NIS2 covers 18 sectors: eleven sectors of high criticality in Annex I (including energy, transport, banking, financial market infrastructures, health, drinking water and waste water, digital infrastructure, B2B ICT service management, public administration, space) and seven other critical sectors in Annex II (including postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research). Under the size-cap rule, companies in these sectors are in scope in principle from medium size upwards – from 50 employees or more than EUR 10 million in annual turnover and annual balance sheet total, calculated in accordance with Recommendation 2003/361/EC. Large companies in the Annex I sectors (from 250 employees or over EUR 50 million in turnover and over EUR 43 million in balance sheet total) are generally classified as essential entities, the rest as important ones. Certain providers, such as qualified trust service providers, are covered regardless of their size.
NIS2: The EU Legal Framework for Cybersecurity
What Directive (EU) 2022/2555 requires of essential and important entities – and how Germany has implemented it in the BSIG through the NIS2UmsuCG.
With Directive (EU) 2022/2555 (NIS2), the EU has fundamentally expanded its legal framework for cybersecurity: instead of a narrow circle of critical infrastructure operators, it addresses 18 sectors and explicitly makes cybersecurity a responsibility of the management level. At its core are a catalogue of ten minimum measures, tiered reporting obligations for significant incidents and substantial sanctions. Germany has implemented the directive through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), which has been in force since 6 December 2025 and anchors the obligations in the revised BSIG. For the estimated 30,000 or so affected entities, three questions arise above all: Am I in scope, which obligations apply – and how do I demonstrate compliance with them?
From the Directive to the BSIG: key milestones
Tap a milestone for details.
EU transposition deadline expires
The EU transposition deadline for Directive (EU) 2022/2555 expires — the German implementation follows a good year later.
Bundestag adopts the NIS2UmsuCG
The Bundestag adopts the NIS2 Implementation and Cybersecurity Strengthening Act; its centrepiece is the revised BSIG.
NIS2UmsuCG enters into force
The obligations are anchored in the revised BSIG — the legislator assumes around 30,000 affected entities.
Statutory registration deadline expires
For entities already in scope when the law entered into force, the three-month deadline for self-registration with the BSI expires (§ 33 BSIG).
BSI grace period ends
A grace period communicated by the BSI for registration ends; organisations must assess their own applicability on their own responsibility — no official notification is foreseen.
The Essentials at a Glance
Six topic blocks — tap to expand.
Am I in scope? Sectors and thresholds
Annex I, Annex II and the size-cap rule at a glance.
- Eleven sectors of high criticality — from energy and health to space.
- Large companies in these sectors are generally classified as essential entities.
- Seven other critical sectors — from postal and courier services to research.
- The size-cap rule applies here too: in scope in principle from medium size upwards.
- In scope in principle from 50 employees or more than EUR 10 million in annual turnover and annual balance sheet total.
- Large Annex I companies (from 250 employees or over EUR 50 million in turnover and over EUR 43 million in balance sheet total) are generally classified as essential entities.
- Certain providers, such as qualified trust service providers, are covered regardless of their size.
NIS2 Reality Check — Registration, Supply Chain & Liability
The first year of NIS2 in a CISO whitepaper: the registration gap, supply chain as a core duty and the personal liability of management — an actionable roadmap after the deadline.
Registration after the deadline
The BSI portal, the missed deadline and why catching up ends the ongoing breach but doesn't heal the past.
Supply-chain security
Why Section 30 BSIG makes the supply chain a standalone duty and certificates alone aren't enough.
Management liability
Personal liability under Section 38 BSIG, the training duty and the fine framework.
12-step roadmap
Twelve concrete steps from gap to conformity — plus the NIS2 calendar.
German-language whitepaper · direct download after a short request.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Richtlinie (EU) 2022/2555 (NIS-2-Richtlinie)
Primary source for Art. 20 (governance and training obligation), Art. 21(2) (ten minimum measures), Art. 23 (reporting deadlines) as well as Annexes I and II with the 18 sectors.
Gesetz über das Bundesamt für Sicherheit in der Informationstechnik (BSIG)
German implementation: §§ 28, 30, 32, 33 and 38 BSIG govern entity categories, risk management, reporting obligations, registration and management duties.
NIS-2-regulierte Unternehmen (Themenseite)
Official information on registration via the BSI portal, on the online applicability check and on the obligations of particularly important and important entities.
NIS2-Umsetzungsgesetz (Themenseite)
Timeline of the German implementation, entity categories under § 28 BSIG and the estimate of around 30,000 affected companies.
Clarify whether NIS2 applies to you and implement your obligations in a structured way?
In a no-obligation initial consultation, we classify your organisation and show you how to set up registration, risk management and reporting processes pragmatically – integrated with ISO/IEC 27001.