The German NIS2UmsuCG applies with no transition period. Around 29,500 companies across 18 sectors are directly affected. Managing directors are personally liable.
The NIS2 Directive (EU 2022/2555) is the revised EU cybersecurity directive. In Germany, it came into force on 6 December 2025 as the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) — with no transition period.
It obligates companies in 18 defined sectors to implement risk management, report cyberattacks to the BSI, and register. Managing directors and board members are personally liable and cannot delegate this responsibility. The EU Directive and the German implementation act are available for download at the bottom of the page.
Defines which companies qualify as an "important" or "especially important" entity. Sector, number of employees and turnover are decisive.
Technical and organisational cybersecurity measures. At least 10 areas must be addressed, including access controls, encryption, and backup management.
Significant security incidents must be reported to the BSI: initial notification within 24 hours, follow-up notification within 72 hours.
Executive management must approve risk management measures and can be held personally liable for violations. Cannot be delegated.
In summary, the two entity categories break down as follows:
Key difference: Especially important entities are subject to proactive BSI supervision (reviews at any time without a specific trigger, evidence obligation every 3 years) — important entities are subject only to reactive supervision (the BSI generally only becomes active after an incident or a report).
The NIS2 Directive applies across the EU, but national implementation varies significantly: while Germany is among the countries with fully completed implementation, other member states are still in the legislative process or at the start of it.
Important for internationally active companies: NIS2 can also affect companies that are not based in the EU but deliver services or products into the European market. What matters is not the company's registered location, but whether services are provided to EU customers and whether the company falls into one of the 18 regulated sectors. Affected companies outside the EU must appoint an EU representative and meet the NIS2 requirements.
From analysis to full implementation — CONSUVATION guides you along the entire path to NIS2 compliance.
Turnkey information security management system, fully tailored to the NIS2 requirements under § 30 BSIG. Includes all documents, processes and evidence.
Learn More →A practical guide to NIS2 implementation — presented clearly for executive management and IT staff. With concrete action guidance, checklists and template documents.
Download Now →Tailored training for executive management (§ 38 BSIG obligation), IT teams and employees. In person or online — certified and demonstrable for BSI audits.
Request Training →Complete process model including all 10 risk management areas under § 30 BSIG. Ready-made policies, procedures and forms — immediately usable.
Request Now →Instead of scattered Word and Excel files, we provide you with a dedicated application for NIS2 implementation. It brings together all policies, work instructions, documents and risk analyses in one place — including its own employee portal with the policies, processes, work resources and training relevant to each individual.
CONSUVATION works exclusively with experienced senior consultants. With over 25 years of experience in information security, we are among the pioneers of the industry — our experts were among the first certified auditors for BS 7799, the British standard considered the direct precursor of today's ISO 27001.
Our consultants combine this unique founding knowledge with current practical experience in ISO 27001, TISAX and CADIS — as consultants, certified auditors and active ISO working group members for the ISO 27001 standard.
This insider knowledge, built up over more than two decades, feeds directly into your NIS2 implementation — for maximum security and standards compliance.
Meet Our Experts →Download our free NIS2 implementation checklist or get advice from an expert.