
The ultimate guide to NIS2 and email security: What the law requires, which businesses are affected, and how to implement §30 BSIG for email.
The NIS2 Implementation Act came into force on December 6, 2025 – with no transition period. Approximately 29,500 companies in Germany must implement the new cybersecurity obligations immediately. Email is at the center: Over 90% of all successful cyberattacks start with a phishing email.
This guide explains what NIS2 specifically means for your email infrastructure, which measures are mandatory, and how to implement the requirements efficiently.
The NIS2 Directive (Network and Information Security Directive 2) is an EU-wide regulation to strengthen cybersecurity. In Germany, it was transposed into national law through the NIS2 Implementation Act (NIS2UmsuCG) and published as the revised BSI Act (BSIG) on December 6, 2025.
At its core, NIS2 requires companies to implement specific technical and organizational measures in the area of cybersecurity – including explicitly securing email communication.
NIS2 applies to companies that meet at least one of the following criteria:
Size criteria:
Sector affiliation (18 sectors):
Essential entities:
Important entities:
Important: Suppliers of affected companies can also be indirectly obligated – regardless of their own size.
§30 BSIG defines for risk management. Six of them directly affect email security:
The latest posts from our blog.

An Email Security Gateway is the central line of defense for business email communication. This guide explains how it works, what threats it blocks, and why it is essential for NIS2 and GDPR…

Choosing the right Email Security Gateway is critical for business communication security. This comparison shows the most important criteria and typical pitfalls.

Proper configuration of a Secure Email Gateway determines security and user experience. These 10 best practices help IT teams achieve optimal setup.
Legal text: Concepts and procedures for the use of cryptographic methods.
For email, this means:
Legal text: Secured voice, video, and text communication as well as secured emergency communication.
For email, this means:
Legal text: Management of security incidents.
For email, this means:
Legal text: Security in the supply chain including communication.
For email, this means:
Email as attack vector No. 1 must be a central consideration in every risk analysis. Transparency across the entire mail flow is mandatory.
Email availability must be ensured through appropriate measures (redundancy, SLA guarantees, failover).
To cover all requirements, companies need five layers of protection:
Use this checklist to make your email infrastructure NIS2-compliant:
The consequences of non-compliance are significant:
Essential entities:
Important entities:
Personal liability: Under §38 BSIG, management must approve risk management measures and oversee their implementation. If they fail to fulfill this duty, they are personally liable.
Conbool is the only platform that combines all three email security requirements on a single platform:
Setup takes minutes, not months: Register your domain, set the MX record, configure policies – done. Hosted in ISO 27001 certified data centers in Frankfurt and Berlin.
NIS2 makes email security mandatory – with personal executive liability and fines up to EUR 10 million. Companies that act now not only protect their communication but also avoid severe penalties.
The good news: With the right solution, implementation takes just a few minutes. Conbool covers all email requirements under §30 BSIG – automated, auditable, and Made in Germany.
Further reading: