NIS2 Compliance Checklist for Companies Operating in Germany

NIS2 turns cybersecurity from best practice into a legal duty for companies in 18 regulated sectors across the EU. In Germany it is implemented via the BSIG, the national cybersecurity act, and supervised by the BSI. As a rule of thumb, companies with 50 or more employees or €10 million in turnover in a covered sector should assume they are in scope — including German subsidiaries of international groups.

The core obligations are concrete: documented cyber risk management, technical and organizational security measures including supply-chain security, registration with the BSI, and an incident-reporting process fast enough to hit a 24-hour early-warning deadline. Executive management must approve and oversee these measures personally. The checklist below breaks the program into practical steps you can start today.

Your checklist

  1. 1Assess applicability: map your German and EU entities against the 18 NIS2 sectors and the size thresholds (roughly 50+ employees or €10M+ turnover), and document the result even if you conclude you are out of scope.
  2. 2Classify your entity: determine whether you qualify as an 'essential' or 'important' entity under the BSIG, since this drives the intensity of supervision.
  3. 3Register with the BSI: complete the mandatory registration for in-scope entities and designate a point of contact reachable by the authority.
  4. 4Establish risk management: identify and assess cyber risks across IT and OT, and document a risk-management concept that management formally approves.
  5. 5Implement baseline security measures: access controls, encryption, backup and recovery, vulnerability handling, and multi-factor authentication where appropriate.
  6. 6Secure the supply chain: assess key suppliers and service providers, and add cybersecurity requirements to contracts with critical vendors.
  7. 7Build a 24-hour incident-reporting process: define what counts as a significant incident, who reports to the BSI, and test the workflow before you need it.
  8. 8Train management and staff: NIS2 expects regular cybersecurity training, including for the executive level that carries personal oversight responsibility.
  9. 9Review annually: reassess scope, risks, and measures at least yearly and after major changes such as acquisitions or new services in Germany.

Matching tool

Comply with NIS2 before the BSI comes knocking.

NIS2 Shield → Check now for free

Frequently asked questions

How do I find out whether my company is in scope of NIS2?

Check three things: whether your activities fall into one of the 18 regulated sectors, whether you meet the size thresholds (roughly 50+ employees or €10 million+ turnover), and whether you provide those services in the EU. The BSI offers an official self-assessment tool, and the result should be documented either way.

What documentation does the BSI expect from in-scope companies?

At minimum a documented risk-management concept, evidence of implemented technical and organizational security measures, a business-continuity plan, and a defined incident-reporting process. The documentation must show that executive management approved and monitors these measures.

We are a supplier to a NIS2-regulated company but not in scope ourselves. What should we do?

Expect contractual pass-through. NIS2 requires in-scope entities to manage supply-chain risk, so regulated customers increasingly demand security measures, audit rights, and incident-notification duties from vendors. Working through the same checklist positions you to keep those contracts.

More about NIS2 Shield →