Skip to content

Häufig gestellte Fragen

What is the NIS-2 Directive?
NIS-2 is the second EU directive on network and information security (Directive (EU) 2022/2555) and replaces the original NIS Directive from 2016. It aims to establish a uniformly high level of cybersecurity across the entire European Union and obliges affected companies to implement risk management, reporting and governance measures. As a directive, it has no direct legal effect but must be transposed into national law by each member state. In Germany, this is done through the NIS-2 Implementation Act (NIS2UmsuCG), which anchors the requirements primarily in the amended BSI Act.
Which companies are affected by NIS-2?
NIS-2 covers organisations in 18 regulated sectors, including energy, transport, banking, health, drinking water, digital infrastructure, public administration, waste management, food and chemical production, and large parts of the manufacturing industry. Company size is generally the decisive factor: as a rule, entities with 50 or more employees or ten million euros in annual turnover are affected, and in certain sectors regardless of size. The directive distinguishes between particularly important and important entities, which differ mainly in the applicable thresholds and the intensity of government oversight. In Germany, an estimated 29,500 to 30,000 companies fall within the scope.
What specific obligations does NIS-2 impose?
At the core are technical and organisational risk management measures that must reflect the current state of the art and are listed in the directive as a minimum standard. These include risk analysis and security concepts, the handling of security incidents, business continuity with backup and crisis management, supply chain security, as well as cryptography, access control and multi-factor authentication. In addition, there are tiered reporting obligations towards the supervisory authority and training requirements. The directive also explicitly requires an active role for company management, which must approve the measures and monitor their implementation.
What penalties can a NIS-2 violation incur?
For particularly important entities, fines of up to 10 million euros or 2 percent of worldwide annual turnover are provided for, whichever amount is higher; for important entities the range is lower, at up to 7 million euros or 1.4 percent of worldwide annual turnover. At its upper end, the sanction level is thus comparable to the GDPR. Beyond fines, the supervisory authority can issue binding orders and, in serious cases, suspend activities or certifications. Added to this is the personal responsibility of company management, which can be held liable for compliance with the risk management obligations.
By when did NIS-2 have to be implemented, and does it already apply in Germany?
The EU deadline for transposing the directive into national law already expired on 17 October 2024. Germany missed this deadline by a wide margin; the NIS-2 Implementation Act (NIS2UmsuCG) was only passed in November 2025 and entered into force on 6 December 2025. The act does not provide for a general transition period for affected companies, meaning registration, reporting and risk management obligations apply immediately. Companies should therefore promptly check whether they fall within the scope and document their security measures accordingly.
What reporting deadlines apply in the event of a security incident?
NIS-2 provides for a three-stage reporting system for significant security incidents. First, an early warning must be submitted to the competent authority — in Germany the BSI — within 24 hours of becoming aware of the incident. A more detailed assessment of the incident follows within 72 hours, and a final report after one month at the latest. An incident is considered significant in particular if it causes severe operational disruptions or financial losses, or is capable of significantly affecting other natural or legal persons.
What does NIS-2 mean for operating an ERP system?
An ERP system bundles master, financial, logistics and HR data and is therefore often among a company's most sensitive applications, which is why many NIS-2 requirements directly affect its operation. In practical terms, this means a well-designed role concept based on the principle of least privilege, strong authentication via multi-factor procedures, and a complete audit trail that documents changes traceably. Since ERP systems communicate with upstream and third-party systems via numerous interfaces, securing these connections and having a defined patch and update process also fall under the required measures. If operation is outsourced to service providers or to the cloud, responsibility remains with the affected company.