An Edge Built on Knowledge and Experience
ISO 27001 OT Security RED Directive RCE Directive TISAX CADIS
In force since 6 December 2025

NIS2 Directive Germany – act now.

The German NIS2UmsuCG applies with no transition period. Around 29,500 companies across 18 sectors are directly affected. Managing directors are personally liable.

29,500
Companies Affected
€10 M
Max. Fine
18
Regulated Sectors
Am I Subject to NIS2?
Quick check in 30 seconds — free & no registration
German BSI Act (NIS2UmsuCG) in force since Dec. 2025
✓ Based on official BSI sources
✓ Regularly updated – as of June 2026
✓ Reviewed by CONSUVATION experts
What Is NIS2? — Quick Answer

The NIS2 Directive (EU 2022/2555) is the revised EU cybersecurity directive. In Germany, it came into force on 6 December 2025 as the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) — with no transition period.

It obligates companies in 18 defined sectors to implement risk management, report cyberattacks to the BSI, and register. Managing directors and board members are personally liable and cannot delegate this responsibility. The EU Directive and the German implementation act are available for download at the bottom of the page.

The 5 Core Provisions

Which Obligations Apply to Your Company?

NIS2 compliance chain: applicability under section 28 BSIG, risk management under section 30, reporting obligation under section 32, management liability under section 38, fine under section 65
§ 28 BSIG

NIS2 Applicability

Defines which companies qualify as an "important" or "especially important" entity. Sector, number of employees and turnover are decisive.

§ 30 BSIG

Risk Management

Technical and organisational cybersecurity measures. At least 10 areas must be addressed, including access controls, encryption, and backup management.

§ 32 BSIG

Reporting Obligations

Significant security incidents must be reported to the BSI: initial notification within 24 hours, follow-up notification within 72 hours.

§ 38 BSIG

Management Liability

Executive management must approve risk management measures and can be held personally liable for violations. Cannot be delegated.

€10 million
maximum fine (§ 65 BSIG)
or 2% of worldwide annual turnover
Timeline & Deadlines

What Applies When — The NIS2 Timeline

January 2023
EU NIS2 Directive Enters Into Force done
Directive (EU) 2022/2555 officially entered into force. Member states had until October 2024 to transpose it into national law.
6 December 2025
NIS2UmsuCG Applies in Germany done
The NIS2 Implementation Act entered into force with no transition period. All obligations apply immediately to around 29,500 companies.
6 March 2026
BSI Registration Deadline Passed overdue
The deadline for registering with the BSI has passed. Affected companies without registration risk immediate fines — register now if you haven't already.
Ongoing
Reporting Obligations & Risk Management Active
Significant security incidents must be reported within 24 hours. ISMS build-out and risk management must be implemented now.
From 2028
First Compliance Reviews by the BSI
Especially important entities may be actively reviewed for compliance by the BSI. Documentation should be built up starting now.
18 Sectors

Which Industries Are Affected?

Especially important entity (Annex 1) — from 250 employees or €50M turnover
Important entity (Annex 2) — from 50 employees or €10M turnover
Energy
Electricity, gas, oil, heating, hydrogen
Transport
Air, rail, water, road
Banking & Financial Markets
Credit institutions, trading venues
Health
Hospitals, laboratories, pharmaceutical manufacturers
Drinking Water & Wastewater
Supply & disposal
Digital Infrastructure
Cloud, DNS, IXP, TLD, CDN
IT Services
Managed services (MSP, MSSP)
Public Administration
Federal and state authorities
Space
Operators of ground infrastructure
Postal & Courier Services
Parcel and letter delivery
Waste Management
Disposal, recycling
Chemicals
Manufacture & distribution of hazardous substances
Food
Wholesale, processing, production
Manufacturing
Medical devices, electronics, machinery
Digital Services
Online marketplaces, search engines
Research
Research institutions

In summary, the two entity categories break down as follows:

NIS2 sectors Germany: overview of especially important and important entities

Key difference: Especially important entities are subject to proactive BSI supervision (reviews at any time without a specific trigger, evidence obligation every 3 years) — important entities are subject only to reactive supervision (the BSI generally only becomes active after an incident or a report).

Beyond Germany

NIS2 Implementation Across Europe

NIS2 implementation across Europe by country, maturity as of January 2026

The NIS2 Directive applies across the EU, but national implementation varies significantly: while Germany is among the countries with fully completed implementation, other member states are still in the legislative process or at the start of it.

Important for internationally active companies: NIS2 can also affect companies that are not based in the EU but deliver services or products into the European market. What matters is not the company's registered location, but whether services are provided to EU customers and whether the company falls into one of the 18 regulated sectors. Affected companies outside the EU must appoint an EU representative and meet the NIS2 requirements.

Implementation Checklist

What Do Affected Companies Need to Implement?

Organisational Measures

📋Complete BSI registration (deadline: 6 March 2026 — overdue)
🏛️Build an ISMS (information security management system)
📜Document risk analysis and security policies
👤Train executive management in cybersecurity (§ 38 BSIG)
🤝Review supply chain security (suppliers & service providers)
📞Implement a reporting process for security incidents

Technical Measures (§ 30 BSIG)

🔐Set up access control and identity management
🔒Encryption for data at rest and in transit
💾Backup management and business continuity plan
🔍Vulnerability management and patch processes
🛡️Network security: segmentation and monitoring
🧪Security testing and penetration testing (regular)
Frequently Asked Questions

NIS2: Frequently Asked Questions

Generally no. The minimum size for "important entities" is 50 employees or €10 million in annual turnover. Exceptions apply to companies of particular critical importance (e.g. certain telecom providers, qualified trust service providers, DNS and TLD providers) — these fall under NIS2 regardless of size.
The registration deadline expired on 6 March 2026. Unregistered companies must register immediately and risk fines. The BSI can impose sanctions for violations. Contact the BSI registration portal directly and complete the registration without delay.
Experience shows ISO 27001 covers 70–80% of NIS2 requirements. Specific NIS2 requirements remain, in particular BSI registration, the concrete reporting obligation for incidents (24h/72h deadline), the training and liability rules for executive management (§ 38 BSIG), and supply chain security.
For significant security incidents, a two-stage reporting obligation applies: an initial notification (early warning) within 24 hours of becoming aware of the incident, and a follow-up notification (complete report) within 72 hours. A final report must be submitted no later than one month.
Yes. § 38 BSIG obligates executive management to approve and oversee the risk management measures. This duty cannot be delegated. In the event of violations, fines can be imposed personally on executive management. In extreme cases, the BSI can apply for the temporary removal of management personnel.
Yes. What matters is not the company's registered location, but whether services are provided within the EU. Companies based outside the EU that offer services to EU citizens or businesses and fall into one of the 18 sectors must appoint an EU representative and meet the NIS2 requirements.
CONSUVATION Products

Our NIS2 Solutions for Your Company

From analysis to full implementation — CONSUVATION guides you along the entire path to NIS2 compliance.

NIS2 ISMS icon shield
Management System

NIS2 ISMS

Turnkey information security management system, fully tailored to the NIS2 requirements under § 30 BSIG. Includes all documents, processes and evidence.

Learn More →
NIS2 handbook icon documentation
Documentation

NIS2 Handbook

A practical guide to NIS2 implementation — presented clearly for executive management and IT staff. With concrete action guidance, checklists and template documents.

Download Now →
NIS2 training icon team
Training

NIS2 Training

Tailored training for executive management (§ 38 BSIG obligation), IT teams and employees. In person or online — certified and demonstrable for BSI audits.

Request Training →
Our Tool

Our NIS2 Application: Your Central Platform for Implementation

Instead of scattered Word and Excel files, we provide you with a dedicated application for NIS2 implementation. It brings together all policies, work instructions, documents and risk analyses in one place — including its own employee portal with the policies, processes, work resources and training relevant to each individual.

Policies
All NIS2-relevant policies stored centrally, version-controlled and assigned to the respective risk management areas under § 30 BSIG.
Work Instructions
Concrete work instructions for practical implementation in day-to-day operations – not just theory.
Document Management
Central management of all evidence documents – version-controlled, traceable and always audit-ready.
Risk Analysis
Structured risk analysis per area as the basis for prioritised action planning.
Employee Portal
Role-based access for all employees to the policies, processes, work resources and training relevant to them.
Our Expertise

Experienced Experts — No Junior Consultants

CONSUVATION works exclusively with experienced senior consultants. With over 25 years of experience in information security, we are among the pioneers of the industry — our experts were among the first certified auditors for BS 7799, the British standard considered the direct precursor of today's ISO 27001.

Our consultants combine this unique founding knowledge with current practical experience in ISO 27001, TISAX and CADIS — as consultants, certified auditors and active ISO working group members for the ISO 27001 standard.

This insider knowledge, built up over more than two decades, feeds directly into your NIS2 implementation — for maximum security and standards compliance.

Meet Our Experts →
ISO 27001
Consultants, auditors & ISO working group members — deep, first-hand standards knowledge
TISAX
Many years of experience in the automotive industry — VDA ISA, assessment & certification
CADIS
Specialised know-how in data security & compliance — proven in practice
CISA · CISM · CRISC · CGEIT
Our consultants hold the most renowned international ISACA certifications — from IT audit (CISA) and security management (CISM) to risk management (CRISC) and IT governance (CGEIT).
25+
Years of Experience
BS 7799
First auditors of the ISO precursor standard
ISO
Working Group Members
100%
Senior Consultants
NIS2 Topic World

All NIS2 Topics In Depth

Foundation & Framework
Organisation & Documentation
Operations & Incident Management
Liability & Sanctions

Ready to Become NIS2 Compliant?

Download our free NIS2 implementation checklist or get advice from an expert.

Download Checklist Free (PDF) Request a Consultation
BSI News