01Scope: 18 Sectors and the Size-Cap Rule
NIS2 covers 18 sectors: eleven sectors of high criticality in Annex I (including energy, transport, banking, financial market infrastructures, health, drinking water and waste water, digital infrastructure, B2B ICT service management, public administration, space) and seven other critical sectors in Annex II (including postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research). Under the size-cap rule, companies in these sectors are in scope in principle from medium size upwards – from 50 employees or more than EUR 10 million in annual turnover and annual balance sheet total, calculated in accordance with Recommendation 2003/361/EC. Large companies in the Annex I sectors (from 250 employees or over EUR 50 million in turnover and over EUR 43 million in balance sheet total) are generally classified as essential entities, the rest as important ones. Certain providers, such as qualified trust service providers, are covered regardless of their size.
02Governance and Training Obligations for Management Bodies (Art. 20)
Art. 20 anchors cybersecurity as a management responsibility: management bodies must approve the risk management measures under Art. 21, oversee their implementation and can be held liable for infringements. Art. 20(2) obliges the members of management bodies to attend training in order to be able to identify risks and assess risk management practices and their impact on the services provided; comparable training is to be offered to employees on a regular basis. The German implementation in § 38 BSIG goes further: management must implement the measures themselves and monitor their implementation, they are liable under the rules of company law for damage caused culpably, and participation in training is explicitly designed as a regular obligation (§ 38(3) BSIG).
03The Ten Minimum Measures under Art. 21(2)
All entities must take appropriate and proportionate technical, operational and organisational measures based on an all-hazards approach. Art. 21(2) lists ten minimum areas for this: policies on risk analysis and information system security, incident handling, business continuity with backup, recovery and crisis management, supply chain security including relationships with direct suppliers (point (d)), security in the acquisition, development and maintenance of IT systems including vulnerability handling, policies to assess the effectiveness of the measures, cyber hygiene and cybersecurity training, cryptography and encryption, human resources security with access control and asset management, and multi-factor authentication and secured (emergency) communication. § 30(2) BSIG transposes this catalogue almost word for word into German law.
04Reporting Obligations: 24 Hours, 72 Hours, One Month (Art. 23)
Significant incidents must be reported in stages: an early warning without undue delay, at the latest 24 hours after becoming aware of the incident; a notification with an initial assessment of severity, impact and indicators of compromise at the latest after 72 hours; upon request, an intermediate report on status updates; and at the latest one month after the notification, a final report covering causes, type of threat and remediation measures. If the incident is still ongoing, a progress report initially takes the place of the final report. In Germany, the BSI receives the reports (§ 32 BSIG); operators of critical facilities must additionally provide information on the affected facility and the impact of its failure.
05German Implementation: NIS2UmsuCG and Registration Obligation
The Bundestag adopted the NIS2UmsuCG on 13 November 2025; it has been in force since 6 December 2025 – a good year after the EU transposition deadline expired in October 2024. Its centrepiece is the revised BSIG: it distinguishes between particularly important entities, important entities and operators of critical facilities (§ 28 BSIG); the legislator assumes around 30,000 affected entities. Affected organisations must register themselves with the BSI within three months (§ 33 BSIG) – for entities that were already in scope when the law entered into force, the statutory deadline expired on 6 March 2026, and a grace period communicated by the BSI ends on 31 July 2026. For self-assessment, the BSI provides a non-binding online applicability check; no official notification is foreseen – organisations must assess their own applicability on their own responsibility.
06Sanctions and Supervision
For essential entities, NIS2 provides for fines of up to EUR 10 million or 2% of worldwide annual turnover, for important entities up to EUR 7 million or 1.4% – whichever amount is higher applies. The German BSIG adopts these fine frameworks (§ 65 BSIG). In addition, the BSI has supervisory powers ranging from requests for information to audits, with supervision of particularly important entities reaching further than that of important ones. On top of this comes the personal responsibility of management under § 38 BSIG, who cannot escape their implementation and oversight duties by delegation.