
The ultimate guide to NIS2 and email security: What the law requires, which businesses are affected, and how to implement §30 BSIG for email.
The NIS2 Implementation Act came into force on December 6, 2025 – with no transition period. Approximately 29,500 companies in Germany must implement the new cybersecurity obligations immediately. Email is at the center: Over 90% of all successful cyberattacks start with a phishing email.
This guide explains what NIS2 specifically means for your email infrastructure, which measures are mandatory, and how to implement the requirements efficiently.
The NIS2 Directive (Network and Information Security Directive 2) is an EU-wide regulation to strengthen cybersecurity. In Germany, it was transposed into national law through the NIS2 Implementation Act (NIS2UmsuCG) and published as the revised BSI Act (BSIG) on December 6, 2025.
At its core, NIS2 requires companies to implement specific technical and organizational measures in the area of cybersecurity – including explicitly securing email communication.
NIS2 applies to companies that meet at least one of the following criteria:
Size criteria:
Sector affiliation (18 sectors):
Essential entities:
Important entities:
Important: Suppliers of affected companies can also be indirectly obligated – regardless of their own size.
§30 BSIG defines for risk management. Six of them directly affect email security:
Die neuesten Beiträge aus unserem Blog.

Die richtige Konfiguration eines Secure Email Gateways entscheidet über Sicherheit und Nutzererfahrung. Diese 10 Best Practices helfen IT-Teams bei der optimalen Einrichtung.

Die Auswahl des richtigen Email Security Gateways ist entscheidend für die Sicherheit der Unternehmenskommunikation. Dieser Vergleich zeigt die wichtigsten Kriterien und typische Fallstricke.

Microsoft 365 bietet Basis-Sicherheit, aber kein vollständiges Email Security Gateway. Dieser Guide zeigt, welche Lücken bestehen und wie ein externes Gateway sie schließt.
Legal text: Concepts and procedures for the use of cryptographic methods.
For email, this means:
Legal text: Secured voice, video, and text communication as well as secured emergency communication.
For email, this means:
Legal text: Management of security incidents.
For email, this means:
Legal text: Security in the supply chain including communication.
For email, this means:
Email as attack vector No. 1 must be a central consideration in every risk analysis. Transparency across the entire mail flow is mandatory.
Email availability must be ensured through appropriate measures (redundancy, SLA guarantees, failover).
To cover all requirements, companies need five layers of protection:
Use this checklist to make your email infrastructure NIS2-compliant:
The consequences of non-compliance are significant:
Essential entities:
Important entities:
Personal liability: Under §38 BSIG, management must approve risk management measures and oversee their implementation. If they fail to fulfill this duty, they are personally liable.
Conbool is the only platform that combines all three email security requirements on a single platform:
Setup takes minutes, not months: Register your domain, set the MX record, configure policies – done. Hosted in ISO 27001 certified data centers in Frankfurt and Berlin.
NIS2 makes email security mandatory – with personal executive liability and fines up to EUR 10 million. Companies that act now not only protect their communication but also avoid severe penalties.
The good news: With the right solution, implementation takes just a few minutes. Conbool covers all email requirements under §30 BSIG – automated, auditable, and Made in Germany.
Further reading: