NIS2 - European Cybersecurity Directive
The NIS2 Directive (EU 2022/2555) marks a paradigm shift in European cybersecurity legislation. It significantly expands the scope of application and requires all EU member states to create a high common level of security for network and information systems. Germany implements the directive through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG).
What is NIS2 and Why is it Relevant?
Section titled “What is NIS2 and Why is it Relevant?”NIS2 replaces the original NIS Directive from 2016 and dramatically expands the scope: from approximately 4,500 operators of critical infrastructures to an estimated 29,000 affected companies in Germany. This massive expansion reflects the reality that cyberattacks now affect all industries and the economy as a whole must become resilient.
Why Implement NIS2?
Section titled “Why Implement NIS2?”Legal Necessity:
- Avoidance of significant penalties (up to 20 million EUR or 2% of global turnover)
- Fulfillment of legal compliance requirements
- Protection from personal liability of management
- Legal certainty in regulated markets
Business Benefits:
- Competitive advantage through early compliance
- Trust from customers, partners, and authorities
- Facilitated access to public contracts
- Synergies with existing standards (ISO 27001, IT Baseline Protection)
Security Benefits:
- Risk-based cybersecurity governance
- Proactive incident response processes
- Strengthened supply chain security
- Anchoring cybersecurity at executive level
Practice Tip: Use Timing Although Germany missed the EU implementation deadline, companies can gain an advantage by starting preparations now. The law is expected to come into force in early 2026.
Status of German Implementation
Section titled “Status of German Implementation”Current Timeline
Section titled “Current Timeline”Delayed Implementation:
- EU deadline: October 17, 2024 (missed)
- Cabinet decision: July 30, 2025
- Planned entry into force: Early 2026
- Registration deadline: 3 months after entry into force
Legal Consequences:
- EU Commission issued reasoned opinion (May 7, 2025)
- Infringement procedure threatens
- No long transition period for companies
Competent Authority
Section titled “Competent Authority”The Federal Office for Information Security (BSI) will serve as the central supervisory authority with expanded powers:
- Registration and monitoring of companies
- Ordering and enforcement of measures
- Imposing fines
- Coordinating incident response
Scope and Affected Companies
Section titled “Scope and Affected Companies”Three Categories of Entities
Section titled “Three Categories of Entities”1. Operators of Critical Facilities (KRITIS)
Section titled “1. Operators of Critical Facilities (KRITIS)”- Retain existing KRITIS obligations
- Thresholds remain unchanged (e.g., supply ≥ 500,000 people)
- Additional NIS2 requirements
- Mandatory audits every three years
2. Essential Entities
Section titled “2. Essential Entities”Size Criteria:
- ≥ 250 employees OR
- Annual turnover > 50 million EUR AND balance sheet total > 43 million EUR
Affected Sectors:
- Energy and water management
- Transport and traffic
- Banking and financial market infrastructures
- Healthcare
- Digital infrastructure
- Public administration
Size-Independent Coverage:
- Top-level domain registries
- DNS providers
- Telecommunications networks
- Cloud computing services
3. Important Entities
Section titled “3. Important Entities”Size Criteria:
- ≥ 50 employees OR
- Annual turnover > 10 million EUR AND balance sheet total > 10 million EUR
Additional Sectors:
- Postal and courier services
- Waste management
- Chemical industry
- Food production
- Manufacturing
- Digital services
- Research organizations
Sanctions and Penalties
Section titled “Sanctions and Penalties”| Category | Fine | Assessment Basis |
|---|---|---|
| Essential Entities | up to 20 million EUR | or 2% of global annual turnover |
| Important Entities | up to 10 million EUR | or 1.4% of global annual turnover |
Personal Liability: Executive and board members are personally liable for breaches of duty in implementing and monitoring measures.
Core Concepts and Requirements
Section titled “Core Concepts and Requirements”Risk Management Approach
Section titled “Risk Management Approach”NIS2 requires systematic risk management based on “state of the art” considering risks, company size, and costs.
Technical and Organizational Measures
Section titled “Technical and Organizational Measures”Basic Security Measures:
- Risk assessment and IT security concepts
- Incident response and business continuity management
- Backup management and disaster recovery
- Supply chain security and vendor management
- Secure development, procurement, and maintenance
- Vulnerability management and security assessments
Technical Controls:
- Cryptography and key management
- Access management and multi-factor authentication
- Secure communication (voice, video, text communication)
- Emergency communication systems
Organizational Controls:
- Cyber hygiene and employee training
- Management training on cyber risks
- Documentation and evidence management
Extended Requirements for Essential Entities
Section titled “Extended Requirements for Essential Entities”Additional Technical Measures:
- Deployment of attack detection systems
- Extended monitoring and logging systems
- Regular penetration testing
Audit Obligations:
- Proof of measure implementation every three years
- Audits, inspections, or certificates as evidence
- Possible random BSI audits
Notification and Registration Obligations
Section titled “Notification and Registration Obligations”Registration with BSI
Section titled “Registration with BSI”Self-Identification: Companies must independently check whether they fall under NIS2 and register within three months.
Required Information:
- Company name and legal form
- Contact details and contact persons
- IP address ranges
- Industry classification
- EU countries of business activity
- Annual data updates
Incident Response Procedures
Section titled “Incident Response Procedures”Three-Stage Notification for Significant Security Incidents:
| Stage | Time Limit | Content |
|---|---|---|
| Initial Report | 24 hours | Basic incident information |
| Follow-up Report | 72 hours | Detailed analysis and initial measures |
| Final Report | 1 month | Complete investigation and lessons learned |
Additional Notification Obligations:
- BSI may request interim reports
- Public information for significant impacts
- Customer warnings in specific sectors (finance, ICT, digital services)
Governance and Leadership Responsibility
Section titled “Governance and Leadership Responsibility”Management Responsibility:
- Personal liability of management
- Approval and monitoring of security measures
- Mandatory training on cyber risks
- Integration into strategic business planning
BSI Supervisory Powers:
- Comprehensive audit and enforcement powers
- Imposition of fines and sanctions
- Random audits based on risk profiles
- Ordering additional security measures
Integration with Existing Standards
Section titled “Integration with Existing Standards”Synergies with ISO 27001
Section titled “Synergies with ISO 27001”NIS2 requirements largely overlap with established ISMS standards:
Overlapping Areas:
- Risk management and risk treatment
- Incident response and business continuity
- Access controls and authentication
- Supplier management and outsourcing
- Employee training and awareness
- Documentation and evidence management
NIS2-Specific Extensions:
- Notification obligations within 24/72 hours/1 month
- Management liability and training
- BSI registration and monitoring
- Sector-specific requirements
Compatibility with IT Baseline Protection
Section titled “Compatibility with IT Baseline Protection”BSI IT Baseline Protection provides a solid foundation for NIS2 compliance:
- Building block-oriented implementation
- Structured risk assessment
- Established security measures
- Proven audit procedures
Practice Tip: Combine Standards Companies with ISO 27001 certification or IT Baseline Protection implementation already have a good starting point. Existing processes only need to be extended with NIS2-specific elements.
Implementation Strategies and Best Practices
Section titled “Implementation Strategies and Best Practices”Phased Implementation
Section titled “Phased Implementation”Phase 1: Clarify Applicability
Section titled “Phase 1: Clarify Applicability”Threshold Analysis:
- Review of industry affiliation
- Assessment of company size (employees, turnover, balance sheet)
- Identification of critical business areas
- Consideration of subsidiaries and group structures
Special Attention for:
- DNS, cloud, or TLD service providers (size-independent)
- Companies with mixed business areas
- International group structures
Phase 2: Build or Extend ISMS
Section titled “Phase 2: Build or Extend ISMS”Establish Risk Management:
- Systematic threat and vulnerability analysis
- Definition of protection objectives and acceptance thresholds
- Implementation of risk-based controls
- Continuous monitoring and improvement
Cover All NIS2 Topic Areas:
- Business continuity and disaster recovery
- Supply chain security and vendor management
- Vulnerability management and patch processes
- Training programs for all employee levels
Phase 3: Operational Implementation
Section titled “Phase 3: Operational Implementation”Define Notification Processes:
- Clear responsibilities and escalation paths
- Templates for initial, follow-up, and final reports
- Integration into existing incident response processes
- Regular exercises and tests
Ensure Documentation:
- All security measures and risk assessments
- Training records and management training
- Audit results and improvement measures
- Supplier assessments and contracts
Avoiding Common Implementation Errors
Section titled “Avoiding Common Implementation Errors”Insufficient Scope Definition:
- Overlooking subsidiaries or business areas
- Incorrect assessment of size criteria
- Incomplete coverage of digital services
Lack of Management Involvement:
- Treatment as purely IT-technical topic
- Missing executive training
- Insufficient resource allocation
Incomplete Supply Chain Analysis:
- Neglecting cloud service providers
- Missing contract adjustments with suppliers
- Insufficient monitoring of third parties
Support Through the fuentis Suite
Section titled “Support Through the fuentis Suite”The fuentis Suite provides comprehensive support for NIS2 implementation:
NIS2 Compliance Module
Section titled “NIS2 Compliance Module”- Pre-configured requirements according to § 30 BSIG-E
- Automatic applicability check based on size criteria
- Gap analysis to existing ISMS standards
- Compliance dashboard with implementation status
Risk Management
Section titled “Risk Management”- Structured capture of all NIS2-relevant risks
- Linking with assets and business processes
- Automatic risk assessment and prioritization
- Integration with existing risk management processes
Incident Management
Section titled “Incident Management”- Mapping of three-stage notification processes
- Automatic reminders for notification deadlines
- Templates for BSI notifications
- Documentation and tracking of incidents
Asset Management
Section titled “Asset Management”- Central capture of all information-processing assets
- Assignment of responsibilities and criticalities
- Monitoring of changes and updates
- Integration with configuration management
Supplier Management
Section titled “Supplier Management”- Assessment and monitoring of service providers
- Management of security requirements and evidence
- Audit planning and execution
- Contract management with security clauses
Audit and Review Functions
Section titled “Audit and Review Functions”- Planning and conducting internal audits
- Tracking non-conformities and measures
- Management review support
- Automated reporting for BSI audits
Training and Awareness
Section titled “Training and Awareness”- NIS2-specific training modules
- Management training on cyber risks
- Employee awareness programs
- Tracking of training completions and deadlines
Preparing for BSI Audits
Section titled “Preparing for BSI Audits”Audit Types and Procedures
Section titled “Audit Types and Procedures”KRITIS Audits (every 3 years):
- Complete review of all measures
- On-site audits or remote assessments
- Alternative: Recognized certifications (ISO 27001, IT Baseline Protection)
Random BSI Audits:
- Risk-based selection of companies
- Focus on specific vulnerabilities or incidents
- Short notice periods
Audit Preparation
Section titled “Audit Preparation”Documentation Requirements:
- Complete ISMS documentation
- Evidence for all implemented measures
- Risk assessments and treatment strategies
- Incident response plans and evidence
- Training materials and certificates
Practical Tips:
- Regular internal audits as preparation
- Continuous documentation updates
- Clear responsibilities and contact persons
- Practice audit situations with the team
Future Perspectives and Developments
Section titled “Future Perspectives and Developments”European Harmonization
Section titled “European Harmonization”Trends in the EU:
- Further harmonization of national implementations
- Increased cross-border cooperation
- Integration with other EU cybersecurity initiatives
- Possible tightening of requirements
Technological Developments
Section titled “Technological Developments”New Challenges:
- Artificial intelligence and machine learning
- IoT and Industrial IoT security
- 5G networks and edge computing
- Quantum computing and post-quantum cryptography
Adaptation of Requirements:
- Regular updates of technical standards
- Consideration of new threat scenarios
- Evolution of “state of the art” definition
Key Takeaways at a Glance
Section titled “Key Takeaways at a Glance”The 5 Most Important Success Factors for NIS2 Compliance:
-
Early Applicability Assessment: Clarify immediately whether your company falls under NIS2 - the size criteria are complex and capture significantly more organizations than before
-
ISMS as Compliance Foundation: An established information security management system according to ISO 27001 or IT Baseline Protection forms the best basis for NIS2 compliance
-
Secure Management Commitment: Personal liability of management makes cybersecurity a top management issue - management training and involvement are indispensable
-
Build Incident Response Capabilities: The 24-hour notification obligation requires established processes, clear responsibilities, and practiced procedures
-
Systematically Secure Supply Chains: Supply chain risks are a central NIS2 topic - assess and monitor all critical service providers and suppliers
Why NIS2 is More Than Just Compliance: NIS2 marks the transition from voluntary to mandatory cybersecurity for large parts of the economy. Companies that proactively implement NIS2 create not only legal certainty but also a sustainable competitive advantage through increased resilience, customer trust, and operational excellence in digital transformation.