NIS-2 FAQ.

39 practical questions on the NIS-2 Directive and the German NIS2UmsuCG: scope, obligations, registration, sanctions, supply-chain impact, and edge cases. Written for operators and management.

01. Basics

What NIS-2 is, where it comes from, and how it relates to the previous regime.

What is the NIS-2 Directive?

NIS-2 is EU Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It replaces the original NIS Directive of 2016 and substantially broadens the scope of mandatory cybersecurity requirements, incident-reporting obligations, and supervision.

The directive entered into force on 16 January 2023. Member states were required to transpose it into national law by 17 October 2024. Germany missed this deadline by more than a year.

What is the German NIS2UmsuCG?

The NIS-2-Umsetzungs- und Cybersicherheitsstaerkungsgesetz (NIS2UmsuCG) is the German implementation law for NIS-2. It overhauls the BSI Act (BSIG) and creates two new categories of regulated entities, replacing the previous KRITIS-only scope.

Key dates: passed by the Bundestag on 13 November 2025, approved by the Bundesrat on 20 November 2025, published in the Bundesgesetzblatt on 5 December 2025, in force from 6 December 2025. There is no transition period.

How is NIS-2 different from NIS-1 and the previous IT-Sicherheitsgesetz?

Three differences matter most:

  • Scope. NIS-1 covered roughly 2,000 KRITIS operators in Germany. NIS-2 covers approximately 29,500 entities across 18 sectors.
  • Self-classification. Under NIS-2, companies must determine themselves whether they fall within scope. There is no notification from the authority.
  • Personal management liability. The new BSIG holds the management body personally accountable for compliance, including approval and supervision of the risk-management measures.
Why is the EU regulating cybersecurity at this depth?

The Commission justified NIS-2 with three structural arguments: the dramatic increase in attack volume and sophistication since 2016, the high level of cross-border dependency in critical sectors, and the inconsistent transposition of NIS-1 across member states. NIS-2 raises the floor and harmonises minimum measures, reporting timelines, and supervisory powers.

Is NIS-2 a regulation or a directive?

NIS-2 is a directive, not a regulation. It binds member states to a result but leaves the form and method of implementation to national law. This is why each country has its own implementation act (in Germany: NIS2UmsuCG; in Austria: NISG 2024; in the Netherlands: Cyberbeveiligingswet). The substance is similar, the details vary.

02. Who is affected

Sector, size, and self-classification logic. The single most common source of NIS-2 mistakes.

Which companies are affected by NIS-2 in Germany?

An entity is in scope if it operates in one of 18 listed sectors and exceeds size thresholds. The new BSIG distinguishes two categories:

  • Essential entities (besonders wichtige Einrichtungen, "bwE"): entities in 11 sectors of high criticality, generally with at least 250 employees, or more than EUR 50M annual revenue and more than EUR 43M balance sheet total.
  • Important entities (wichtige Einrichtungen, "wE"): entities in additional critical sectors, generally with at least 50 employees, or more than EUR 10M annual revenue and more than EUR 10M balance sheet total.

Some entity types are in scope regardless of size (e.g. providers of public electronic communications networks, trust service providers, top-level domain name registries, certain entities of the central government).

What does "essential entity" (besonders wichtige Einrichtung) mean?

An essential entity operates in one of the sectors of high criticality defined in Annex I of NIS-2: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration, and space.

Essential entities are subject to proactive supervision by the BSI: regular audits, targeted inspections, and on-site verifications. Penalties can reach EUR 10 million or 2 percent of global annual revenue, whichever is higher.

What does "important entity" (wichtige Einrichtung) mean?

An important entity operates in one of the other critical sectors defined in Annex II of NIS-2: postal and courier services, waste management, manufacture, production and distribution of chemicals, production, processing and distribution of food, manufacturing (machinery, motor vehicles, electronic equipment, medical devices), digital providers (search engines, social platforms, online marketplaces), and research.

Important entities are subject to reactive supervision: the BSI may investigate when there is evidence of non-compliance. Penalties can reach EUR 7 million or 1.4 percent of global annual revenue, whichever is higher.

Which sectors are covered?

The 18 sectors are split between Annex I (essential) and Annex II (important):

Annex I sectors (essential entities): Energy (electricity, district heating and cooling, oil, gas, hydrogen), Transport (air, rail, water, road), Banking, Financial market infrastructures, Health (providers, EU reference labs, research and manufacturing of medicinal products, manufacture of medical devices considered critical during a public health emergency), Drinking water, Waste water, Digital infrastructure (IXP, DNS, TLD, cloud, data centres, CDN, trust services, electronic communications), ICT service management (managed services, managed security services), Public administration (central and regional level), Space.

Annex II sectors (important entities): Postal and courier services, Waste management, Manufacture, production and distribution of chemicals, Production, processing and distribution of food, Manufacturing (medical devices, computer/electronic/optical products, electrical equipment, machinery, motor vehicles, other transport equipment), Digital providers (online marketplaces, online search engines, social networking services platforms), Research organisations.

How do I check whether my company is in scope?

Use the BSI Betroffenheitspruefung at betroffenheitspruefung.bsi.bund.de as the official tool. The check asks for sector, size criteria, and corporate structure, and outputs a binding classification.

The IHK also provides decision trees. Independent counsel is recommended for edge cases, in particular for entities with multiple business lines or complex group structures.

What about subsidiaries and corporate groups?

NIS-2 applies at the level of the legal entity, not the group. Each subsidiary must be assessed independently against the size and sector criteria. A holding company may itself be out of scope while subsidiaries are in scope, or vice versa.

However, the size thresholds are applied with reference to the EU SME definition (Commission Recommendation 2003/361/EC), which considers linked and partner enterprises. A small subsidiary of a large group is treated as a large company for size-threshold purposes.

Does NIS-2 apply to non-EU companies?

Yes, in two cases:

  • If the entity offers services in the EU, even without an EU establishment. In this case, the entity must designate a representative established in one of the member states where it offers services.
  • If the entity has an EU establishment, the establishment itself falls under the law of the member state where it is located.

For certain digital infrastructure entities (DNS providers, TLD registries, cloud computing services, data centres, CDNs, online marketplaces, online search engines, social networking platforms), the rules on main establishment determine jurisdiction.

I am not directly in scope. Can I still be affected?

Yes, almost certainly, via the supply-chain obligations of your customers. Essential and important entities must assess and manage cybersecurity risks across their supply chain, including the relationships with direct suppliers and service providers.

In practice this means: if any of your B2B customers is in NIS-2 scope, expect to receive supplier questionnaires, contractual security requirements, audit clauses, and incident-notification obligations passed through to you. This indirect effect reaches deep into the Mittelstand.

03. Registration and deadlines

Self-registration with the BSI, MUK process, and what happens if you missed the deadline.

By when did I have to register with the BSI?

The BSI registration portal opened on 6 January 2026. The deadline for affected entities to register was 6 March 2026. As of June 2026, that deadline has passed.

For entities that become subject to NIS-2 after this date (for example, because they cross a size threshold or enter a covered sector), the registration must occur within three months of becoming in scope.

How does BSI registration work in practice?

Two-step process:

  1. Step 1: Mein Unternehmenskonto (MUK). Create an organisation account at mein-unternehmenskonto.de. This is the federal government's central digital ID for businesses and is reused across many e-government services.
  2. Step 2: BSI portal. Log in to the BSI portal with the MUK identity and complete the NIS-2 registration form: legal entity, sector classification (bwE or wE), establishment data, contact points for incidents.

The registration confirms the entity to the BSI and triggers the operational obligations: incident reporting via the portal, possible audit invitations, and the ability to receive BSI threat intelligence.

What happens if I missed the registration deadline?

Missing the registration is itself a violation of the BSIG. Penalties for failure to register fall under the general fine regime: up to EUR 10 million or 2 percent of global revenue for essential entities, up to EUR 7 million or 1.4 percent for important entities. Personal management liability also applies.

Practical recommendation: register as soon as possible. Late registration does not retroactively avoid the violation, but it limits exposure and signals good-faith effort, which the BSI is likely to consider in any enforcement action.

Will the BSI inform me whether I am in scope?

No. NIS-2 is built on mandatory self-classification. The BSI does not maintain a list of in-scope entities and does not send notifications. The burden is entirely on the company to assess its own status, register, and comply.

The BSI can, however, issue an order that confirms an entity's in-scope status if the BSI becomes aware of non-compliance with the registration obligation.

04. Technical and organisational measures

Article 21 of NIS-2 and Sections 30 to 31 of the new BSIG translate cybersecurity into ten concrete obligation areas.

What technical and organisational measures must I implement?

Article 21(2) NIS-2 lists ten obligation areas, transposed verbatim into Section 30 of the new BSIG. All ten must be addressed by both essential and important entities, applying the "state of the art" and risk-based proportionality:

  1. Policies on risk analysis and information system security.
  2. Incident handling.
  3. Business continuity, such as backup management, disaster recovery, and crisis management.
  4. Supply-chain security, including security-related aspects of relationships with direct suppliers and service providers.
  5. Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure.
  6. Policies and procedures to assess the effectiveness of cybersecurity risk-management measures.
  7. Basic cyber hygiene practices and cybersecurity training.
  8. Policies and procedures regarding the use of cryptography and, where appropriate, encryption.
  9. Human resources security, access control policies, and asset management.
  10. The use of multi-factor authentication or continuous authentication solutions, secured voice/video/text communications, and secured emergency communication systems.
Do I need an ISMS certified to ISO/IEC 27001?

No, not as a legal obligation. The BSIG does not require a specific framework or certification. However, an operational ISMS is the most efficient way to demonstrate compliance with the ten measure areas.

In practice, three frameworks are commonly used:

  • ISO/IEC 27001 (with Annex A controls). The international reference. Certification is voluntary, but the documentation it produces maps cleanly to Section 30 BSIG.
  • BSI IT-Grundschutz. The German federal baseline. Particularly common in public-sector adjacent entities. Heavier documentation overhead than ISO 27001 but with explicit alignment to BSI expectations.
  • NIST Cybersecurity Framework 2.0. Less common in Germany but used in multinational contexts.

Cortavion view: for a Mittelstand entity newly in scope, a slim ISO 27001-aligned ISMS is usually the fastest path to defensible compliance.

What role does BSI IT-Grundschutz play?

IT-Grundschutz is the BSI's own catalogue of cybersecurity controls, organised into modules (Bausteine) by topic. It is not mandatory for NIS-2 compliance, but it is the reference the BSI itself uses, which makes it influential in supervisory discussions.

For most non-public-sector entities, a leaner ISO 27001 implementation is more efficient. IT-Grundschutz remains the natural choice for federal entities, state-level agencies, and operators with strong public-sector ties.

What supply-chain obligations apply?

Affected entities must take into account, when implementing supply-chain security measures:

  • The specific vulnerabilities of each direct supplier and service provider.
  • The overall quality of products and the cybersecurity practices of suppliers and providers, including secure development procedures.
  • The results of coordinated risk assessments of critical supply chains carried out at EU level.

This translates to operational practices: supplier questionnaires, contractual security clauses, right to audit, incident-notification clauses, and ongoing monitoring of supplier security posture. Cortavion observation: most NIS-2 entities are underestimating the effort required here.

Do I need to appoint a designated security officer (CISO)?

The BSIG does not mandate a specific role title. However, it requires the management body to approve and supervise the risk-management measures. In practice, this responsibility is almost always delegated operationally to a CISO, information security officer (ISO), or IT security officer (ITSB).

The function does not have to be a full-time internal role. Many Mittelstand entities use an external CISO-as-a-service arrangement. What matters is that the role is clearly defined, has adequate authority, and reports to management at appropriate cadence.

What training and awareness obligations apply?

Two distinct obligations:

  • Management training. The management body of essential and important entities must follow training on cybersecurity, and is encouraged to offer similar training to staff on a regular basis. This is binding for management and is often the most overlooked NIS-2 requirement.
  • Staff cyber hygiene. Basic cyber hygiene practices and cybersecurity training are one of the ten measure areas of Section 30 BSIG. Implementation typically includes annual mandatory training, phishing simulations, and onboarding modules.
What does "state of the art" mean in practice?

"State of the art" (Stand der Technik) is a moving target. The BSI explicitly references it in Section 30 BSIG and applies it through a combination of:

  • Established baselines such as ISO 27001, IT-Grundschutz, and CIS Critical Security Controls.
  • Sector-specific guidance (energy, finance, health each have additional references).
  • BSI publications on specific topics (e.g. cloud security, supply-chain security).

The TeleTrust Verband publishes an annual "Stand der Technik" handbook that is widely used in Germany as a practical reference.

What must I document, and how long do I have to keep the records?

The BSIG does not prescribe a specific retention period. As a defensive baseline, retain:

  • At least 7 years: ISMS documentation, risk assessments, audit reports, management approvals of the cybersecurity strategy, incident records, supplier security assessments.
  • At least 3 years: security training records, access reviews, vulnerability scan results, change records.
  • Indefinitely: records of regulatory submissions to the BSI (registrations, incident notifications, audit findings).

Alignment with the GoBD retention rules for tax-relevant records can simplify the documentation architecture.

05. Incident reporting

The three-step timeline (24h, 72h, one month) and what counts as a reportable incident.

When must I report a security incident?

You must report a "significant" cybersecurity incident. The reporting follows a three-step timeline starting from the moment of knowledge of the incident:

  1. Within 24 hours: an early warning indicating whether the incident is suspected to be caused by malicious acts or could have a cross-border impact.
  2. Within 72 hours: an incident notification, including an initial assessment of the incident, its severity, impact, and (where available) indicators of compromise.
  3. Within one month: a final report describing the incident in detail, the type of threat, the applied mitigation measures, and any cross-border impact.

Interim status reports may be requested by the BSI at any time during the incident handling.

What is a "significant" incident under NIS-2?

An incident is "significant" if it meets at least one of two criteria from Article 23(3) NIS-2:

  • It has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned.
  • It has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.

The EU has issued an implementing regulation (Commission Implementing Regulation (EU) 2024/2690) with quantitative thresholds for specific sectors. For non-listed sectors, the assessment is qualitative.

To whom must I report incidents?

The BSI is the central single point of contact. Reports are submitted through the BSI portal that opened on 6 January 2026 (the same portal used for registration).

Depending on the incident type, parallel reporting obligations may apply: BfV (in cases of suspected state-sponsored activity), the data protection authorities (in case of a personal data breach under GDPR), the BaFin (for financial entities), and customers/users in some sectors. Cortavion recommendation: prepare a single incident-reporting playbook that explicitly maps each obligation to a named owner.

Must I notify my customers of significant incidents?

In some cases, yes. The BSI may instruct the entity to inform users whose services may be affected by a significant cyber threat or incident. Additionally, for some sectors (electronic communications, trust services, digital infrastructure providers), direct user notification obligations may be triggered automatically.

Independent of NIS-2, contractual obligations to customers may also trigger notification duties. Review supplier agreements for incident-notification clauses.

06. Management liability and sanctions

Personal accountability for management, fine ranges, and what the BSI can do in enforcement.

Is management personally liable under NIS-2?

Yes. Section 38 of the new BSIG holds the management body of essential and important entities personally accountable for the approval and supervision of the implementation of cybersecurity risk-management measures.

This means:

  • Management must approve the cybersecurity risk-management measures in a formal, documented way.
  • Management must oversee their implementation.
  • Management must follow mandatory cybersecurity training.
  • If risk-management measures are not adequate and an incident causes damage, members of management can be held personally liable to the entity for breach of their duty of care.
What are the maximum penalties?

For essential entities: administrative fines of up to EUR 10 million or 2 percent of the total worldwide annual turnover of the preceding financial year, whichever is higher.

For important entities: administrative fines of up to EUR 7 million or 1.4 percent of total worldwide annual turnover, whichever is higher.

These maximums apply to violations of the core risk-management measures (Section 30 BSIG) and the reporting obligations. Lesser violations (administrative offences) are subject to lower thresholds.

What enforcement powers does the BSI have?

The BSI can:

  • Order on-site inspections and audits, with the right to compel access to premises, systems, and records.
  • Order ad-hoc security audits by an independent third party.
  • Order disclosure of risk-assessment results and supporting evidence.
  • Issue binding instructions to remedy deficiencies within a set time frame.
  • For essential entities only: temporarily suspend a person from exercising managerial functions, or temporarily prohibit the entity from providing its services, if other measures have been exhausted.

The last two powers (managerial suspension and service prohibition) are unprecedented in German cyber regulation and signal a significant escalation.

How does NIS-2 affect D&O insurance?

The personal liability regime under Section 38 BSIG materially increases D&O exposure. Practical implications:

  • Insurers are tightening underwriting for entities in NIS-2 scope. Expect cybersecurity questionnaires, exclusion clauses for non-compliance, and possible premium increases.
  • Existing D&O policies should be reviewed for the precise coverage of regulatory fines, defence costs, and shareholder derivative claims linked to cybersecurity failures.
  • Management is well advised to ensure that the formal approval of risk-management measures is documented through board resolutions, with version control. This documentation is the primary defence in any future claim.

Cortavion observation: this is not a legal-counsel topic to defer. The window between "incident" and "claim" is narrow.

07. Implementation in practice

Where to start, typical costs, common pitfalls, audit cadence.

Where should I start if I am newly in scope?

A pragmatic sequencing, starting from zero:

  1. Week 1-2: Confirm scope. Run the BSI Betroffenheitspruefung. Document the result.
  2. Week 3-4: Register with the BSI (if you have not). Designate the contact points for incidents.
  3. Month 2: Gap assessment. Map your current security controls against Section 30 BSIG. A consultant-led gap assessment typically takes 3-4 weeks for a mid-sized entity.
  4. Month 3-4: Quick wins. Close the most exploitable gaps first: MFA, EDR, backup verification, asset inventory, basic incident-response playbook.
  5. Month 4-9: ISMS build-out. Stand up the formal information security management system. Document policies, run a first risk assessment, brief management.
  6. Month 6+: Supply chain. Roll out supplier security assessments and contractual updates. This is a 12-18 month effort even for medium-sized supplier bases.

Quick-win-first is critical. Most entities new to NIS-2 underestimate the runway and over-invest in documentation before they have the operational controls in place.

What does NIS-2 compliance typically cost?

Highly dependent on starting point and complexity. Rough ranges for a mid-market entity (200-500 employees, mid-tech-maturity, single-jurisdiction):

  • Year 1 setup: EUR 80,000 to 350,000 (consulting, tooling, training, registration). Highly variable.
  • Annual run-rate: EUR 60,000 to 200,000 (managed services, ongoing audits, tooling licences, internal CISO function).

Drivers of higher cost: heterogeneous IT landscape, large supplier base, multiple legal entities, regulated sectors with additional sectoral requirements (e.g. health, energy).

Drivers of lower cost: cloud-first architecture, existing ISO 27001, focused supplier base, single legal entity.

Fines for non-compliance start above this range, so the ROI calculation is usually straightforward.

What are the most common mistakes companies make?
  • Waiting for the BSI to notify them. The BSI does not notify. You must self-classify.
  • Treating NIS-2 as an IT project. The personal liability provisions make it a board-level matter. Without management ownership, the project stalls.
  • Buying tools before defining processes. Tools without processes generate audit findings rather than reducing risk.
  • Ignoring the supply chain. Supplier security is one of the ten obligation areas, but it is usually pushed to year 2 or 3. Customers in scope start asking questions in year 1.
  • Under-documenting management approval. The formal board approval of the cybersecurity strategy is the most important single piece of paper. Many entities have the substance but not the formal resolution.
  • Confusing certification with compliance. ISO 27001 certification helps but does not equal NIS-2 compliance. The two scopes overlap but are not identical.
How often must I re-audit or provide evidence?

The BSIG does not prescribe a specific audit frequency. In practice:

  • Essential entities (bwE): expect proactive BSI supervision. The BSI may schedule audits, request evidence packs, or conduct on-site inspections. Plan for an internal full review at least annually.
  • Important entities (wE): reactive supervision. Audits are typically triggered by incident reports or third-party complaints. Annual internal reviews are still the operational baseline.
  • If certified to ISO 27001: the standard's own surveillance audits (annual) and recertification (every three years) define the audit cadence.

Independent of formal audits, entities should run an internal management review of the ISMS at least annually, with documented findings and follow-up actions.

Can I outsource NIS-2 compliance to a managed service provider?

You can outsource implementation, monitoring, and operations. You cannot outsource the legal accountability. The management body remains responsible regardless of which functions are delegated.

That said, an MSP or managed SOC can deliver most of the operational substance: detection, response, vulnerability management, supplier monitoring, evidence collection, and audit support. The internal function then becomes one of governance, oversight, and supplier-management of the MSP.

If you go this route, the MSP contract must include: explicit cybersecurity scope, audit rights, incident notification commitments, sub-processor disclosure, exit support, and clear allocation of responsibilities for each of the ten measure areas of Section 30 BSIG.

08. Adjacent regulation and outlook

How NIS-2 sits next to DORA, the Cyber Resilience Act, the KRITIS-Dachgesetz, and where the regulation is heading next.

How does NIS-2 relate to DORA?

DORA (Regulation (EU) 2022/2554, Digital Operational Resilience Act) is the financial-sector-specific cybersecurity regulation. It applies to banks, insurers, investment firms, and their critical ICT third-party providers. Where DORA applies, it generally takes precedence over NIS-2 as lex specialis for the financial sector.

In practice: a bank is in scope of NIS-2 (as an essential entity in the banking sector) but follows DORA's more detailed regime for its core obligations. The two are designed to be compatible, but the operational implementation is sector-specific.

How does NIS-2 relate to the EU Cyber Resilience Act (CRA)?

The Cyber Resilience Act (Regulation (EU) 2024/2847) is a product-focused regulation: it applies to products with digital elements placed on the EU market. NIS-2 is an entity-focused regulation: it applies to the operations of entities in specific sectors.

The two interact at the supply-chain level. NIS-2 entities must consider the cybersecurity of products they use; the CRA improves the baseline security of those products. For a manufacturer of digital products, both regulations may apply: the CRA to the products, NIS-2 to the company's own operations.

What is the KRITIS-Dachgesetz and how is it different?

The KRITIS-Dachgesetz (Kritis-Dachgesetz) is a separate German law, in force since 17 March 2026. It implements the EU CER Directive (Critical Entities Resilience, (EU) 2022/2557), which focuses on physical and operational resilience of critical infrastructure, complementing NIS-2's focus on cybersecurity.

An entity can be subject to both: NIS-2 covers the cyber dimension, the KRITIS-Dachgesetz covers physical security, business continuity for non-cyber events, and resilience against natural disasters and physical attacks. Most KRITIS entities are also NIS-2 essential entities.

What changes might come at the EU level (CSA2 and beyond)?

In early 2026 the European Commission opened consultations on a potential "Cyber Security Act 2" (CSA2) and on adjustments to NIS-2 itself, including:

  • Refinement of size thresholds and sector definitions to reduce ambiguous cases.
  • Possible easing of obligations for the smallest entities currently in scope.
  • Harmonisation of incident-reporting timelines across NIS-2, DORA, and GDPR.
  • Expansion of EU-wide certification schemes (continuation of the existing EUCC and EUCS).

None of this is law yet. Realistic timeline for any binding amendment: not before 2027. Until then, the rules described in this FAQ apply.

This FAQ is provided for general information. It is not legal, compliance, or audit advice. It does not replace a formal NIS-2 readiness assessment, independent legal counsel, or supervisory guidance from the BSI. Cortavion accepts no liability for decisions based on this content. Where this FAQ describes regulatory thresholds or deadlines, the legally binding sources are the cited directives, regulations, and the German Bundesgesetzblatt.