NIS2 Compliance Checklist for Companies Operating in Germany
NIS2 turns cybersecurity from best practice into a legal duty for companies in 18 regulated sectors across the EU. In Germany it is implemented via the BSIG, the national cybersecurity act, and supervised by the BSI. As a rule of thumb, companies with 50 or more employees or €10 million in turnover in a covered sector should assume they are in scope — including German subsidiaries of international groups.
The core obligations are concrete: documented cyber risk management, technical and organizational security measures including supply-chain security, registration with the BSI, and an incident-reporting process fast enough to hit a 24-hour early-warning deadline. Executive management must approve and oversee these measures personally. The checklist below breaks the program into practical steps you can start today.
Your checklist
- 1Assess applicability: map your German and EU entities against the 18 NIS2 sectors and the size thresholds (roughly 50+ employees or €10M+ turnover), and document the result even if you conclude you are out of scope.
- 2Classify your entity: determine whether you qualify as an 'essential' or 'important' entity under the BSIG, since this drives the intensity of supervision.
- 3Register with the BSI: complete the mandatory registration for in-scope entities and designate a point of contact reachable by the authority.
- 4Establish risk management: identify and assess cyber risks across IT and OT, and document a risk-management concept that management formally approves.
- 5Implement baseline security measures: access controls, encryption, backup and recovery, vulnerability handling, and multi-factor authentication where appropriate.
- 6Secure the supply chain: assess key suppliers and service providers, and add cybersecurity requirements to contracts with critical vendors.
- 7Build a 24-hour incident-reporting process: define what counts as a significant incident, who reports to the BSI, and test the workflow before you need it.
- 8Train management and staff: NIS2 expects regular cybersecurity training, including for the executive level that carries personal oversight responsibility.
- 9Review annually: reassess scope, risks, and measures at least yearly and after major changes such as acquisitions or new services in Germany.
Frequently asked questions
How do I find out whether my company is in scope of NIS2?
Check three things: whether your activities fall into one of the 18 regulated sectors, whether you meet the size thresholds (roughly 50+ employees or €10 million+ turnover), and whether you provide those services in the EU. The BSI offers an official self-assessment tool, and the result should be documented either way.
What documentation does the BSI expect from in-scope companies?
At minimum a documented risk-management concept, evidence of implemented technical and organizational security measures, a business-continuity plan, and a defined incident-reporting process. The documentation must show that executive management approved and monitors these measures.
We are a supplier to a NIS2-regulated company but not in scope ourselves. What should we do?
Expect contractual pass-through. NIS2 requires in-scope entities to manage supply-chain risk, so regulated customers increasingly demand security measures, audit rights, and incident-notification duties from vendors. Working through the same checklist positions you to keep those contracts.