires you to ensure supply chain security, including the security-related aspects of your relationships with direct suppliers and service providers. You must know which service providers have access to your systems or data and assess their security levels. Agree on contractual security requirements and continuously review critical suppliers. Our article on NIS2 Supply Chain Security. A Vendor Risk Management It combines questionnaires with an external technical assessment of suppliers and makes it possible to compare their security status.
Action 5: Security in Procurement, Development, and Maintenance
Number 5 concerns security measures for the procurement, development, and maintenance of IT systems, components, and processes. Define security requirements as early as the procurement phase—for example, regarding update delivery and secure default settings. For operations, you need a patch management system with clear deadlines and a process for addressing reported vulnerabilities. If you develop software in-house, you should implement secure development guidelines, code reviews, and testing. Decommissioned systems must be consistently shut down; otherwise, they remain accessible from the Internet as unmaintained legacy systems.
A robust vulnerability management process should not rely solely on final NVD assessments. With Preemptive Intelligence LocateRisk compares alerts from multiple sources with the visible attack surface at an early stage. This supports prioritization in patch and vulnerability management; however, a technical assessment to determine whether a specific system is affected is still required.
Measures 6 and 7: Measure effectiveness, embed cyber hygiene
Action 6: Evaluating the Effectiveness of the Measures
Number 6 calls for strategies and procedures to evaluate the effectiveness of risk management measures. It is not enough to implement measures just once; you must regularly measure their impact. Suitable metrics include patch lifetimes, internal audit results, and technical reviews. A KPI-based Security Rating It continuously monitors the security situation as it appears from the outside and makes changes over time traceable. This also provides management—which is required to oversee implementation in accordance with § 38 BSIG—with a clear basis for decision-making.
Measure 7: Training and Cyber Hygiene
Number 7 calls for comprehensive training and awareness-raising measures in the area of information technology security. Establish a recurring awareness program for all employees, featuring practical content on phishing, passwords, and how to handle suspicious incidents. In addition, cyber hygiene should be part of everyday practice: timely updates, minimal access privileges, and clear rules for mobile devices. Note the separate requirement under Section 38 of the BSIG: Management must regularly participate in training to be able to assess risks and risk management practices. This training requirement applies personally to members of management.
Measures 8 through 10: Cryptography, Personnel, and Authentication
Measure 8: Cryptography and Encryption
Requirement 8 calls for policies and processes for the use of cryptographic methods. Document which data you encrypt at rest and in transit, which methods are permitted, and how you generate, store, and renew keys. Check your externally accessible services for outdated protocols, expiring certificates, and weak TLS configurations. The BSI’s Technical Guideline TR-02102 provides guidance on recommended procedures and key lengths.
Measure 9: Personnel Security, Access Control, and Asset Management
Number 9 covers concepts for staff security, access control, and the management of ICT systems, products, and processes. Regulate employee onboarding, role changes, and departure with clear authorization processes. Grant access according to the need-to-know principle and recertify access rights regularly. The foundation for this is a well-maintained asset inventory: Only those who know which systems exist and who is responsible for them can properly control access.
Action 10: Multi-factor authentication and secure communication
Number 10 requires the use of multi-factor authentication or continuous authentication solutions, as well as secure voice, video, and text communication and, where applicable, secure emergency communication systems. Prioritize MFA for administrator accounts, remote access, and externally accessible login screens. Check your communication tools for transport encryption and access protection. Additionally, plan a communication channel for crisis situations that functions independently of the primary infrastructure, which may have been compromised.
ISO 27001 Mapping: Leveraging Existing Structures
The content of these ten measures overlaps significantly with the requirements of ISO/IEC 27001:2022. Organizations that already operate an information security management system can reuse much of their documentation. The following mapping serves as a guide for a gap analysis. It does not replace a case-by-case review, as Section 30 of the BSIG is, in some respects, more specific than the standard.
No.
Measure pursuant to Section 30(2) of the BSIG
ISO/IEC 27001:2022 (Selection)
1
Risk Analysis and IT Security Strategies
Chapters 6.1.2 and 8.2, Control 5.1
2
Security Incident Response
Controls 5.24 through 5.28
3
Business Continuity, Backup, Crisis Management
Controls 5.29, 5.30, 8.13, 8.14
4
Supply Chain Security
Controls 5.19 through 5.22
5
Acquisition, Development, and Maintenance
Controls 8.25 through 8.31, 5.23
6
Assessment of Effectiveness
Chapters 9.1 through 9.3
7
Training and Cyber Hygiene
Chapters 7.2 and 7.3, Controls 6.3, 8.7
8
Cryptography and Encryption
Control 8.24
9
Human Resources, Access Control, Asset Management
Controls 6.1 through 6.5, 5.15 through 5.18, 5.9
10
MFA and Secure Communication
Controls 8.5, 5.14, 5.17
An existing certification does not automatically fulfill legal obligations. Registration, reporting requirements, and the obligations of management continue to apply regardless of the management system.
Prioritization Roadmap: Implementation in Three Phases
Legally, all ten measures take effect immediately. In practice, however, companies need to implement them in a specific order. The following roadmap prioritizes the measures based on risk and effort. It is a recommendation, not a legally mandated sequence.
Phase 1 (Months 1 through 3): Transparency and Responsibilities
Determine whether you are affected by conducting the BSI impact assessment and complete registration in accordance with Section 33 of the BSIG
Define responsibilities, the budget, and the reporting structure to senior management
Systematically identify assets and the attack surface; conduct an initial risk analysis (Action 1)
Establish the reporting process under Section 32 of the BSIG, including templates and responsibilities (Action 2)
Implement immediate measures: MFA for administrator and remote access, test backup and recovery (Measures 3 and 10)
Phase 2 (Months 4 through 9): Concepts and Processes
Document concepts for cryptography, access control, and personnel security (Measures 8 and 9)
Inventory and evaluate suppliers, and review contractual requirements (Action 4)
Define Procurement, Patch, and Vulnerability Management Processes (Action 5)
Launch a training program for employees and management (Action 7)
Expand emergency and crisis management capabilities and conduct a drill (Action 3)
Phase 3 (starting in Month 10): Effectiveness and Improvement
Define key performance indicators and report them regularly to management (Action 6)
Conduct a Gap Analysis Against ISO 27001 or an Internal Audit
Establish continuous monitoring of your own attack surface
Update risk analyses and plans at least once a year
No. The obligations under Section 30 of the BSIG have been in effect since the NIS-2 Implementation Act took effect on December 6, 2025. There is no statutory grace period for the technical and organizational measures. Section 33 of the BSIG grants a three-month period for registration with the BSI only after an organization has met the criteria.
Certification covers many requirements in terms of content and serves as a solid foundation. However, it does not automatically replace legal obligations. Registration, reporting requirements, and the obligations of management apply regardless of the management system. A gap analysis shows where your existing ISMS already meets the requirements of Section 30(2) of the BSIG and where gaps remain.
Section 65 of the BSIG provides for fines of up to 10 million euros for particularly important institutions and up to 7 million euros for important institutions. If an institution’s total revenue exceeds 500 million euros, the fine range increases to up to 2 percent or 1.4 percent of total revenue, respectively. The specific amount depends on the circumstances of the individual case, in particular the nature, severity, and duration of the violation. In addition, under § 38 BSIG, management is liable to its own organization if it culpably violates its implementation and monitoring obligations.
According to Section 30(2) of the BSIG, the measures must comply with the state of the art and take into account the relevant European and international standards. The term is intentionally dynamic: What is appropriate today may be outdated in a few years. Guidance is provided by the BSI’s IT-Grundschutz, the BSI’s Technical Guidelines, and the ISO 27001 family of standards. At the same time, Section 30(1) of the BSIG requires proportionate measures: Factors such as the size of the organization, its risk exposure, and implementation costs are taken into account in the assessment.
Conclusion: Start by gaining transparency into your attack surface
The ten mandatory measures under Section 30 of the BSIG are not a one-time project, but rather an ongoing process consisting of analysis, implementation, and monitoring. The most effective first step is to ensure transparency regarding one’s own vulnerabilities, because without a reliable external perspective, the risk analysis lacks important foundational information. A IT Risk Analysis by LocateRisk Within 48 hours, it shows you which of your company's systems and software applications are visible on the Internet and where action is needed—all without installing any agents.
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.