+49 6151 6290246

Published: August 6, 2026

NIS2 Directive: What Companies Need to Know Now

This text was generated using artificial intelligence (AI).

The NIS2 Directive requires significantly more companies than before to implement cybersecurity measures, follow reporting procedures, and register with the BSI. The German NIS2 Implementation Act (NIS2UmsuCG) has been in effect since December 6, 2025, with no general transition periods. This overview explains who is affected, what obligations apply, what fines may be imposed, and what deadlines you should be aware of. As of August 2026.

Key Points at a Glance

What is the NIS2 Directive?

NIS2 stands for the second EU Directive on Network and Information Security. Directive (EU) 2022/2555 entered into force on January 16, 2023, and replaces the first NIS Directive from 2016. Its goal is to ensure a uniformly high level of cybersecurity throughout the European Union.

Compared to the previous directive, NIS2 significantly expands its scope. It covers more sectors, lowers the size thresholds, and standardizes reporting requirements, oversight, and sanctions. Another new feature is the explicit responsibility of management bodies: executive boards and management teams must approve cybersecurity measures, monitor their implementation, and undergo regular training.

Member States were required to transpose the directive into national law by October 17, 2024. Germany missed this deadline and did not complete implementation until the end of 2025. Since then, the German implementing law has been the sole source of law for affected companies, as the directive itself does not impose any direct obligations on companies.

NIS2UmsuCG: The German Implementation Act has been in effect since December 2025

On November 13, 2025, the Bundestag passed the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG). According to the BSI, following its publication in the Federal Law Gazette on December 5, 2025, the law has been in effect since December 6, 2025. At the heart of the law is a comprehensive revision of the BSI Act (BSIG), which governs requirements, reporting channels, and oversight.

Important for practical implementation: The law does not provide for any general transition periods. The obligations regarding risk management, registration, and reporting have been in effect since the law took effect. The BSI is the central supervisory authority and provides a dedicated portal as well as a tool for assessing whether an organization is affected.

The BSIG distinguishes between two new categories: particularly important facilities and important facilities. Operators of critical infrastructure (KRITIS) remain a separate group subject to additional requirements, such as regular compliance audits. According to the BSI, this will expand the number of supervised facilities from around 4,500 to approximately 29,500.

Who is affected? Sectors and size thresholds

Whether a company falls under the scope of the BSIG depends on two factors: the sector and the company’s size. Annexes 1 and 2 of the BSIG list a total of 18 sectors. These include, among others, energy, transportation and traffic, finance, healthcare, drinking water and wastewater, digital infrastructure, public administration, postal and courier services, waste management, chemicals, food, the manufacturing industry, as well as digital service providers and research institutions.

CategoryCriteria under Section 28 of the BSIGRange of Fines Under Section 65 of the BSIG
Particularly Important FacilitiesSectors in Annex 1 with at least 250 employees or annual revenue exceeding 50 million euros and total assets exceeding 43 million eurosUp to 10 million euros; for annual revenue exceeding 500 million euros, up to 2 percent of global revenue
Important FacilitiesSectors of Plants 1 and 2 with at least 50 employees or annual revenue and total assets exceeding 10 million eurosUp to 7 million euros; for annual revenue exceeding 500 million euros, up to 1.4 percent of global revenue
Operators of Critical Infrastructure (KRITIS)Facilities that exceed the thresholds set by the BSI Critical Infrastructure Regulation, regardless of company sizeLike particularly important institutions, they also have their own reporting obligations

Some organizations are subject to the law regardless of their size, including qualified trust service providers, top-level domain registries, and DNS service providers. Different thresholds apply to providers of public telecommunications services. The BSI offers a free compliance assessment on its website that allows you to determine your classification by answering a series of questions.

Overview of Obligations: Risk Management, Registration, Reporting

The centerpiece is Section 30 of the BSIG. It requires affected organizations to implement appropriate, proportionate, and effective technical and organizational measures. The law specifies a minimum set of requirements for this purpose:

You can find a detailed breakdown of all the measures in our article on the NIS2 Requirements and Mandatory Measures. The article on the requirements for service providers and suppliers discusses NIS2 Supply Chain Security. In addition, there is the requirement to register with the BSI and the multi-tiered reporting requirement for significant security incidents under Section 32 of the BSIG:

AnnouncementDeadlineContents
Initial ReportImmediately, no later than 24 hours after becoming aware of itSuspicion of an unlawful act or potential cross-border implications
Follow-up ReportNo later than 72 hours after becoming awareInitial Assessment Including Severity, Impact, and Indicators of Compromise
Final ReportNo later than one month after the follow-up reportFinal report; if the incident is ongoing, provide an initial update

Fines and Executive Liability

The schedule of fines in Section 65 of the BSIG grades penalties according to the category and severity of the violation. For particularly important facilities, the range extends up to 10 million euros; for important facilities, up to 7 million euros. If global annual revenue exceeds 500 million euros, fines of up to 2 percent or 1.4 percent of that revenue may be imposed. Violations of registration and reporting requirements are also subject to fines.

Section 38 of the BSIG holds management personally accountable. Management must implement the risk management measures specified in Section 30 of the BSIG and oversee their implementation. Specialized departments and service providers may carry out the operational work, but oversight remains the responsibility of management. If members of management culpably violate these duties, they are liable to the institution for damages in accordance with the applicable rules of corporate law.

In addition, there is a personal training requirement: Members of management must regularly participate in cybersecurity training in order to assess risks and evaluate measures. Cybersecurity is thus a legally mandated management responsibility. In practice, this means that management needs a robust, transparent data foundation regarding its own risk profile in order to fulfill its monitoring obligation.

Schedule and Deadlines: Do Not Delay BSI Registration

Affected organizations must register with the BSI within three months of meeting the criteria. For companies that were already subject to the law when it took effect, this deadline expired on March 6, 2026. Registration is carried out via the BSI portal in conjunction with the organizational account „My Company Account,“ which requires an ELSTER certificate.

The response fell short of expectations. The BSI had granted a generous extension until July 31, 2026. According to heise online, 18,845 organizations had registered by that date—6,490 of which were classified as “particularly important” and 12,355 as “important”—while approximately 29,500 had been expected. Anyone affected who has not yet registered should do so immediately, as the requirement remains in effect and violations can be punished as administrative offenses.

Regardless of registration, the substantive obligations already apply. The BSI may conduct audits of compliance at any time for particularly important entities, and on an ad hoc basis for important entities. It is therefore advisable to maintain a documented record of the status of implementation even without a specific notice of an upcoming audit.

How Companies Are Responding Now

A pragmatic approach involves four steps. First: Determine whether you are affected—for example, using the BSI’s impact assessment—and complete the registration. Second: Assess the current state. This includes a risk analysis of your own IT infrastructure, as Section 30 of the BSIG mandates that a risk analysis be the first step in any action plan. Third: Prioritize and close gaps, ranging from backup strategies to encryption and multi-factor authentication. Fourth: Define reporting channels and responsibilities so that the 24-hour deadline can be met in the event of an emergency.

For the second step, External Attack Surface Management (EASM) A fact-based overview from an external perspective: Without requiring the installation of any agents, it shows which of your company’s systems, services, and software components are accessible from the Internet and where vulnerabilities exist. A KPI-Based Security Rating makes the status measurable and transparent to management, and also serves as recurring evidence to fulfill the monitoring obligation under § 38 BSIG.

When prioritizing new vulnerabilities, the recency of the data is also a factor. With Preemptive Intelligence LocateRisk cross-checks alerts from multiple sources against the visible attack surface even before a final NVD assessment is conducted. Such alerts supplement the risk analysis but do not replace technical verification on the affected system.

To put this in context: An external analysis is no substitute for an information security management system and does not always identify whether a specific software version in use is vulnerable. However, it does highlight which systems are exposed and where a more in-depth review should be conducted. To address the supply chain obligations under Section 30 of the BSIG, a Vendor Risk Management, which systematically evaluates service providers and suppliers.

Frequently asked questions


Generally, not directly. Exceptions apply, among others, to qualified trust service providers, TLD registries, and DNS service providers, which are covered regardless of their size. Indirectly, however, NIS2 affects many smaller companies: Regulated customers must assess the security of their supply chain and pass on requirements to their service providers.


The registration requirement under Section 33 of the BSIG remains in effect even after the deadlines have passed. A violation may be punished as an administrative offense subject to a fine. In addition, the company will miss out on information from the BSI—such as warnings and situation reports—that is sent via the contact information on file.


ISO 27001 certification structurally addresses many of the requirements of Section 30 of the BSIG and serves as a solid foundation. However, it does not replace either the registration requirement or the reporting obligations, including their specific deadlines. Check the scope of the certificate: It must actually cover the relevant systems and processes.


The BSI provides an online compliance check featuring a questionnaire based on Section 28 of the BSIG and Annexes 1 and 2. The key factors are the sector, number of employees, annual revenue, and total assets. For corporate group structures and borderline cases, a supplementary legal assessment is recommended.


You must report significant security incidents to the BSI immediately, no later than 24 hours after becoming aware of them. A report containing an initial assessment must be submitted within 72 hours, and a final report must be submitted no later than one month afterward. If the incident is ongoing, a progress report will be submitted in its place for the time being.

Conclusion: Get a Clear Picture of Your Own Risk Profile Now

NIS2 is now law in Germany, with no general transition periods and with personal accountability resting with senior management. The first concrete step is to conduct an honest assessment of your organization’s attack surface. LocateRisk analyzes your externally visible IT infrastructure without requiring agent installation and delivers a KPI-based assessment within 48 hours—GDPR-compliant and hosted in certified German data centers. Get started with a IT Risk Analysis for Your Company and create the data foundation for your NIS2 implementation.


Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!

Your personal consultantLukas BaumannCEO

+49 6151 6290246

Get in Touch Now

en_USEnglish