Skip to content

Check NIS2 Applicability and Implement Cybersecurity Obligations

Provimedia 4 min read 11 July 2026 2 views
Unternehmerpflichten
Check NIS2 Applicability and Implement Cybersecurity Obligations
Illustrative image · AI-generated

Since December 6, 2025, Germany's new BSI Act implementing the NIS2 Directive has been in force, bringing new cybersecurity obligations for thousands of companies across 18 sectors.

In short: the BSIG requires "important" and "particularly important" entities across 18 sectors, generally from 50 employees or more than 10 million euros in revenue, to register with the BSI, implement risk management measures such as MFA, backups, and supply chain security, and follow staggered reporting deadlines for security incidents. Executive management is personally liable, and violations can trigger fines of up to 10 million euros or 2% of worldwide annual revenue.

Who is affected by NIS2?

"Important" and "particularly important" entities in one of 18 legally defined sectors are affected, generally companies with 50 or more employees or more than 10 million euros in annual revenue. The covered sectors include, among others, energy, transport, healthcare, digital infrastructure, waste management, and manufacturing. What matters is not company size alone but belonging to one of these sectors: a software company with 80 employees can fall outside the scope, while a water utility with 55 employees is clearly covered. Anyone unsure should specifically check their status, for example with the BSI status check or a tool like Company Audit, which automatically compares industry-specific obligations. Within the sectors, the law further distinguishes between "particularly important" entities, such as energy, water, banking, or digital infrastructure, subject to proactive oversight, and "important" entities, which the BSI checks on an occasion-based basis.

What exactly do affected companies need to do?

Affected entities must register with the BSI and build a risk management program for their IT and OT systems. The law requires specific technical and organizational measures, including multi-factor authentication, a backup and incident response plan, the use of cryptography, and securing the supply chain against service providers and suppliers. In addition, executive management must oversee the implementation of these measures and undergo regular training on cybersecurity topics, since it is personally liable for this. The measures taken should also be documented so that, in the course of a BSI audit or after a security incident, it remains traceable which steps were implemented and when.

By when must security incidents be reported?

For significant security incidents, a three-stage reporting procedure applies at the BSI: an initial report within 24 hours, a follow-up report with a detailed assessment within 72 hours, and a final report no later than one month after the incident. So that this timeline can be met in a real incident, the reporting process should be defined in advance and known throughout the company: who reports, to whom, and with what information.

Reporting stepDeadlineContent
Initial report24 hoursBrief report of the incident, including any possible cross-border impact
Follow-up report72 hoursInitial assessment of the incident with severity and impact
Final report1 monthDetailed report on causes, countermeasures, and lessons learned from the incident

What are the consequences of violating NIS2 obligations?

Violations of the registration, risk management, or reporting obligations can be penalized with fines of up to 10 million euros or 2% of worldwide annual revenue, whichever amount is higher. Because executive management is personally liable for overseeing these measures, failures can additionally lead to civil law consequences for management and the board. Even companies that do not themselves fall directly under NIS2 feel the effects of the regulation: they are effectively pushed toward comparable security measures through the supply chain requirements of their customers.

The most important steps for NIS2 implementation

  1. Check whether the company belongs to one of the 18 NIS2 sectors, for example using the BSI status check.
  2. If affected, register with the BSI within the deadline.
  3. Implement risk management measures: multi-factor authentication, backup and incident response plan, cryptography, and supply chain security.
  4. Establish a reporting process for security incidents with the 24-hour, 72-hour, and one-month deadlines.
  5. Train executive management and document the oversight of these measures to meet the personal liability of management.

Frequently asked questions

From how many employees does NIS2 apply?

The standard threshold is 50 employees or more than 10 million euros in annual revenue. However, it is additionally decisive that the company belongs to one of the 18 legally named sectors, since size alone is not sufficient to be in scope.

Are smaller companies also affected by NIS2?

Not directly, as a rule, if the thresholds are not reached. However, smaller suppliers and service providers of affected entities are often effectively pushed toward comparable security measures through the supply chain requirements of their customers.

What happens if a security incident is reported late?

If the staggered reporting deadline of 24 hours for the initial report, 72 hours for the follow-up report, or one month for the final report is missed, this constitutes a violation of Section 32 BSIG, which can be penalized with a fine.

Is executive management personally liable for NIS2 violations?

Yes. The BSIG provides that executive management oversees the implementation of the risk management measures, undergoes training, and can be held personally accountable for failures.

How do I find out whether my company is affected?

The most reliable option is the official BSI status check, which specifically asks about sector membership, size, and revenue. Anyone still unsure should carry out this check before registering to avoid unnecessary effort.

Source: Sections 28, 30, 32, 33 BSIG (NIS2 Implementation Act). This article is general information and does not replace legal advice in individual cases. As of: July 2026.

Share this article

Stay up to date

Get the latest articles, insights and industry updates straight to your inbox.

Unsubscribe at any time. See our privacy policy.

Decide for yourself what Google shows you

Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.

Add provimedia.de to my preferred sources

Ihre Unternehmer­pflichten im Griff

Company Audit erstellt Ihnen in wenigen Minuten eine individuelle Pflichtenliste – mit Fristen-Kalender, Erinnerungen und KI-Assistent. Für Selbständige und KMU.