NIS2: Who is affected and what to do now
A practical guide to the applicability analysis and the key obligations under the German BSIG.
Who falls under NIS2?
The NIS2 Directive significantly widens the circle of regulated companies. It covers medium-sized and large entities in critical sectors — from energy and healthcare to drinking water and digital infrastructure. Providers of cloud services, data center services, and social networks also fall within its scope.
As a rule of thumb: companies with 50 or more employees or €10 million in annual turnover in one of the 18 defined sectors should assume they are in scope and document this properly. Supply chain obligations can also mean that smaller suppliers become indirectly obligated.
Essential and important entities
The German implementation act (BSIG) distinguishes two categories. Essential entities (250 or more employees or €50 million in turnover in particularly critical sectors such as energy, transport, or healthcare) are subject to stricter requirements and proactive supervision. Important entities (50–249 employees) are supervised reactively but must meet the same technical measures.
The key obligations at a glance
- Risk management: identification and assessment of cyber risks, with a documented concept
- Security measures: access controls, encryption, securing supply chains
- Incident reporting: initial report to the BSI within 24 hours, follow-up report after 72 hours
- Management duties: personal responsibility and active oversight of the measures
- Training: regular training for management and employees
Personal liability of management
A key difference from earlier rules: the NIS2 implementation act (BSIG) establishes personal liability for company management. Anyone who fails to actively oversee the implementation of the cybersecurity measures is personally liable — regardless of any corporate insurance. Fines of up to €10 million or 2% of global annual turnover can be imposed.
The BSI check as a first step
Whether your company is affected can be clarified quickly with the official applicability checker from the BSI, Germany's Federal Office for Information Security. It asks for your sector, headcount, and turnover and gives an initial assessment. The formal obligation to register with the BSI applies once the national implementation of the BSIG enters into force.
Frequently asked questions
Is my company affected by NIS2 if we have fewer than 50 employees?
Companies with fewer than 50 employees are generally not directly affected by NIS2. Exception: critical infrastructure (KRITIS) entities and providers of certain digital services may be in scope regardless of size. As a supplier, you can also be contractually pulled into NIS2 obligations.
What are the reporting obligations for a security incident under NIS2?
Affected entities must report significant security incidents to the BSI without undue delay, where feasible within 24 hours, as an early warning. A full report with an initial assessment follows within 72 hours. A final report must be submitted no later than one month after.
When does the NIS2 implementation act (BSIG) fully enter into force in Germany?
Germany has transposed the NIS2 Directive into national law with the new BSIG. Affected companies must meet the requirements immediately upon entry into force and register with the BSI.
How does NIS2 differ from the original NIS Directive?
NIS2 expands the covered sectors from 7 to 18, lowers the thresholds, introduces personal liability for management, and significantly tightens the sanctions. Fines rise from a previous maximum of €100,000 to up to €10 million or 2% of annual turnover.