Skip to content

NIS2 - European Cybersecurity Directive

The NIS2 Directive (EU 2022/2555) marks a paradigm shift in European cybersecurity legislation. It significantly expands the scope of application and requires all EU member states to create a high common level of security for network and information systems. Germany implements the directive through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG).

NIS2 replaces the original NIS Directive from 2016 and dramatically expands the scope: from approximately 4,500 operators of critical infrastructures to an estimated 29,000 affected companies in Germany. This massive expansion reflects the reality that cyberattacks now affect all industries and the economy as a whole must become resilient.

Legal Necessity:

  • Avoidance of significant penalties (up to 20 million EUR or 2% of global turnover)
  • Fulfillment of legal compliance requirements
  • Protection from personal liability of management
  • Legal certainty in regulated markets

Business Benefits:

  • Competitive advantage through early compliance
  • Trust from customers, partners, and authorities
  • Facilitated access to public contracts
  • Synergies with existing standards (ISO 27001, IT Baseline Protection)

Security Benefits:

  • Risk-based cybersecurity governance
  • Proactive incident response processes
  • Strengthened supply chain security
  • Anchoring cybersecurity at executive level

Practice Tip: Use Timing Although Germany missed the EU implementation deadline, companies can gain an advantage by starting preparations now. The law is expected to come into force in early 2026.

Delayed Implementation:

  • EU deadline: October 17, 2024 (missed)
  • Cabinet decision: July 30, 2025
  • Planned entry into force: Early 2026
  • Registration deadline: 3 months after entry into force

Legal Consequences:

  • EU Commission issued reasoned opinion (May 7, 2025)
  • Infringement procedure threatens
  • No long transition period for companies

The Federal Office for Information Security (BSI) will serve as the central supervisory authority with expanded powers:

  • Registration and monitoring of companies
  • Ordering and enforcement of measures
  • Imposing fines
  • Coordinating incident response

1. Operators of Critical Facilities (KRITIS)

Section titled “1. Operators of Critical Facilities (KRITIS)”
  • Retain existing KRITIS obligations
  • Thresholds remain unchanged (e.g., supply ≥ 500,000 people)
  • Additional NIS2 requirements
  • Mandatory audits every three years

Size Criteria:

  • ≥ 250 employees OR
  • Annual turnover > 50 million EUR AND balance sheet total > 43 million EUR

Affected Sectors:

  • Energy and water management
  • Transport and traffic
  • Banking and financial market infrastructures
  • Healthcare
  • Digital infrastructure
  • Public administration

Size-Independent Coverage:

  • Top-level domain registries
  • DNS providers
  • Telecommunications networks
  • Cloud computing services

Size Criteria:

  • ≥ 50 employees OR
  • Annual turnover > 10 million EUR AND balance sheet total > 10 million EUR

Additional Sectors:

  • Postal and courier services
  • Waste management
  • Chemical industry
  • Food production
  • Manufacturing
  • Digital services
  • Research organizations
CategoryFineAssessment Basis
Essential Entitiesup to 20 million EURor 2% of global annual turnover
Important Entitiesup to 10 million EURor 1.4% of global annual turnover

Personal Liability: Executive and board members are personally liable for breaches of duty in implementing and monitoring measures.

NIS2 requires systematic risk management based on “state of the art” considering risks, company size, and costs.

Basic Security Measures:

  • Risk assessment and IT security concepts
  • Incident response and business continuity management
  • Backup management and disaster recovery
  • Supply chain security and vendor management
  • Secure development, procurement, and maintenance
  • Vulnerability management and security assessments

Technical Controls:

  • Cryptography and key management
  • Access management and multi-factor authentication
  • Secure communication (voice, video, text communication)
  • Emergency communication systems

Organizational Controls:

  • Cyber hygiene and employee training
  • Management training on cyber risks
  • Documentation and evidence management

Extended Requirements for Essential Entities

Section titled “Extended Requirements for Essential Entities”

Additional Technical Measures:

  • Deployment of attack detection systems
  • Extended monitoring and logging systems
  • Regular penetration testing

Audit Obligations:

  • Proof of measure implementation every three years
  • Audits, inspections, or certificates as evidence
  • Possible random BSI audits

Self-Identification: Companies must independently check whether they fall under NIS2 and register within three months.

Required Information:

  • Company name and legal form
  • Contact details and contact persons
  • IP address ranges
  • Industry classification
  • EU countries of business activity
  • Annual data updates

Three-Stage Notification for Significant Security Incidents:

StageTime LimitContent
Initial Report24 hoursBasic incident information
Follow-up Report72 hoursDetailed analysis and initial measures
Final Report1 monthComplete investigation and lessons learned

Additional Notification Obligations:

  • BSI may request interim reports
  • Public information for significant impacts
  • Customer warnings in specific sectors (finance, ICT, digital services)

Management Responsibility:

  • Personal liability of management
  • Approval and monitoring of security measures
  • Mandatory training on cyber risks
  • Integration into strategic business planning

BSI Supervisory Powers:

  • Comprehensive audit and enforcement powers
  • Imposition of fines and sanctions
  • Random audits based on risk profiles
  • Ordering additional security measures

NIS2 requirements largely overlap with established ISMS standards:

Overlapping Areas:

  • Risk management and risk treatment
  • Incident response and business continuity
  • Access controls and authentication
  • Supplier management and outsourcing
  • Employee training and awareness
  • Documentation and evidence management

NIS2-Specific Extensions:

  • Notification obligations within 24/72 hours/1 month
  • Management liability and training
  • BSI registration and monitoring
  • Sector-specific requirements

BSI IT Baseline Protection provides a solid foundation for NIS2 compliance:

  • Building block-oriented implementation
  • Structured risk assessment
  • Established security measures
  • Proven audit procedures

Practice Tip: Combine Standards Companies with ISO 27001 certification or IT Baseline Protection implementation already have a good starting point. Existing processes only need to be extended with NIS2-specific elements.

Implementation Strategies and Best Practices

Section titled “Implementation Strategies and Best Practices”

Threshold Analysis:

  • Review of industry affiliation
  • Assessment of company size (employees, turnover, balance sheet)
  • Identification of critical business areas
  • Consideration of subsidiaries and group structures

Special Attention for:

  • DNS, cloud, or TLD service providers (size-independent)
  • Companies with mixed business areas
  • International group structures

Establish Risk Management:

  • Systematic threat and vulnerability analysis
  • Definition of protection objectives and acceptance thresholds
  • Implementation of risk-based controls
  • Continuous monitoring and improvement

Cover All NIS2 Topic Areas:

  • Business continuity and disaster recovery
  • Supply chain security and vendor management
  • Vulnerability management and patch processes
  • Training programs for all employee levels

Define Notification Processes:

  • Clear responsibilities and escalation paths
  • Templates for initial, follow-up, and final reports
  • Integration into existing incident response processes
  • Regular exercises and tests

Ensure Documentation:

  • All security measures and risk assessments
  • Training records and management training
  • Audit results and improvement measures
  • Supplier assessments and contracts

Insufficient Scope Definition:

  • Overlooking subsidiaries or business areas
  • Incorrect assessment of size criteria
  • Incomplete coverage of digital services

Lack of Management Involvement:

  • Treatment as purely IT-technical topic
  • Missing executive training
  • Insufficient resource allocation

Incomplete Supply Chain Analysis:

  • Neglecting cloud service providers
  • Missing contract adjustments with suppliers
  • Insufficient monitoring of third parties

The fuentis Suite provides comprehensive support for NIS2 implementation:

  • Pre-configured requirements according to § 30 BSIG-E
  • Automatic applicability check based on size criteria
  • Gap analysis to existing ISMS standards
  • Compliance dashboard with implementation status
  • Structured capture of all NIS2-relevant risks
  • Linking with assets and business processes
  • Automatic risk assessment and prioritization
  • Integration with existing risk management processes
  • Mapping of three-stage notification processes
  • Automatic reminders for notification deadlines
  • Templates for BSI notifications
  • Documentation and tracking of incidents
  • Central capture of all information-processing assets
  • Assignment of responsibilities and criticalities
  • Monitoring of changes and updates
  • Integration with configuration management
  • Assessment and monitoring of service providers
  • Management of security requirements and evidence
  • Audit planning and execution
  • Contract management with security clauses
  • Planning and conducting internal audits
  • Tracking non-conformities and measures
  • Management review support
  • Automated reporting for BSI audits
  • NIS2-specific training modules
  • Management training on cyber risks
  • Employee awareness programs
  • Tracking of training completions and deadlines

KRITIS Audits (every 3 years):

  • Complete review of all measures
  • On-site audits or remote assessments
  • Alternative: Recognized certifications (ISO 27001, IT Baseline Protection)

Random BSI Audits:

  • Risk-based selection of companies
  • Focus on specific vulnerabilities or incidents
  • Short notice periods

Documentation Requirements:

  • Complete ISMS documentation
  • Evidence for all implemented measures
  • Risk assessments and treatment strategies
  • Incident response plans and evidence
  • Training materials and certificates

Practical Tips:

  • Regular internal audits as preparation
  • Continuous documentation updates
  • Clear responsibilities and contact persons
  • Practice audit situations with the team

Trends in the EU:

  • Further harmonization of national implementations
  • Increased cross-border cooperation
  • Integration with other EU cybersecurity initiatives
  • Possible tightening of requirements

New Challenges:

  • Artificial intelligence and machine learning
  • IoT and Industrial IoT security
  • 5G networks and edge computing
  • Quantum computing and post-quantum cryptography

Adaptation of Requirements:

  • Regular updates of technical standards
  • Consideration of new threat scenarios
  • Evolution of “state of the art” definition

The 5 Most Important Success Factors for NIS2 Compliance:

  1. Early Applicability Assessment: Clarify immediately whether your company falls under NIS2 - the size criteria are complex and capture significantly more organizations than before

  2. ISMS as Compliance Foundation: An established information security management system according to ISO 27001 or IT Baseline Protection forms the best basis for NIS2 compliance

  3. Secure Management Commitment: Personal liability of management makes cybersecurity a top management issue - management training and involvement are indispensable

  4. Build Incident Response Capabilities: The 24-hour notification obligation requires established processes, clear responsibilities, and practiced procedures

  5. Systematically Secure Supply Chains: Supply chain risks are a central NIS2 topic - assess and monitor all critical service providers and suppliers

Why NIS2 is More Than Just Compliance: NIS2 marks the transition from voluntary to mandatory cybersecurity for large parts of the economy. Companies that proactively implement NIS2 create not only legal certainty but also a sustainable competitive advantage through increased resilience, customer trust, and operational excellence in digital transformation.