Book an Appointment

NIS2: The EU Legal Framework for Cybersecurity

What Directive (EU) 2022/2555 requires of essential and important entities – and how Germany has implemented it in the BSIG through the NIS2UmsuCG.

With Directive (EU) 2022/2555 (NIS2), the EU has fundamentally expanded its legal framework for cybersecurity: instead of a narrow circle of critical infrastructure operators, it addresses 18 sectors and explicitly makes cybersecurity a responsibility of the management level. At its core are a catalogue of ten minimum measures, tiered reporting obligations for significant incidents and substantial sanctions. Germany has implemented the directive through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), which has been in force since 6 December 2025 and anchors the obligations in the revised BSIG. For the estimated 30,000 or so affected entities, three questions arise above all: Am I in scope, which obligations apply – and how do I demonstrate compliance with them?

The Essentials at a Glance

01

Scope: 18 Sectors and the Size-Cap Rule

NIS2 covers 18 sectors: eleven sectors of high criticality in Annex I (including energy, transport, banking, financial market infrastructures, health, drinking water and waste water, digital infrastructure, B2B ICT service management, public administration, space) and seven other critical sectors in Annex II (including postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research). Under the size-cap rule, companies in these sectors are in scope in principle from medium size upwards – from 50 employees or more than EUR 10 million in annual turnover and annual balance sheet total, calculated in accordance with Recommendation 2003/361/EC. Large companies in the Annex I sectors (from 250 employees or over EUR 50 million in turnover and over EUR 43 million in balance sheet total) are generally classified as essential entities, the rest as important ones. Certain providers, such as qualified trust service providers, are covered regardless of their size.

02

Governance and Training Obligations for Management Bodies (Art. 20)

Art. 20 anchors cybersecurity as a management responsibility: management bodies must approve the risk management measures under Art. 21, oversee their implementation and can be held liable for infringements. Art. 20(2) obliges the members of management bodies to attend training in order to be able to identify risks and assess risk management practices and their impact on the services provided; comparable training is to be offered to employees on a regular basis. The German implementation in § 38 BSIG goes further: management must implement the measures themselves and monitor their implementation, they are liable under the rules of company law for damage caused culpably, and participation in training is explicitly designed as a regular obligation (§ 38(3) BSIG).

03

The Ten Minimum Measures under Art. 21(2)

All entities must take appropriate and proportionate technical, operational and organisational measures based on an all-hazards approach. Art. 21(2) lists ten minimum areas for this: policies on risk analysis and information system security, incident handling, business continuity with backup, recovery and crisis management, supply chain security including relationships with direct suppliers (point (d)), security in the acquisition, development and maintenance of IT systems including vulnerability handling, policies to assess the effectiveness of the measures, cyber hygiene and cybersecurity training, cryptography and encryption, human resources security with access control and asset management, and multi-factor authentication and secured (emergency) communication. § 30(2) BSIG transposes this catalogue almost word for word into German law.

04

Reporting Obligations: 24 Hours, 72 Hours, One Month (Art. 23)

Significant incidents must be reported in stages: an early warning without undue delay, at the latest 24 hours after becoming aware of the incident; a notification with an initial assessment of severity, impact and indicators of compromise at the latest after 72 hours; upon request, an intermediate report on status updates; and at the latest one month after the notification, a final report covering causes, type of threat and remediation measures. If the incident is still ongoing, a progress report initially takes the place of the final report. In Germany, the BSI receives the reports (§ 32 BSIG); operators of critical facilities must additionally provide information on the affected facility and the impact of its failure.

05

German Implementation: NIS2UmsuCG and Registration Obligation

The Bundestag adopted the NIS2UmsuCG on 13 November 2025; it has been in force since 6 December 2025 – a good year after the EU transposition deadline expired in October 2024. Its centrepiece is the revised BSIG: it distinguishes between particularly important entities, important entities and operators of critical facilities (§ 28 BSIG); the legislator assumes around 30,000 affected entities. Affected organisations must register themselves with the BSI within three months (§ 33 BSIG) – for entities that were already in scope when the law entered into force, the statutory deadline expired on 6 March 2026, and a grace period communicated by the BSI ends on 31 July 2026. For self-assessment, the BSI provides a non-binding online applicability check; no official notification is foreseen – organisations must assess their own applicability on their own responsibility.

06

Sanctions and Supervision

For essential entities, NIS2 provides for fines of up to EUR 10 million or 2% of worldwide annual turnover, for important entities up to EUR 7 million or 1.4% – whichever amount is higher applies. The German BSIG adopts these fine frameworks (§ 65 BSIG). In addition, the BSI has supervisory powers ranging from requests for information to audits, with supervision of particularly important entities reaching further than that of important ones. On top of this comes the personal responsibility of management under § 38 BSIG, who cannot escape their implementation and oversight duties by delegation.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der Europäischen Union / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS-2-Richtlinie)

Primary source for Art. 20 (governance and training obligation), Art. 21(2) (ten minimum measures), Art. 23 (reporting deadlines) as well as Annexes I and II with the 18 sectors.

Bundesministerium der Justiz / gesetze-im-internet.de · 2025

Gesetz über das Bundesamt für Sicherheit in der Informationstechnik (BSIG)

German implementation: §§ 28, 30, 32, 33 and 38 BSIG govern entity categories, risk management, reporting obligations, registration and management duties.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2026

NIS-2-regulierte Unternehmen (Themenseite)

Official information on registration via the BSI portal, on the online applicability check and on the obligations of particularly important and important entities.

OpenKRITIS · 2026

NIS2-Umsetzungsgesetz (Themenseite)

Timeline of the German implementation, entity categories under § 28 BSIG and the estimate of around 30,000 affected companies.

Clarify whether NIS2 applies to you and implement your obligations in a structured way?

In a no-obligation initial consultation, we classify your organisation and show you how to set up registration, risk management and reporting processes pragmatically – integrated with ISO/IEC 27001.