Reference

NIS2

NIS2 is the EU cybersecurity directive. In Germany it applies through the NIS2 Implementation Act, which writes the duties into the BSI Act. This page explains who is in scope, what Section 30 BSIG requires and which deadlines are running.

Last updated: 2 September 2026

What is NIS2?

NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It obliges companies in 18 sectors to manage risk, report security incidents and implement technical minimum measures. In Germany it has applied since 6 December 2025 through the NIS2 Implementation Act.

The spelling "NIS 2" with a space means the same thing. The name refers to the second version of the Network and Information Security Directive; it replaces the 2016 original and widens its scope considerably: instead of some 500 critical infrastructure operators, around 29,500 German companies now fall under it.

The real change is liability. NIS2 makes cybersecurity a management duty: the management body must approve the risk management measures, oversee their implementation and is personally liable under Section 38 BSIG. That duty cannot be delegated.

NIS2 in numbers

29,500
affected companies in Germany
18
sectors in scope
24 hrs
deadline for the initial incident report
EUR 10m
maximum fine, or 2 % of annual turnover

Directive, implementation act, BSIG

Three names, one body of rules. Knowing the chain is how you find the provision that actually applies.

  1. European level

    The NIS2 Directive

    Directive (EU) 2022/2555, in force since January 2023. A directive does not apply directly: it obliges member states to translate it into national law. For companies it is therefore an aid to interpretation, not a legal basis.

  2. National implementation

    The NIS2 Implementation Act

    The NIS2 Implementation and Cybersecurity Strengthening Act entered into force on 6 December 2025. It is an amending act: it contains few duties of its own and instead rewrites the BSI Act. Anyone looking for the statutory text is looking for the BSIG.

  3. Applicable law

    The BSIG

    The BSI Act carries the duties. Section 28 defines scope, Section 30 the risk management measures, Sections 32 to 35 reporting and registration, Section 38 the duties of the management body and Section 65 the fines. There is no transition period.

Who is in scope?

Two criteria must coincide: sector and size. Where both apply, NIS2 applies automatically, with no notice and no request.

Essential entities

250 or more employees, or turnover above EUR 50m and a balance sheet total above EUR 43m

In the sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space. These entities are subject to ongoing supervision by the BSI.

Fines up to EUR 10m or 2 % of worldwide annual turnover

Important entities

50 or more employees, or turnover and balance sheet total above EUR 10m

All remaining sectors as well as smaller entities in those listed above: postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research. Supervision is triggered by cause; the duties themselves are identical.

Fines up to EUR 7m or 1.4 % of worldwide annual turnover

Regardless of size

Operators of critical installations, qualified trust service providers, top-level domain registries, DNS providers and providers of public telecommunications networks fall under NIS2 irrespective of headcount or turnover.

What about suppliers?

Suppliers are not automatically in scope themselves, but they are bound contractually: Section 30(2) no. 4 requires affected companies to assess the security of their direct suppliers. In practice that means questionnaires, evidence and contract clauses passing the standard down the chain.

The 18 sectors

Sectors of high criticality first, then the other critical sectors.

  • Energy
  • Transport
  • Banking
  • Financial market infrastructure
  • Health
  • Drinking water
  • Waste water
  • Digital infrastructure
  • ICT service management
  • Public administration
  • Space
  • Postal and courier
  • Waste management
  • Chemicals
  • Food
  • Manufacturing
  • Digital providers
  • Research

The ten requirements under Section 30 BSIG

Section 30(2) BSIG lists ten measures every affected company must implement. They follow Article 21 of the directive and apply to both classes of entity alike.

The benchmark is proportionality: what is required is the state of the art, measured against risk, company size and potential damage. There is no fixed product list.

No.MeasureWhat it coversEmail relevance
§30 Abs. 2Nr. 1Risk analysis and security policiesA documented analysis of the risks to your own information systems, and policies derived from it.no direct link
§30 Abs. 2Nr. 2Incident handlingDetection, response, recovery and follow-up of incidents as a governed process.direct
§30 Abs. 2Nr. 3Business continuityBackup management, disaster recovery and crisis management.indirect
§30 Abs. 2Nr. 4Supply chain securityAssessment and contractual assurance of direct suppliers and service providers.direct
§30 Abs. 2Nr. 5Security in acquisition, development and maintenanceSecurity requirements across the system lifecycle, including vulnerability management.no direct link
§30 Abs. 2Nr. 6Assessing effectivenessProcedures that verify whether the measures taken actually work.indirect
§30 Abs. 2Nr. 7Cyber hygiene and trainingBasic security practices and regular training for all staff.indirect
§30 Abs. 2Nr. 8Cryptography and encryptionPolicies and procedures for the use of cryptography, including key management.direct
§30 Abs. 2Nr. 9Personnel security and access controlPersonnel screening, least-privilege access and asset management.no direct link
§30 Abs. 2Nr. 10Multi-factor and secured communicationsMulti-factor or continuous authentication, secured voice, video and text communications, emergency communications.direct

Four of the ten measures bear directly on email

Encryption, incident handling, supply chain communication and secured text communication are hard to evidence without a mail gateway. What that looks like in practice is on the NIS2 email security page.

NIS2 and email security

Deadlines, reports, fines

Alongside the measures under Section 30 sit three formal duties that apply regardless of your IT setup.

Registration with the BSI

Affected entities must register with the BSI within three months of coming into scope, providing contact details, sector and the services concerned. The BSI sends no request: the duty to check whether you are in scope rests with the company.

Reporting security incidents

An incident is significant if it causes severe operational disruption or financial loss, or is capable of harming other natural or legal persons. Reporting has three stages:

  1. 1Within 24 hours: an initial report with what is known.
  2. 2Within 72 hours: confirmation or update with an initial assessment.
  3. 3Within one month: a final report with cause, impact and measures taken.

Duties of the management body

Under Section 38 BSIG the management body must approve the risk management measures and oversee their implementation. It is required to attend training regularly and is personally liable for breaches. Any waiver of that liability is void.

Fines

Essential entities: up to EUR 10m or 2 % of worldwide annual turnover, whichever is higher. Important entities: up to EUR 7m or 1.4 %. Breaches of reporting and registration duties carry their own, lower ranges.

NIS2 and KRITIS

Both sit in the same act and are still routinely confused. KRITIS refers to operators of critical installations: entities exceeding a threshold in the BSI Criticality Regulation whose failure would endanger public supply. They are a subset of essential entities and additionally face evidence obligations every three years and mandatory attack detection systems.

NIS2 is the wider term. A company can be in scope of NIS2 without being a KRITIS operator; conversely, everything that applies under NIS2 applies to KRITIS operators too, and more. The separate KRITIS umbrella act governs physical resilience and is not part of the BSIG.

The difference in one line
AspectNIS2KRITIS
TriggerSector and company sizeThreshold in the BSI Criticality Regulation
Scale in Germanyaround 29,500 entitiesa few hundred installation operators
Evidenceon request by the supervisormandatory every three years
Attack detectionpart of proportionalityexplicitly required

Frequently asked questions about NIS2

What is the difference between NIS2, the implementation act and the BSIG?+

NIS2 is the European directive and does not apply to companies directly. The NIS2 Implementation Act is the German amending act that transposes it by rewriting the BSI Act. The duties that actually apply are therefore in the BSIG, notably Sections 28, 30, 32 to 35 and 38.

Since when has NIS2 applied in Germany?+

Since 6 December 2025. The NIS2 Implementation Act grants no transition period for the measures under Section 30 BSIG: the duties have applied since it entered into force. Registration with the BSI has its own deadline of three months from coming into scope.

What is the difference between an essential and an important entity?+

The classification follows from sector and size. Essential entities are large companies in sectors of high criticality, important entities all other affected companies. The measures under Section 30 BSIG are identical; they differ in supervision, which is ongoing for essential entities, and in the maximum fine of EUR 10m against EUR 7m.

Do I have to fully investigate an incident within 24 hours?+

No. The 24-hour deadline applies to an initial report reflecting what is known at that point, including an assessment of whether an unlawful attack is involved. The assessment follows within 72 hours, the investigation with the final report within one month.

Is ISO 27001 certification enough for NIS2?+

It helps but does not suffice automatically. ISO 27001 covers much of Section 30(2) BSIG, but does not address the reporting and registration duties or the personal responsibility of the management body under Section 38 BSIG. An existing management system shortens the work; it does not replace checking each duty.

Is my company in scope as a supplier?+

Not for that reason alone. Scope follows from meeting the sector and size criteria yourself. Affected customers do, however, pass their requirements down contractually under Section 30(2) no. 4 BSIG, so suppliers end up having to evidence the measures without falling under BSI supervision themselves.

Cover the email requirements

Four of the ten measures under Section 30 BSIG bear directly on email. Conbool covers them with encryption, threat detection, a secure message portal and complete audit logs, hosted in Germany.

This page summarises the state of the legislation in plain language and does not constitute legal advice. The statutory text as amended from time to time prevails.