Book an Appointment

NIS2: The EU Legal Framework for Cybersecurity

What Directive (EU) 2022/2555 requires of essential and important entities – and how Germany has implemented it in the BSIG through the NIS2UmsuCG.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

18sectors in scope
10minimum measures under Art. 21(2)
24hours at the latest for the early warning
~30,000affected entities (legislator's estimate)

With Directive (EU) 2022/2555 (NIS2), the EU has fundamentally expanded its legal framework for cybersecurity: instead of a narrow circle of critical infrastructure operators, it addresses 18 sectors and explicitly makes cybersecurity a responsibility of the management level. At its core are a catalogue of ten minimum measures, tiered reporting obligations for significant incidents and substantial sanctions. Germany has implemented the directive through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), which has been in force since 6 December 2025 and anchors the obligations in the revised BSIG. For the estimated 30,000 or so affected entities, three questions arise above all: Am I in scope, which obligations apply – and how do I demonstrate compliance with them?

From the Directive to the BSIG: key milestones

Tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Am I in scope? Sectors and thresholds

Annex I, Annex II and the size-cap rule at a glance.

11 sectors
  • Eleven sectors of high criticality — from energy and health to space.
  • Large companies in these sectors are generally classified as essential entities.
EnergyTransportBankingHealthDrinking water and waste waterDigital infrastructurePublic administrationSpace
In-depth whitepaper

NIS2 Reality Check — Registration, Supply Chain & Liability

The first year of NIS2 in a CISO whitepaper: the registration gap, supply chain as a core duty and the personal liability of management — an actionable roadmap after the deadline.

Registration after the deadline

The BSI portal, the missed deadline and why catching up ends the ongoing breach but doesn't heal the past.

Supply-chain security

Why Section 30 BSIG makes the supply chain a standalone duty and certificates alone aren't enough.

Management liability

Personal liability under Section 38 BSIG, the training duty and the fine framework.

12-step roadmap

Twelve concrete steps from gap to conformity — plus the NIS2 calendar.

Download the whitepaper (free)

German-language whitepaper · direct download after a short request.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der Europäischen Union / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS-2-Richtlinie)

Primary source for Art. 20 (governance and training obligation), Art. 21(2) (ten minimum measures), Art. 23 (reporting deadlines) as well as Annexes I and II with the 18 sectors.

Bundesministerium der Justiz / gesetze-im-internet.de · 2025

Gesetz über das Bundesamt für Sicherheit in der Informationstechnik (BSIG)

German implementation: §§ 28, 30, 32, 33 and 38 BSIG govern entity categories, risk management, reporting obligations, registration and management duties.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

NIS-2-regulierte Unternehmen (Themenseite)

Official information on registration via the BSI portal, on the online applicability check and on the obligations of particularly important and important entities.

OpenKRITIS · 2026

NIS2-Umsetzungsgesetz (Themenseite)

Timeline of the German implementation, entity categories under § 28 BSIG and the estimate of around 30,000 affected companies.

Clarify whether NIS2 applies to you and implement your obligations in a structured way?

In a no-obligation initial consultation, we classify your organisation and show you how to set up registration, risk management and reporting processes pragmatically – integrated with ISO/IEC 27001.