{"id":9294,"date":"2026-08-06T10:03:35","date_gmt":"2026-08-06T10:03:35","guid":{"rendered":"http:\/\/locaterisk.com\/de\/?post_type=wissen&#038;p=9294"},"modified":"2026-08-06T10:43:24","modified_gmt":"2026-08-06T10:43:24","slug":"nis2-directive-overview","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/nis2-directive-overview\/","title":{"rendered":"NIS2 Directive: What Companies Need to Know Now"},"content":{"rendered":"<h1 class=\"wp-block-heading\">NIS2 Directive: What Companies Need to Know Now<\/h1><span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n\n<p>The NIS2 Directive requires significantly more companies than before to implement cybersecurity measures, follow reporting procedures, and register with the BSI. The German NIS2 Implementation Act (NIS2UmsuCG) has been in effect since December 6, 2025, with no general transition periods. This overview explains who is affected, what obligations apply, what fines may be imposed, and what deadlines you should be aware of. As of August 2026.<\/p>\n\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n\n<ul class=\"wp-block-list\"><li>The NIS2 Directive (EU) 2022\/2555 has been in effect since January 16, 2023. Germany has implemented it through the NIS2 Implementation Act (NIS2UmsuCG), which has been in effect since December 6, 2025.<\/li><li>According to the BSI, the number of regulated entities is rising from about 4,500 to approximately 29,500. This affects companies in 18 sectors with 50 or more employees or annual revenue and total assets of 10 million euros.<\/li><li>These obligations include risk management in accordance with Section 30 of the BSIG, registration with the BSI, and reporting significant security incidents within 24 hours.<\/li><li>Fines can reach up to 10 million euros; for organizations with annual revenue exceeding 500 million euros, fines can amount to up to 2 percent of global revenue. Management must personally oversee implementation and is liable for culpable breaches of duty.<\/li><li>The law does not provide for any general transition periods. Anyone affected who has not yet registered should do so now.<\/li><\/ul>\n\n<h2 class=\"wp-block-heading\">What is the NIS2 Directive?<\/h2>\n\n<p>NIS2 stands for the second EU Directive on Network and Information Security. Directive (EU) 2022\/2555 entered into force on January 16, 2023, and replaces the first NIS Directive from 2016. Its goal is to ensure a uniformly high level of cybersecurity throughout the European Union.<\/p>\n\n<p>Compared to the previous directive, NIS2 significantly expands its scope. It covers more sectors, lowers the size thresholds, and standardizes reporting requirements, oversight, and sanctions. Another new feature is the explicit responsibility of management bodies: executive boards and management teams must approve cybersecurity measures, monitor their implementation, and undergo regular training.<\/p>\n\n<p>Member States were required to transpose the directive into national law by October 17, 2024. Germany missed this deadline and did not complete implementation until the end of 2025. Since then, the German implementing law has been the sole source of law for affected companies, as the directive itself does not impose any direct obligations on companies.<\/p>\n\n<h2 class=\"wp-block-heading\">NIS2UmsuCG: The German Implementation Act has been in effect since December 2025<\/h2>\n\n<p>On November 13, 2025, the Bundestag passed the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG). According to the BSI, following its publication in the Federal Law Gazette on December 5, 2025, the law has been in effect since December 6, 2025. At the heart of the law is a comprehensive revision of the BSI Act (BSIG), which governs requirements, reporting channels, and oversight.<\/p>\n\n<p>Important for practical implementation: The law does not provide for any general transition periods. The obligations regarding risk management, registration, and reporting have been in effect since the law took effect. The BSI is the central supervisory authority and provides a dedicated portal as well as a tool for assessing whether an organization is affected.<\/p>\n\n<p>The BSIG distinguishes between two new categories: particularly important facilities and important facilities. Operators of critical infrastructure (KRITIS) remain a separate group subject to additional requirements, such as regular compliance audits. According to the BSI, this will expand the number of supervised facilities from around 4,500 to approximately 29,500.<\/p>\n\n<h2 class=\"wp-block-heading\">Who is affected? Sectors and size thresholds<\/h2>\n\n<p>Whether a company falls under the scope of the BSIG depends on two factors: the sector and the company\u2019s size. Annexes 1 and 2 of the BSIG list a total of 18 sectors. These include, among others, energy, transportation and traffic, finance, healthcare, drinking water and wastewater, digital infrastructure, public administration, postal and courier services, waste management, chemicals, food, the manufacturing industry, as well as digital service providers and research institutions.<\/p>\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Category<\/th><th>Criteria under Section 28 of the BSIG<\/th><th>Range of Fines Under Section 65 of the BSIG<\/th><\/tr><\/thead><tbody><tr><td>Particularly Important Facilities<\/td><td>Sectors in Annex 1 with at least 250 employees or annual revenue exceeding 50 million euros and total assets exceeding 43 million euros<\/td><td>Up to 10 million euros; for annual revenue exceeding 500 million euros, up to 2 percent of global revenue<\/td><\/tr><tr><td>Important Facilities<\/td><td>Sectors of Plants 1 and 2 with at least 50 employees or annual revenue and total assets exceeding 10 million euros<\/td><td>Up to 7 million euros; for annual revenue exceeding 500 million euros, up to 1.4 percent of global revenue<\/td><\/tr><tr><td>Operators of Critical Infrastructure (KRITIS)<\/td><td>Facilities that exceed the thresholds set by the BSI Critical Infrastructure Regulation, regardless of company size<\/td><td>Like particularly important institutions, they also have their own reporting obligations<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<p>Some organizations are subject to the law regardless of their size, including qualified trust service providers, top-level domain registries, and DNS service providers. Different thresholds apply to providers of public telecommunications services. The BSI offers a free compliance assessment on its website that allows you to determine your classification by answering a series of questions.<\/p>\n\n<h2 class=\"wp-block-heading\">Overview of Obligations: Risk Management, Registration, Reporting<\/h2>\n\n<p>The centerpiece is Section 30 of the BSIG. It requires affected organizations to implement appropriate, proportionate, and effective technical and organizational measures. The law specifies a minimum set of requirements for this purpose:<\/p>\n\n<ul class=\"wp-block-list\"><li>Risk Analysis and Security Concepts for Information Systems<\/li><li>Security Incident Response<\/li><li>Backup Management, Recovery, and Crisis Management<\/li><li>Supply chain security, including direct suppliers and service providers<\/li><li>Security in the Acquisition, Development, and Maintenance of Systems<\/li><li>Approaches for Evaluating the Effectiveness of the Measures<\/li><li>Cyber Hygiene and Training<\/li><li>Cryptography and Encryption<\/li><li>Personnel Security, Access Control, and Facility Management<\/li><li>Multi-factor authentication and secure communication<\/li><\/ul>\n\n<p>You can find a detailed breakdown of all the measures in our article on the <a href=\"\/en\/know\/nis2-requirements-mandatory-measures\/\">NIS2 Requirements and Mandatory Measures<\/a>. The article on the requirements for service providers and suppliers discusses <a href=\"\/en\/know\/nis2-supply-chain-security\/\">NIS2 Supply Chain Security<\/a>. In addition, there is the requirement to register with the BSI and the multi-tiered reporting requirement for significant security incidents under Section 32 of the BSIG:<\/p>\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Announcement<\/th><th>Deadline<\/th><th>Contents<\/th><\/tr><\/thead><tbody><tr><td>Initial Report<\/td><td>Immediately, no later than 24 hours after becoming aware of it<\/td><td>Suspicion of an unlawful act or potential cross-border implications<\/td><\/tr><tr><td>Follow-up Report<\/td><td>No later than 72 hours after becoming aware<\/td><td>Initial Assessment Including Severity, Impact, and Indicators of Compromise<\/td><\/tr><tr><td>Final Report<\/td><td>No later than one month after the follow-up report<\/td><td>Final report; if the incident is ongoing, provide an initial update<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<h2 class=\"wp-block-heading\">Fines and Executive Liability<\/h2>\n\n<p>The schedule of fines in Section 65 of the BSIG grades penalties according to the category and severity of the violation. For particularly important facilities, the range extends up to 10 million euros; for important facilities, up to 7 million euros. If global annual revenue exceeds 500 million euros, fines of up to 2 percent or 1.4 percent of that revenue may be imposed. Violations of registration and reporting requirements are also subject to fines.<\/p>\n\n<p>Section 38 of the BSIG holds management personally accountable. Management must implement the risk management measures specified in Section 30 of the BSIG and oversee their implementation. Specialized departments and service providers may carry out the operational work, but oversight remains the responsibility of management. If members of management culpably violate these duties, they are liable to the institution for damages in accordance with the applicable rules of corporate law.<\/p>\n\n<p>In addition, there is a personal training requirement: Members of management must regularly participate in cybersecurity training in order to assess risks and evaluate measures. Cybersecurity is thus a legally mandated management responsibility. In practice, this means that management needs a robust, transparent data foundation regarding its own risk profile in order to fulfill its monitoring obligation.<\/p>\n\n<h2 class=\"wp-block-heading\">Schedule and Deadlines: Do Not Delay BSI Registration<\/h2>\n\n<p>Affected organizations must register with the BSI within three months of meeting the criteria. For companies that were already subject to the law when it took effect, this deadline expired on March 6, 2026. Registration is carried out via the BSI portal in conjunction with the organizational account \u201eMy Company Account,\u201c which requires an ELSTER certificate.<\/p>\n\n<p>The response fell short of expectations. The BSI had granted a generous extension until July 31, 2026. According to heise online, 18,845 organizations had registered by that date\u20146,490 of which were classified as \u201cparticularly important\u201d and 12,355 as \u201cimportant\u201d\u2014while approximately 29,500 had been expected. Anyone affected who has not yet registered should do so immediately, as the requirement remains in effect and violations can be punished as administrative offenses.<\/p>\n\n<p>Regardless of registration, the substantive obligations already apply. The BSI may conduct audits of compliance at any time for particularly important entities, and on an ad hoc basis for important entities. It is therefore advisable to maintain a documented record of the status of implementation even without a specific notice of an upcoming audit.<\/p>\n\n<h2 class=\"wp-block-heading\">How Companies Are Responding Now<\/h2>\n\n<p>A pragmatic approach involves four steps. First: Determine whether you are affected\u2014for example, using the BSI\u2019s impact assessment\u2014and complete the registration. Second: Assess the current state. This includes a risk analysis of your own IT infrastructure, as Section 30 of the BSIG mandates that a risk analysis be the first step in any action plan. Third: Prioritize and close gaps, ranging from backup strategies to encryption and multi-factor authentication. Fourth: Define reporting channels and responsibilities so that the 24-hour deadline can be met in the event of an emergency.<\/p>\n\n<p>For the second step, <a href=\"\/en\/know\/what-is-easm\/\">External Attack Surface Management (EASM)<\/a> A fact-based overview from an external perspective: Without requiring the installation of any agents, it shows which of your company\u2019s systems, services, and software components are accessible from the Internet and where vulnerabilities exist. A <a href=\"\/en\/know\/what-is-a-security-rating\/\">KPI-Based Security Rating<\/a> makes the status measurable and transparent to management, and also serves as recurring evidence to fulfill the monitoring obligation under \u00a7 38 BSIG.<\/p><p>When prioritizing new vulnerabilities, the recency of the data is also a factor. With <a href=\"\/en\/landing\/preemptive-intelligence-identifying-cyber-risks-before-they-become-apparent\/\">Preemptive Intelligence<\/a> LocateRisk cross-checks alerts from multiple sources against the visible attack surface even before a final NVD assessment is conducted. Such alerts supplement the risk analysis but do not replace technical verification on the affected system.<\/p>\n\n<p>To put this in context: An external analysis is no substitute for an information security management system and does not always identify whether a specific software version in use is vulnerable. However, it does highlight which systems are exposed and where a more in-depth review should be conducted. To address the supply chain obligations under Section 30 of the BSIG, a <a href=\"\/en\/landing\/vendor-risk-management-made-easy\/\">Vendor Risk Management<\/a>, which systematically evaluates service providers and suppliers.<\/p>\n\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Does NIS2 also apply to small businesses with fewer than 50 employees?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Generally, not directly. Exceptions apply, among others, to qualified trust service providers, TLD registries, and DNS service providers, which are covered regardless of their size. Indirectly, however, NIS2 affects many smaller companies: Regulated customers must assess the security of their supply chain and pass on requirements to their service providers.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What happens if an affected company does not register?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">The registration requirement under Section 33 of the BSIG remains in effect even after the deadlines have passed. A violation may be punished as an administrative offense subject to a fine. In addition, the company will miss out on information from the BSI\u2014such as warnings and situation reports\u2014that is sent via the contact information on file.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Is ISO 27001 certification sufficient for NIS2 compliance?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">ISO 27001 certification structurally addresses many of the requirements of Section 30 of the BSIG and serves as a solid foundation. However, it does not replace either the registration requirement or the reporting obligations, including their specific deadlines. Check the scope of the certificate: It must actually cover the relevant systems and processes.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">How can I find out if my company is affected?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">The BSI provides an online compliance check featuring a questionnaire based on Section 28 of the BSIG and Annexes 1 and 2. The key factors are the sector, number of employees, annual revenue, and total assets. For corporate group structures and borderline cases, a supplementary legal assessment is recommended.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What are the deadlines in the event of a security incident?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">You must report significant security incidents to the BSI immediately, no later than 24 hours after becoming aware of them. A report containing an initial assessment must be submitted within 72 hours, and a final report must be submitted no later than one month afterward. If the incident is ongoing, a progress report will be submitted in its place for the time being.<\/p><\/div><\/div><\/div><\/div>\n\n\n<h2 class=\"wp-block-heading\">Conclusion: Get a Clear Picture of Your Own Risk Profile Now<\/h2>\n\n<p>NIS2 is now law in Germany, with no general transition periods and with personal accountability resting with senior management. The first concrete step is to conduct an honest assessment of your organization\u2019s attack surface. LocateRisk analyzes your externally visible IT infrastructure without requiring agent installation and delivers a KPI-based assessment within 48 hours\u2014GDPR-compliant and hosted in certified German data centers. Get started with a <a href=\"\/en\/landing\/it-risk-analysis\/\">IT Risk Analysis for Your Company<\/a> and create the data foundation for your NIS2 implementation.<\/p>","protected":false},"excerpt":{"rendered":"<p>The NIS2 Implementation Act has been in effect since December 6, 2025. An overview of sectors, size thresholds, obligations, fines, and BSI deadlines.<\/p>","protected":false},"author":0,"featured_media":0,"template":"","wissen_thema":[819],"class_list":["post-9294","wissen","type-wissen","status-publish","hentry","wissen_thema-regulatorik-compliance"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NIS2-Richtlinie: Pflichten, Fristen, Bu\u00dfgelder \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"NIS2 gilt in Deutschland seit Dezember 2025. Wer betroffen ist, welche Pflichten gelten, welche Bu\u00dfgelder drohen: \u00dcberblick mit Fristen und Zahlen.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/locaterisk.com\/en\/know\/nis2-directive-overview\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIS2-Richtlinie: Pflichten, Fristen, Bu\u00dfgelder \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"NIS2 gilt in Deutschland seit Dezember 2025. Wer betroffen ist, welche Pflichten gelten, welche Bu\u00dfgelder drohen: \u00dcberblick mit Fristen und Zahlen.\" \/>\n<meta property=\"og:url\" content=\"http:\/\/locaterisk.com\/en\/know\/nis2-directive-overview\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-06T10:43:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-richtlinie-ueberblick\\\/\",\"url\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-richtlinie-ueberblick\\\/\",\"name\":\"NIS2-Richtlinie: Pflichten, Fristen, Bu\u00dfgelder \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-08-06T10:03:35+00:00\",\"dateModified\":\"2026-08-06T10:43:24+00:00\",\"description\":\"NIS2 gilt in Deutschland seit Dezember 2025. Wer betroffen ist, welche Pflichten gelten, welche Bu\u00dfgelder drohen: \u00dcberblick mit Fristen und Zahlen.\",\"breadcrumb\":{\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-richtlinie-ueberblick\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-richtlinie-ueberblick\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-richtlinie-ueberblick\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"NIS2-Richtlinie: Was Unternehmen jetzt wissen m\u00fcssen\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NIS2 Directive: Obligations, Deadlines, Fines \u2013 LocateRisk","description":"NIS2 has been in effect in Germany since December 2025. Who is affected, what obligations apply, and what fines may be imposed: An overview with deadlines and figures.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/locaterisk.com\/en\/know\/nis2-directive-overview\/","og_locale":"en_US","og_type":"article","og_title":"NIS2-Richtlinie: Pflichten, Fristen, Bu\u00dfgelder \u2013 LocateRisk","og_description":"NIS2 gilt in Deutschland seit Dezember 2025. Wer betroffen ist, welche Pflichten gelten, welche Bu\u00dfgelder drohen: \u00dcberblick mit Fristen und Zahlen.","og_url":"http:\/\/locaterisk.com\/en\/know\/nis2-directive-overview\/","og_site_name":"LocateRisk","article_modified_time":"2026-08-06T10:43:24+00:00","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/locaterisk.com\/de\/wissen\/nis2-richtlinie-ueberblick\/","url":"http:\/\/locaterisk.com\/de\/wissen\/nis2-richtlinie-ueberblick\/","name":"NIS2 Directive: Obligations, Deadlines, Fines \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-08-06T10:03:35+00:00","dateModified":"2026-08-06T10:43:24+00:00","description":"NIS2 has been in effect in Germany since December 2025. Who is affected, what obligations apply, and what fines may be imposed: An overview with deadlines and figures.","breadcrumb":{"@id":"http:\/\/locaterisk.com\/de\/wissen\/nis2-richtlinie-ueberblick\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/locaterisk.com\/de\/wissen\/nis2-richtlinie-ueberblick\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/locaterisk.com\/de\/wissen\/nis2-richtlinie-ueberblick\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/locaterisk.com\/de\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"NIS2-Richtlinie: Was Unternehmen jetzt wissen m\u00fcssen"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9294","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"version-history":[{"count":5,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9294\/revisions"}],"predecessor-version":[{"id":9335,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9294\/revisions\/9335"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=9294"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=9294"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}