Check NIS2 Applicability and Implement Cybersecurity Obligations

Since December 6, 2025, Germany's new BSI Act implementing the NIS2 Directive has been in force, bringing new cybersecurity obligations for thousands of companies across 18 sectors.
In short: the BSIG requires "important" and "particularly important" entities across 18 sectors, generally from 50 employees or more than 10 million euros in revenue, to register with the BSI, implement risk management measures such as MFA, backups, and supply chain security, and follow staggered reporting deadlines for security incidents. Executive management is personally liable, and violations can trigger fines of up to 10 million euros or 2% of worldwide annual revenue.
Who is affected by NIS2?
"Important" and "particularly important" entities in one of 18 legally defined sectors are affected, generally companies with 50 or more employees or more than 10 million euros in annual revenue. The covered sectors include, among others, energy, transport, healthcare, digital infrastructure, waste management, and manufacturing. What matters is not company size alone but belonging to one of these sectors: a software company with 80 employees can fall outside the scope, while a water utility with 55 employees is clearly covered. Anyone unsure should specifically check their status, for example with the BSI status check or a tool like Company Audit, which automatically compares industry-specific obligations. Within the sectors, the law further distinguishes between "particularly important" entities, such as energy, water, banking, or digital infrastructure, subject to proactive oversight, and "important" entities, which the BSI checks on an occasion-based basis.
What exactly do affected companies need to do?
Affected entities must register with the BSI and build a risk management program for their IT and OT systems. The law requires specific technical and organizational measures, including multi-factor authentication, a backup and incident response plan, the use of cryptography, and securing the supply chain against service providers and suppliers. In addition, executive management must oversee the implementation of these measures and undergo regular training on cybersecurity topics, since it is personally liable for this. The measures taken should also be documented so that, in the course of a BSI audit or after a security incident, it remains traceable which steps were implemented and when.
By when must security incidents be reported?
For significant security incidents, a three-stage reporting procedure applies at the BSI: an initial report within 24 hours, a follow-up report with a detailed assessment within 72 hours, and a final report no later than one month after the incident. So that this timeline can be met in a real incident, the reporting process should be defined in advance and known throughout the company: who reports, to whom, and with what information.
| Reporting step | Deadline | Content |
|---|---|---|
| Initial report | 24 hours | Brief report of the incident, including any possible cross-border impact |
| Follow-up report | 72 hours | Initial assessment of the incident with severity and impact |
| Final report | 1 month | Detailed report on causes, countermeasures, and lessons learned from the incident |
What are the consequences of violating NIS2 obligations?
Violations of the registration, risk management, or reporting obligations can be penalized with fines of up to 10 million euros or 2% of worldwide annual revenue, whichever amount is higher. Because executive management is personally liable for overseeing these measures, failures can additionally lead to civil law consequences for management and the board. Even companies that do not themselves fall directly under NIS2 feel the effects of the regulation: they are effectively pushed toward comparable security measures through the supply chain requirements of their customers.
The most important steps for NIS2 implementation
- Check whether the company belongs to one of the 18 NIS2 sectors, for example using the BSI status check.
- If affected, register with the BSI within the deadline.
- Implement risk management measures: multi-factor authentication, backup and incident response plan, cryptography, and supply chain security.
- Establish a reporting process for security incidents with the 24-hour, 72-hour, and one-month deadlines.
- Train executive management and document the oversight of these measures to meet the personal liability of management.
Frequently asked questions
From how many employees does NIS2 apply?
The standard threshold is 50 employees or more than 10 million euros in annual revenue. However, it is additionally decisive that the company belongs to one of the 18 legally named sectors, since size alone is not sufficient to be in scope.
Are smaller companies also affected by NIS2?
Not directly, as a rule, if the thresholds are not reached. However, smaller suppliers and service providers of affected entities are often effectively pushed toward comparable security measures through the supply chain requirements of their customers.
What happens if a security incident is reported late?
If the staggered reporting deadline of 24 hours for the initial report, 72 hours for the follow-up report, or one month for the final report is missed, this constitutes a violation of Section 32 BSIG, which can be penalized with a fine.
Is executive management personally liable for NIS2 violations?
Yes. The BSIG provides that executive management oversees the implementation of the risk management measures, undergoes training, and can be held personally accountable for failures.
How do I find out whether my company is affected?
The most reliable option is the official BSI status check, which specifically asks about sector membership, size, and revenue. Anyone still unsure should carry out this check before registering to avoid unnecessary effort.
Source: Sections 28, 30, 32, 33 BSIG (NIS2 Implementation Act). This article is general information and does not replace legal advice in individual cases. As of: July 2026.
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Recapitulative Statement (ZM), OSS, and Intrastat in EU Trade
ZM due by the 25th of the following month, OSS filed quarterly, Intrastat from the threshold: EU reporting obligations explained compactly.
Ensuring Product Safety Under the GPSR
The GPSR and Germany's ProdSG require every seller of non-food products to carry out a risk analysis, appoint an EU responsible person, and provide warning notices, even for tiny quantities.
Product Liability: When Manufacturers Are Liable Without Fault
Manufacturers are liable without fault for defective products: product liability insurance protects against claims that could threaten a company's existence.
Ihre Unternehmerpflichten im Griff
Company Audit erstellt Ihnen in wenigen Minuten eine individuelle Pflichtenliste – mit Fristen-Kalender, Erinnerungen und KI-Assistent. Für Selbständige und KMU.