{"id":9297,"date":"2026-08-06T10:03:37","date_gmt":"2026-08-06T10:03:37","guid":{"rendered":"http:\/\/locaterisk.com\/de\/?post_type=wissen&#038;p=9297"},"modified":"2026-08-06T11:22:08","modified_gmt":"2026-08-06T11:22:08","slug":"nis2-requirements-mandatory-measures","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/nis2-requirements-mandatory-measures\/","title":{"rendered":"NIS2 Requirements: The 10 Mandatory Measures Under Section 30 of the BSIG"},"content":{"rendered":"<h1 class=\"wp-block-heading\">NIS2 Requirements: The 10 Mandatory Measures Under Section 30 of the BSIG<\/h1><span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n<p>The German NIS 2 Implementation Act has been in effect since December 6, 2025. Section 30 of the revised BSI Act (BSIG) requires affected companies to implement ten specific risk management measures. This article explains each measure individually, outlines its practical implementation, and maps the requirements to ISO 27001. As of August 2026.<\/p><p>The requirements are often referred to as <strong>NIS2 Requirements<\/strong>, <strong>Cybersecurity Risk Management Measures<\/strong> or <strong>Measures Pursuant to Section 30 of the BSIG<\/strong> . Section 30 of the BSIG specifies the obligations for particularly important and important facilities in Germany. This section is part of the German implementation and is not equivalent to the European directive itself.<\/p>\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n<ul class=\"wp-block-list\"><li>The NIS-2 Implementation Act entered into force on December 6, 2025. Section 30 of the BSIG requires particularly important and important entities to implement ten risk management measures without a transition period.<\/li><li>According to the BSI, approximately 29,500 organizations in Germany are subject to the new requirements.<\/li><li>The ten measures range from risk analysis to supply chain security to multi-factor authentication. The benchmark is the state of the art.<\/li><li>Under Section 65 of the BSIG, the BSI may impose fines of up to 10 million euros for violations involving particularly important institutions and up to 7 million euros for important institutions. For total revenue of 500 million euros or more, the fines may amount to up to 2 percent or 1.4 percent of total revenue, respectively.<\/li><li>Management must implement the measures, monitor their implementation, and participate in training sessions on a regular basis. In the event of a culpable breach of duty, management is liable to its own institution (Section 38 BSIG).<\/li><\/ul>\n<h2 class=\"wp-block-heading\">Legal Framework: Who Is Subject to the NIS2 Requirements<\/h2>\n<p>The European NIS 2 Directive tightens cybersecurity requirements in the EU. Germany has transposed it into national law through the NIS 2 Implementation Act. The law took effect on December 6, 2025, and its centerpiece is the revised BSI Act. It distinguishes between particularly important facilities and important facilities. According to the BSI, approximately 29,500 organizations in Germany are subject to the new obligations. Whether your company is among them depends on its sector and size. The BSI\u2019s impact assessment provides an initial, non-legally binding guide.<\/p>\n<p>Important for planning: There is no transition period for the risk management measures required under Section 30 of the BSIG. Affected organizations must also register with the BSI in accordance with Section 33 of the BSIG no later than three months after they meet the criteria. The BSI may impose fines for violations of the mandatory measures under Section 65 of the BSIG: up to 10 million euros for particularly important organizations and up to 7 million euros for important organizations. For organizations with total revenue exceeding 500 million euros, the penalty range increases to up to 2 percent or 1.4 percent of total revenue, respectively. Section 38 of the BSIG also holds senior management personally accountable: They must implement the risk management measures, monitor their implementation, and are liable to the organization for any damage caused through negligence in accordance with the rules of corporate law applicable to its legal form. Our article on <a href=\"\/en\/know\/nis2-directive-overview\/\">NIS2 Directive<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">Measures 1 through 3: Risk Analysis, Incident Response, Business Continuity<\/h2>\n<p>Section 30(2) of the BSIG lists ten areas of action that the measures taken must at least cover. The list is therefore not exhaustive, but rather sets a mandatory minimum. The first three areas form the foundation of every security program.<\/p>\n<h3 class=\"wp-block-heading\">Action 1: Risk Analysis and IT Security Strategies<\/h3>\n<p>Requirement 1 calls for approaches to risk analysis and information technology security. This refers to a documented security policy and a repeatable process that identifies, assesses, and addresses risks. To implement this, you first need a robust, well-maintained inventory of your systems. In practice, externally accessible assets are often missing from this inventory\u2014such as forgotten subdomains, test systems, or cloud services used by individual departments. <a href=\"\/en\/know\/what-is-easm\/\">External Attack Surface Management<\/a> provides this external perspective and, as a result, a reliable data foundation for risk analysis. Next, define evaluation criteria, assign responsibilities, and establish a treatment plan, and update the analysis at least once a year.<\/p>\n<h3 class=\"wp-block-heading\">Action 2: Handling Security Incidents<\/h3>\n<p>Requirement 2 calls for processes to manage security incidents. These include an incident response plan with clear roles and escalation procedures, as well as playbooks for typical scenarios such as ransomware or compromised accounts. The plan must be aligned with the reporting requirements under Section 32 of the BSIG: Organizations must report significant security incidents to the BSI immediately, no later than within 24 hours. A follow-up report with an initial assessment must be submitted within 72 hours, and the final report no later than one month after the 72-hour report. Practice this procedure regularly to ensure that responsibilities and communication channels function properly in an emergency.<\/p>\n<h3 class=\"wp-block-heading\">Measure 3: Maintaining Operations and Crisis Management<\/h3>\n<p>Number 3 requires the maintenance of operations. The text of the law explicitly mentions backup management, disaster recovery, and crisis management. In practice, this means: a backup strategy with backups stored separately and protected against modification, documented recovery plans with priorities for critical processes, and a crisis management team with defined communication channels. Test the recovery process regularly under realistic conditions. A backup that has never been tested for restoration remains a risk in the event of an emergency.<\/p>\n<h2 class=\"wp-block-heading\">Measures 4 and 5: Supply Chain and Secure Procurement<\/h2>\n<h3 class=\"wp-block-heading\">Action 4: Supply Chain Security<\/h3>\n<p>Number 4 requires you to ensure supply chain security, including the security-related aspects of your relationships with direct suppliers and service providers. You must know which service providers have access to your systems or data and assess their security levels. Agree on contractual security requirements and continuously review critical suppliers. Our article on <a href=\"\/en\/know\/nis2-supply-chain-security\/\">NIS2 Supply Chain Security<\/a>. A <a href=\"\/en\/landing\/vendor-risk-management-made-easy\/\">Vendor Risk Management<\/a> It combines questionnaires with an external technical assessment of suppliers and makes it possible to compare their security status.<\/p>\n<h3 class=\"wp-block-heading\">Action 5: Security in Procurement, Development, and Maintenance<\/h3>\n<p>Number 5 concerns security measures for the procurement, development, and maintenance of IT systems, components, and processes. Define security requirements as early as the procurement phase\u2014for example, regarding update delivery and secure default settings. For operations, you need a patch management system with clear deadlines and a process for addressing reported vulnerabilities. If you develop software in-house, you should implement secure development guidelines, code reviews, and testing. Decommissioned systems must be consistently shut down; otherwise, they remain accessible from the Internet as unmaintained legacy systems.<\/p><p>A robust vulnerability management process should not rely solely on final NVD assessments. With <a href=\"\/en\/landing\/preemptive-intelligence-identifying-cyber-risks-before-they-become-apparent\/\">Preemptive Intelligence<\/a> LocateRisk compares alerts from multiple sources with the visible attack surface at an early stage. This supports prioritization in patch and vulnerability management; however, a technical assessment to determine whether a specific system is affected is still required.<\/p>\n<h2 class=\"wp-block-heading\">Measures 6 and 7: Measure effectiveness, embed cyber hygiene<\/h2>\n<h3 class=\"wp-block-heading\">Action 6: Evaluating the Effectiveness of the Measures<\/h3>\n<p>Number 6 calls for strategies and procedures to evaluate the effectiveness of risk management measures. It is not enough to implement measures just once; you must regularly measure their impact. Suitable metrics include patch lifetimes, internal audit results, and technical reviews. A KPI-based <a href=\"\/en\/know\/what-is-a-security-rating\/\">Security Rating<\/a> It continuously monitors the security situation as it appears from the outside and makes changes over time traceable. This also provides management\u2014which is required to oversee implementation in accordance with \u00a7 38 BSIG\u2014with a clear basis for decision-making.<\/p>\n<h3 class=\"wp-block-heading\">Measure 7: Training and Cyber Hygiene<\/h3>\n<p>Number 7 calls for comprehensive training and awareness-raising measures in the area of information technology security. Establish a recurring awareness program for all employees, featuring practical content on phishing, passwords, and how to handle suspicious incidents. In addition, cyber hygiene should be part of everyday practice: timely updates, minimal access privileges, and clear rules for mobile devices. Note the separate requirement under Section 38 of the BSIG: Management must regularly participate in training to be able to assess risks and risk management practices. This training requirement applies personally to members of management.<\/p>\n<h2 class=\"wp-block-heading\">Measures 8 through 10: Cryptography, Personnel, and Authentication<\/h2>\n<h3 class=\"wp-block-heading\">Measure 8: Cryptography and Encryption<\/h3>\n<p>Requirement 8 calls for policies and processes for the use of cryptographic methods. Document which data you encrypt at rest and in transit, which methods are permitted, and how you generate, store, and renew keys. Check your externally accessible services for outdated protocols, expiring certificates, and weak TLS configurations. The BSI\u2019s Technical Guideline TR-02102 provides guidance on recommended procedures and key lengths.<\/p>\n<h3 class=\"wp-block-heading\">Measure 9: Personnel Security, Access Control, and Asset Management<\/h3>\n<p>Number 9 covers concepts for staff security, access control, and the management of ICT systems, products, and processes. Regulate employee onboarding, role changes, and departure with clear authorization processes. Grant access according to the need-to-know principle and recertify access rights regularly. The foundation for this is a well-maintained asset inventory: Only those who know which systems exist and who is responsible for them can properly control access.<\/p>\n<h3 class=\"wp-block-heading\">Action 10: Multi-factor authentication and secure communication<\/h3>\n<p>Number 10 requires the use of multi-factor authentication or continuous authentication solutions, as well as secure voice, video, and text communication and, where applicable, secure emergency communication systems. Prioritize MFA for administrator accounts, remote access, and externally accessible login screens. Check your communication tools for transport encryption and access protection. Additionally, plan a communication channel for crisis situations that functions independently of the primary infrastructure, which may have been compromised.<\/p>\n<h2 class=\"wp-block-heading\">ISO 27001 Mapping: Leveraging Existing Structures<\/h2>\n<p>The content of these ten measures overlaps significantly with the requirements of ISO\/IEC 27001:2022. Organizations that already operate an information security management system can reuse much of their documentation. The following mapping serves as a guide for a gap analysis. It does not replace a case-by-case review, as Section 30 of the BSIG is, in some respects, more specific than the standard.<\/p>\n<figure class=\"wp-block-table\"><table><thead><tr><th>No.<\/th><th>Measure pursuant to Section 30(2) of the BSIG<\/th><th>ISO\/IEC 27001:2022 (Selection)<\/th><\/tr><\/thead><tbody><tr><td>1<\/td><td>Risk Analysis and IT Security Strategies<\/td><td>Chapters 6.1.2 and 8.2, Control 5.1<\/td><\/tr><tr><td>2<\/td><td>Security Incident Response<\/td><td>Controls 5.24 through 5.28<\/td><\/tr><tr><td>3<\/td><td>Business Continuity, Backup, Crisis Management<\/td><td>Controls 5.29, 5.30, 8.13, 8.14<\/td><\/tr><tr><td>4<\/td><td>Supply Chain Security<\/td><td>Controls 5.19 through 5.22<\/td><\/tr><tr><td>5<\/td><td>Acquisition, Development, and Maintenance<\/td><td>Controls 8.25 through 8.31, 5.23<\/td><\/tr><tr><td>6<\/td><td>Assessment of Effectiveness<\/td><td>Chapters 9.1 through 9.3<\/td><\/tr><tr><td>7<\/td><td>Training and Cyber Hygiene<\/td><td>Chapters 7.2 and 7.3, Controls 6.3, 8.7<\/td><\/tr><tr><td>8<\/td><td>Cryptography and Encryption<\/td><td>Control 8.24<\/td><\/tr><tr><td>9<\/td><td>Human Resources, Access Control, Asset Management<\/td><td>Controls 6.1 through 6.5, 5.15 through 5.18, 5.9<\/td><\/tr><tr><td>10<\/td><td>MFA and Secure Communication<\/td><td>Controls 8.5, 5.14, 5.17<\/td><\/tr><\/tbody><\/table><\/figure>\n<p>An existing certification does not automatically fulfill legal obligations. Registration, reporting requirements, and the obligations of management continue to apply regardless of the management system.<\/p>\n<h2 class=\"wp-block-heading\">Prioritization Roadmap: Implementation in Three Phases<\/h2>\n<p>Legally, all ten measures take effect immediately. In practice, however, companies need to implement them in a specific order. The following roadmap prioritizes the measures based on risk and effort. It is a recommendation, not a legally mandated sequence.<\/p>\n<h3 class=\"wp-block-heading\">Phase 1 (Months 1 through 3): Transparency and Responsibilities<\/h3>\n<ul class=\"wp-block-list\"><li>Determine whether you are affected by conducting the BSI impact assessment and complete registration in accordance with Section 33 of the BSIG<\/li><li>Define responsibilities, the budget, and the reporting structure to senior management<\/li><li>Systematically identify assets and the attack surface; conduct an initial risk analysis (Action 1)<\/li><li>Establish the reporting process under Section 32 of the BSIG, including templates and responsibilities (Action 2)<\/li><li>Implement immediate measures: MFA for administrator and remote access, test backup and recovery (Measures 3 and 10)<\/li><\/ul>\n<h3 class=\"wp-block-heading\">Phase 2 (Months 4 through 9): Concepts and Processes<\/h3>\n<ul class=\"wp-block-list\"><li>Document concepts for cryptography, access control, and personnel security (Measures 8 and 9)<\/li><li>Inventory and evaluate suppliers, and review contractual requirements (Action 4)<\/li><li>Define Procurement, Patch, and Vulnerability Management Processes (Action 5)<\/li><li>Launch a training program for employees and management (Action 7)<\/li><li>Expand emergency and crisis management capabilities and conduct a drill (Action 3)<\/li><\/ul>\n<h3 class=\"wp-block-heading\">Phase 3 (starting in Month 10): Effectiveness and Improvement<\/h3>\n<ul class=\"wp-block-list\"><li>Define key performance indicators and report them regularly to management (Action 6)<\/li><li>Conduct a Gap Analysis Against ISO 27001 or an Internal Audit<\/li><li>Establish continuous monitoring of your own attack surface<\/li><li>Update risk analyses and plans at least once a year<\/li><\/ul>\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Is there a transition period for the ten measures?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. The obligations under Section 30 of the BSIG have been in effect since the NIS-2 Implementation Act took effect on December 6, 2025. There is no statutory grace period for the technical and organizational measures. Section 33 of the BSIG grants a three-month period for registration with the BSI only after an organization has met the criteria.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Is ISO 27001 certification sufficient as proof of compliance with NIS2?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Certification covers many requirements in terms of content and serves as a solid foundation. However, it does not automatically replace legal obligations. Registration, reporting requirements, and the obligations of management apply regardless of the management system. A gap analysis shows where your existing ISMS already meets the requirements of Section 30(2) of the BSIG and where gaps remain.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What fines can be imposed for violations of \u00a7 30 BSIG?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Section 65 of the BSIG provides for fines of up to 10 million euros for particularly important institutions and up to 7 million euros for important institutions. If an institution\u2019s total revenue exceeds 500 million euros, the fine range increases to up to 2 percent or 1.4 percent of total revenue, respectively. The specific amount depends on the circumstances of the individual case, in particular the nature, severity, and duration of the violation. In addition, under \u00a7 38 BSIG, management is liable to its own organization if it culpably violates its implementation and monitoring obligations.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What does \u201cstate of the art\u201d mean in terms of implementation?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">According to Section 30(2) of the BSIG, the measures must comply with the state of the art and take into account the relevant European and international standards. The term is intentionally dynamic: What is appropriate today may be outdated in a few years. Guidance is provided by the BSI\u2019s IT-Grundschutz, the BSI\u2019s Technical Guidelines, and the ISO 27001 family of standards. At the same time, Section 30(1) of the BSIG requires proportionate measures: Factors such as the size of the organization, its risk exposure, and implementation costs are taken into account in the assessment.<\/p><\/div><\/div><\/div><\/div>\n\n<h2 class=\"wp-block-heading\">Conclusion: Start by gaining transparency into your attack surface<\/h2>\n<p>The ten mandatory measures under Section 30 of the BSIG are not a one-time project, but rather an ongoing process consisting of analysis, implementation, and monitoring. The most effective first step is to ensure transparency regarding one\u2019s own vulnerabilities, because without a reliable external perspective, the risk analysis lacks important foundational information. A <a href=\"\/en\/landing\/it-risk-analysis\/\">IT Risk Analysis by LocateRisk<\/a> Within 48 hours, it shows you which of your company's systems and software applications are visible on the Internet and where action is needed\u2014all without installing any agents.<\/p>","protected":false},"excerpt":{"rendered":"<p>The Ten Risk Management Measures Under Section 30 of the BSIG: What Is Required, How to Implement Them Successfully, and How They Map to ISO 27001.<\/p>","protected":false},"author":0,"featured_media":0,"template":"","wissen_thema":[819],"class_list":["post-9297","wissen","type-wissen","status-publish","hentry","wissen_thema-regulatorik-compliance"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NIS2-Anforderungen: 10 Ma\u00dfnahmen nach \u00a730 BSIG \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"Alle zehn NIS2-Pflichtma\u00dfnahmen nach \u00a730 BSIG erkl\u00e4rt: Anforderungen, Umsetzung, ISO-27001-Mapping und Roadmap in drei Phasen. Stand August 2026.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/locaterisk.com\/en\/know\/nis2-requirements-mandatory-measures\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIS2-Anforderungen: 10 Ma\u00dfnahmen nach \u00a730 BSIG \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"Alle zehn NIS2-Pflichtma\u00dfnahmen nach \u00a730 BSIG erkl\u00e4rt: Anforderungen, Umsetzung, ISO-27001-Mapping und Roadmap in drei Phasen. Stand August 2026.\" \/>\n<meta property=\"og:url\" content=\"http:\/\/locaterisk.com\/en\/know\/nis2-requirements-mandatory-measures\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-06T11:22:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-anforderungen-pflichtmassnahmen\\\/\",\"url\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-anforderungen-pflichtmassnahmen\\\/\",\"name\":\"NIS2-Anforderungen: 10 Ma\u00dfnahmen nach \u00a730 BSIG \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-08-06T10:03:37+00:00\",\"dateModified\":\"2026-08-06T11:22:08+00:00\",\"description\":\"Alle zehn NIS2-Pflichtma\u00dfnahmen nach \u00a730 BSIG erkl\u00e4rt: Anforderungen, Umsetzung, ISO-27001-Mapping und Roadmap in drei Phasen. Stand August 2026.\",\"breadcrumb\":{\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-anforderungen-pflichtmassnahmen\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-anforderungen-pflichtmassnahmen\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/nis2-anforderungen-pflichtmassnahmen\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/locaterisk.com\\\/de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"NIS2-Anforderungen: Die 10 Pflichtma\u00dfnahmen nach \u00a7 30 BSIG\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NIS2 Requirements: 10 Measures Under Section 30 of the BSIG \u2013 LocateRisk","description":"All Ten Mandatory NIS2 Measures Under Section 30 of the BSIG Explained: Requirements, Implementation, ISO 27001 Mapping, and a Three-Phase Roadmap. As of August 2026.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/locaterisk.com\/en\/know\/nis2-requirements-mandatory-measures\/","og_locale":"en_US","og_type":"article","og_title":"NIS2-Anforderungen: 10 Ma\u00dfnahmen nach \u00a730 BSIG \u2013 LocateRisk","og_description":"Alle zehn NIS2-Pflichtma\u00dfnahmen nach \u00a730 BSIG erkl\u00e4rt: Anforderungen, Umsetzung, ISO-27001-Mapping und Roadmap in drei Phasen. Stand August 2026.","og_url":"http:\/\/locaterisk.com\/en\/know\/nis2-requirements-mandatory-measures\/","og_site_name":"LocateRisk","article_modified_time":"2026-08-06T11:22:08+00:00","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/locaterisk.com\/de\/wissen\/nis2-anforderungen-pflichtmassnahmen\/","url":"http:\/\/locaterisk.com\/de\/wissen\/nis2-anforderungen-pflichtmassnahmen\/","name":"NIS2 Requirements: 10 Measures Under Section 30 of the BSIG \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-08-06T10:03:37+00:00","dateModified":"2026-08-06T11:22:08+00:00","description":"All Ten Mandatory NIS2 Measures Under Section 30 of the BSIG Explained: Requirements, Implementation, ISO 27001 Mapping, and a Three-Phase Roadmap. As of August 2026.","breadcrumb":{"@id":"http:\/\/locaterisk.com\/de\/wissen\/nis2-anforderungen-pflichtmassnahmen\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/locaterisk.com\/de\/wissen\/nis2-anforderungen-pflichtmassnahmen\/"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/locaterisk.com\/de\/wissen\/nis2-anforderungen-pflichtmassnahmen\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/locaterisk.com\/de\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"NIS2-Anforderungen: Die 10 Pflichtma\u00dfnahmen nach \u00a7 30 BSIG"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9297","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"version-history":[{"count":6,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9297\/revisions"}],"predecessor-version":[{"id":9340,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/9297\/revisions\/9340"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=9297"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=9297"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}