NIS2
NIS2 is the EU cybersecurity directive. In Germany it applies through the NIS2 Implementation Act, which writes the duties into the BSI Act. This page explains who is in scope, what Section 30 BSIG requires and which deadlines are running.
Last updated: 2 September 2026
What is NIS2?
NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It obliges companies in 18 sectors to manage risk, report security incidents and implement technical minimum measures. In Germany it has applied since 6 December 2025 through the NIS2 Implementation Act.
The spelling "NIS 2" with a space means the same thing. The name refers to the second version of the Network and Information Security Directive; it replaces the 2016 original and widens its scope considerably: instead of some 500 critical infrastructure operators, around 29,500 German companies now fall under it.
The real change is liability. NIS2 makes cybersecurity a management duty: the management body must approve the risk management measures, oversee their implementation and is personally liable under Section 38 BSIG. That duty cannot be delegated.
NIS2 in numbers
- 29,500
- affected companies in Germany
- 18
- sectors in scope
- 24 hrs
- deadline for the initial incident report
- EUR 10m
- maximum fine, or 2 % of annual turnover
Directive, implementation act, BSIG
Three names, one body of rules. Knowing the chain is how you find the provision that actually applies.
- European level
The NIS2 Directive
Directive (EU) 2022/2555, in force since January 2023. A directive does not apply directly: it obliges member states to translate it into national law. For companies it is therefore an aid to interpretation, not a legal basis.
- National implementation
The NIS2 Implementation Act
The NIS2 Implementation and Cybersecurity Strengthening Act entered into force on 6 December 2025. It is an amending act: it contains few duties of its own and instead rewrites the BSI Act. Anyone looking for the statutory text is looking for the BSIG.
- Applicable law
The BSIG
The BSI Act carries the duties. Section 28 defines scope, Section 30 the risk management measures, Sections 32 to 35 reporting and registration, Section 38 the duties of the management body and Section 65 the fines. There is no transition period.
Who is in scope?
Two criteria must coincide: sector and size. Where both apply, NIS2 applies automatically, with no notice and no request.
Essential entities
250 or more employees, or turnover above EUR 50m and a balance sheet total above EUR 43m
In the sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space. These entities are subject to ongoing supervision by the BSI.
Fines up to EUR 10m or 2 % of worldwide annual turnover
Important entities
50 or more employees, or turnover and balance sheet total above EUR 10m
All remaining sectors as well as smaller entities in those listed above: postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research. Supervision is triggered by cause; the duties themselves are identical.
Fines up to EUR 7m or 1.4 % of worldwide annual turnover
Regardless of size
Operators of critical installations, qualified trust service providers, top-level domain registries, DNS providers and providers of public telecommunications networks fall under NIS2 irrespective of headcount or turnover.
What about suppliers?
Suppliers are not automatically in scope themselves, but they are bound contractually: Section 30(2) no. 4 requires affected companies to assess the security of their direct suppliers. In practice that means questionnaires, evidence and contract clauses passing the standard down the chain.
The 18 sectors
Sectors of high criticality first, then the other critical sectors.
- Energy
- Transport
- Banking
- Financial market infrastructure
- Health
- Drinking water
- Waste water
- Digital infrastructure
- ICT service management
- Public administration
- Space
- Postal and courier
- Waste management
- Chemicals
- Food
- Manufacturing
- Digital providers
- Research
The ten requirements under Section 30 BSIG
Section 30(2) BSIG lists ten measures every affected company must implement. They follow Article 21 of the directive and apply to both classes of entity alike.
The benchmark is proportionality: what is required is the state of the art, measured against risk, company size and potential damage. There is no fixed product list.
| No. | Measure | What it covers | Email relevance |
|---|---|---|---|
| §30 Abs. 2Nr. 1 | Risk analysis and security policies | A documented analysis of the risks to your own information systems, and policies derived from it. | no direct link |
| §30 Abs. 2Nr. 2 | Incident handling | Detection, response, recovery and follow-up of incidents as a governed process. | direct |
| §30 Abs. 2Nr. 3 | Business continuity | Backup management, disaster recovery and crisis management. | indirect |
| §30 Abs. 2Nr. 4 | Supply chain security | Assessment and contractual assurance of direct suppliers and service providers. | direct |
| §30 Abs. 2Nr. 5 | Security in acquisition, development and maintenance | Security requirements across the system lifecycle, including vulnerability management. | no direct link |
| §30 Abs. 2Nr. 6 | Assessing effectiveness | Procedures that verify whether the measures taken actually work. | indirect |
| §30 Abs. 2Nr. 7 | Cyber hygiene and training | Basic security practices and regular training for all staff. | indirect |
| §30 Abs. 2Nr. 8 | Cryptography and encryption | Policies and procedures for the use of cryptography, including key management. | direct |
| §30 Abs. 2Nr. 9 | Personnel security and access control | Personnel screening, least-privilege access and asset management. | no direct link |
| §30 Abs. 2Nr. 10 | Multi-factor and secured communications | Multi-factor or continuous authentication, secured voice, video and text communications, emergency communications. | direct |
Four of the ten measures bear directly on email
Encryption, incident handling, supply chain communication and secured text communication are hard to evidence without a mail gateway. What that looks like in practice is on the NIS2 email security page.
Deadlines, reports, fines
Alongside the measures under Section 30 sit three formal duties that apply regardless of your IT setup.
Registration with the BSI
Affected entities must register with the BSI within three months of coming into scope, providing contact details, sector and the services concerned. The BSI sends no request: the duty to check whether you are in scope rests with the company.
Reporting security incidents
An incident is significant if it causes severe operational disruption or financial loss, or is capable of harming other natural or legal persons. Reporting has three stages:
- 1Within 24 hours: an initial report with what is known.
- 2Within 72 hours: confirmation or update with an initial assessment.
- 3Within one month: a final report with cause, impact and measures taken.
Duties of the management body
Under Section 38 BSIG the management body must approve the risk management measures and oversee their implementation. It is required to attend training regularly and is personally liable for breaches. Any waiver of that liability is void.
Fines
Essential entities: up to EUR 10m or 2 % of worldwide annual turnover, whichever is higher. Important entities: up to EUR 7m or 1.4 %. Breaches of reporting and registration duties carry their own, lower ranges.
NIS2 and KRITIS
Both sit in the same act and are still routinely confused. KRITIS refers to operators of critical installations: entities exceeding a threshold in the BSI Criticality Regulation whose failure would endanger public supply. They are a subset of essential entities and additionally face evidence obligations every three years and mandatory attack detection systems.
NIS2 is the wider term. A company can be in scope of NIS2 without being a KRITIS operator; conversely, everything that applies under NIS2 applies to KRITIS operators too, and more. The separate KRITIS umbrella act governs physical resilience and is not part of the BSIG.
| Aspect | NIS2 | KRITIS |
|---|---|---|
| Trigger | Sector and company size | Threshold in the BSI Criticality Regulation |
| Scale in Germany | around 29,500 entities | a few hundred installation operators |
| Evidence | on request by the supervisor | mandatory every three years |
| Attack detection | part of proportionality | explicitly required |
All NIS2 topics
What this page summarises is set out in full elsewhere. Thirteen pages, sorted by question.
Fundamentals and liability
- NIS2 and email security: the complete guideThe 30-page primer: scope, measures, deadlines, pitfalls.
- Which email obligations now applyWhat the directive requires of the mail channel, paragraph by paragraph.
- Executive liability under Section 38 BSIGWhy management is personally liable and how to document compliance.
The measures in detail
- Section 30 BSIG: the ten mandatory measuresEvery measure explained individually, with its link to email.
- Is email encryption mandatory?What no. 8 requires, where TLS suffices and where S/MIME or PGP are needed.
- Reporting a security incidentThe 24-hour deadline in practice: who reports what, and to whom.
- Supply chain security under no. 4How requirements are passed to suppliers and evidenced.
- The email contingency planBusiness continuity for the mail channel: outage, recovery, fallback.
- Logging and SIEM integrationWhat supervisors want to see and how email events get there.
Implementation with Conbool
- NIS2 and email securityThe four email-relevant measures and how Conbool covers them.
- NIS2 encryptionS/MIME and PGP automated, with key management and policy rules.
- NIS2 business continuityAn emergency mailbox and continued operation when the mail server fails.
- NIS2 training obligationCyber hygiene and training under no. 7, documented and evidenced.
Frequently asked questions about NIS2
What is the difference between NIS2, the implementation act and the BSIG?+
NIS2 is the European directive and does not apply to companies directly. The NIS2 Implementation Act is the German amending act that transposes it by rewriting the BSI Act. The duties that actually apply are therefore in the BSIG, notably Sections 28, 30, 32 to 35 and 38.
Since when has NIS2 applied in Germany?+
Since 6 December 2025. The NIS2 Implementation Act grants no transition period for the measures under Section 30 BSIG: the duties have applied since it entered into force. Registration with the BSI has its own deadline of three months from coming into scope.
What is the difference between an essential and an important entity?+
The classification follows from sector and size. Essential entities are large companies in sectors of high criticality, important entities all other affected companies. The measures under Section 30 BSIG are identical; they differ in supervision, which is ongoing for essential entities, and in the maximum fine of EUR 10m against EUR 7m.
Do I have to fully investigate an incident within 24 hours?+
No. The 24-hour deadline applies to an initial report reflecting what is known at that point, including an assessment of whether an unlawful attack is involved. The assessment follows within 72 hours, the investigation with the final report within one month.
Is ISO 27001 certification enough for NIS2?+
It helps but does not suffice automatically. ISO 27001 covers much of Section 30(2) BSIG, but does not address the reporting and registration duties or the personal responsibility of the management body under Section 38 BSIG. An existing management system shortens the work; it does not replace checking each duty.
Is my company in scope as a supplier?+
Not for that reason alone. Scope follows from meeting the sector and size criteria yourself. Affected customers do, however, pass their requirements down contractually under Section 30(2) no. 4 BSIG, so suppliers end up having to evidence the measures without falling under BSI supervision themselves.
Cover the email requirements
Four of the ten measures under Section 30 BSIG bear directly on email. Conbool covers them with encryption, threat detection, a secure message portal and complete audit logs, hosted in Germany.
This page summarises the state of the legislation in plain language and does not constitute legal advice. The statutory text as amended from time to time prevails.