Guide · IT security

NIS2: Does it even apply to us?

The German NIS2 Implementation Act (NIS2UmsuCG) came into force on 6 December 2025 – with no transition period. Instead of around 4,500 organisations as before, roughly 29,500 companies are now covered. So the first question is not what to do, but whether it applies to you at all.

By Dipl.-Ing. Mohamed Khater, Founder and Managing Director, since 1992 · · 7 min read

What has applied since December 2025

Germany transposed the EU directive late: the deadline expired in October 2024, the first draft bill fell with the collapse of the governing coalition, and the European Commission opened infringement proceedings. The NIS2 Implementation and Cybersecurity Strengthening Act was finally passed on 13 November 2025 and has been in force since 6 December 2025.

For companies, one detail is decisive: there is no transition period. Anyone covered was bound from day one. Registration with the BSI (German Federal Office for Information Security) was due within three months, i.e. by 6 March 2026, with an extended grace period until 31 July 2026. Both dates have now passed.

To give a sense of the scale: of around 29,500 companies covered, only about 11,500 had registered by the first deadline – just under four in ten. If you have done nothing so far, you are not alone, but that is no excuse.

How it works

Three questions determine your classification

Companies have to determine for themselves whether they are covered – no official notice will land on your desk. Check in this order.

  • Sector. Does your actual activity fall into one of the 18 sectors covered? What counts is what you do, not what is entered in the commercial register.
  • Size. From 50 employees or more than €10 million in turnover, a company in a covered sector counts as an important entity. From 250 employees or more than €50 million in turnover in a sector of high criticality, it counts as an essential entity, with stricter supervision.
  • Supply chain. Even if you do not reach the thresholds, you are rarely unaffected: under § 30 BSIG (German BSI Act), covered companies must secure their supply chain and pass the requirements on by contract.

Tool

Three-step applicability check

An initial assessment in under a minute. The evaluation runs in your browser – nothing is transmitted and nothing is stored.

1 In which sector does your company operate?

What counts is the actual activity, not the entry in the commercial register.

2 How large is your company?

Employees including part-time staff. Turnover and balance sheet total of the last completed financial year.

3 Do you supply companies that are themselves covered by NIS2?

For example energy suppliers, hospitals, banks, larger industrial companies or public bodies – as a supplier or as a service provider.

Result

Answer the three questions to get an initial assessment.

This check is for guidance only and is not legal advice. The classification depends on details no form can capture – such as subsidiaries, group structures or special rules for critical facilities. The BSI's own applicability check is the binding one.

If you are covered: what to do now

The obligations under § 30 BSIG are not a list to file away – you must be able to prove they have been implemented. This order has proven itself in practice.

  • Register with the BSI now. The deadline has passed; a late registration is still better than none.
  • Assign responsibility at management level. The law explicitly holds management accountable – delegating to IT does not release them.
  • Take stock of the risks. Which systems does the business depend on, what happens if they fail, where is the data?
  • Set up reporting channels. Significant security incidents must be reported within 24 hours. That cannot be improvised while the business is at a standstill.
  • Make backup and recovery verifiable. What counts is not the backup but the documented restore test.
  • Include your suppliers. Your service providers also become part of what you have to evidence – including whoever manages your IT.

Frequently asked questions

What we are often asked

We have 30 employees. Does NIS2 apply to us?

Directly, as a rule, no – the threshold is 50 employees or €10 million in turnover. Indirectly, however, it very much does if you supply or provide services to companies that are covered. In practice the requirement then comes not from the BSI but from your largest customer – as a questionnaire or a new contract clause.

What happens if we missed the registration?

The obligation to register continues. Fines are possible, but a late registration is always a better position than none at all. For a specific assessment of your case, legal advice is the right route – we are an IT service provider, not a law firm.

Is it enough if our IT service provider takes care of it?

No. Responsibility remains with management – the law says so explicitly. A service provider can implement and document the measures, but cannot take the obligation off your hands. We provide the technical implementation and the evidence; the decisions and the responsibility stay with you.

Does this also apply to medical practices and hospitals?

Health is one of the sectors of high criticality. But size remains decisive: a practice with eight employees does not reach the threshold; a hospital as a rule does. Independently of this, practices remain subject to the requirements of the German Social Code (Sozialgesetzbuch) and data protection law.

NIS2 does not apply to us. Can we tick it off?

Legally yes, in practice no. The NIS2 measures are not something lawmakers dreamt up; they are what makes a ransomware incident survivable: tested backups, separated permissions, an emergency plan and people who know whom to call. That is money well spent even without an obligation.

Dipl.-Ing. Mohamed Khater

Dipl.-Ing. Mohamed Khater founded INFONET Computer GmbH in Cologne in 1992 and still runs it as owner today. INFONET supports small and medium-sized businesses in the Rhineland with the technical implementation of these requirements – from the initial assessment to the documented restore test.

Further reading

Free security check

Where do you really stand?

In around 60 minutes we check your firewall, backups, endpoint protection, permissions and patch status – and tell you where your three biggest risks lie. Free of charge and without obligation.

+49 221 984300-0Switchboard and support hotline

[email protected]Reply within 4 hours on working days

Robert-Perthel-Straße 7250739 Köln – Bilderstöckchen

Mon–Fri 9 am–6 pmEmergency support outside these hours by arrangement