The NIS-2 Implementation Act has come into force – are you affected?

The NIS-2 Implementation Act has been in force since 6 December 2025 and sets new standards for cyber and information security in Germany. Under the Act, binding legal obligations now apply to a significantly larger number of organisations. For the first time, around 30,000 organisations are required to implement comprehensive technical and organisational security measures to protect their networks and information systems.

From risk management systems and attack detection to strict reporting requirements – these requirements are designed to ensure a consistent and appropriate level of security across the EU.

Make proactive use of the new NIS 2 requirements – not only to meet your compliance obligations, but also to strengthen your cyber security in the long term.

Companies in the spotlight: risks in cyberspace

Every day, sensitive information is exchanged that is exposed to risks in cyberspace. Whether they are small and medium-sized enterprises or global corporations, every company is a potential target for cybercriminals.

The NIS 2 Implementation Act: How to improve your cyber security with GKK

The entry into force of the Act marks the start of a new phase in cybersecurity regulation in Germany: it provides greater legal certainty, whilst at the same time increasing the responsibilities of company management and extending information security obligations to a large number of small and medium-sized enterprises.

Failure to comply with the prescribed measures may not only result in substantial fines for the company, but may also lead to personal liability claims against the management.

Our chartered accountants and certified IT specialists at GKK IT-Consulting can assist you with a NIS 2 impact assessment and the subsequent implementation of the statutory NIS 2 requirements.

NIS-2 Implementation Act comes into force

How to improve your IT security with GKK!

Click here for the GKK NIS-2 initial consultation

Which companies are affected?

Which sectors are affected?
Appendix 1: Sectors comprising critical and important facilitiesAppendix 2: Sectors comprising important facilities
EnergyTransport and traffic (postal and courier services sub-sector)
Transport and trafficWaste management
FinanceProduction, manufacture and trade in chemical substances
HealthProduction, processing and distribution of food
Water (including wastewater)Manufacturing industry / manufacture of goods
Digital infrastructureDigital service providers
SpaceResearch

 

What size of businesses are affected?
  • Particularly important organisation: an organisation that falls under a category listed in Annex 1

     

    • at least 250 employees or
    • annual turnover > €50 million and annual balance sheet total > €43 million

     

  • Important organisation: an organisation that falls under a category listed in Annex 1 or 2

     

    • At least 50 employees or
    • Annual turnover > €10 million and annual balance sheet total > €10 million

     

  • Operators of critical facilities (previously ‘critical infrastructure’): Thresholds to be determined by statutory order (as before)

     

    • are, in principle, also particularly important organisations
       

       

 

What are the requirements?

The Act on the Federal Office for Information Security and on Information Security in Organisations, as amended (BSIG, as amended), stipulates:

Risk management measures for particularly important facilities and important facilities (Section 30)

Implementation of a suitable, state-of-the-art risk management system

Obligation to register (Section 33)

Compulsory registration with the Federal Office for Information Security (BSI)

Reporting obligations (Section 32)

Reporting security incidents to the Federal Office

Duties to provide information (Section 35)

In the event of significant security incidents, the Federal Office may order that the recipients of its services be informed

Obligations regarding implementation, monitoring and training for the management of particularly important institutions and important institutions (Section 38)

Implementation of the risk management measures to be taken in accordance with Section 30, as well as the implementation of appropriate governance processes to ensure compliance with and monitoring of the measures taken.

Regular participation in training by senior management to acquire sufficient knowledge and skills to identify and assess risks and risk management practices in the field of information technology security, and to be able to assess their impact on the services provided by the organisation.

What we offer

Impact analysis

We analyse your business areas and business units against the complex, defined criteria of the BSIG (as amended). In doing so, we take into account not only potential immediate applicability but also IT security-related due diligence requirements, which increasingly arise from business relationships with regulated clients and may become contractually relevant. We summarise the results clearly in a management letter, thereby providing an appropriate basis for decision-making.

GAP analysis

In the event that your organisation is affected, we will carry out a NIS-2 GAP analysis to assess how well your organisation is already prepared to meet the specified requirements and what steps are still needed to fully comply with the legal requirements.

NIS-2 Governance & Implementation of Measures

We support you in the efficient management and coordination of NIS 2 measures, so that your organisation can meet the requirements quickly and effectively. In doing so, we assist you in the successful implementation and documentation of the required measures.

Reporting

We design a reporting process to the supervisory authority that is tailored to your needs and integrate it into your existing incident and crisis management processes.

Pfeil

Workshops & Training Courses

We offer training courses and workshops on cyber security, tailored to your specific needs, to ensure that you and your team are as well prepared as possible to face the challenges you currently face.

[Translate to English:] Vorteile von NIS-2

Your benefits at a glance

Compliance with the statutory NIS-2 requirements

Compliance with the statutory NIS 2 requirements protects your organisation from legal risks.

Protection of sensitive data and information assets

Protect your business from unauthorised access and misuse.

Vermeidung von finanziellen Schäden

Avoid financial losses by proactively minimising the risks posed by cyber attacks, data loss and business interruptions.

Competitive advantage and building customer trust

Gain a competitive edge through proven high security standards and build your customers’ trust by ensuring reliable protection of sensitive data.

Implementation of a sustainable level of cyber security

Take your business to a level of cyber security that ensures long-term protection against digital threats and strengthens your organisation’s resilience.

Avoiding directors’ and officers’ liability

Implementing the NIS 2 requirements can reduce the liability risk for management.

FAQ

FAQ on cyber security

What is the NIS-2 Directive all about?

The NIS-2 Directive (Directive (EU) 2022/2555) was introduced by the European Union to ensure a high common level of cybersecurity within the EU (at national level). It replaces the previous NIS Directive (Directive (EU) 2016/1148) and takes account of the increased requirements resulting from growing digitalisation and mounting threats from the cyber domain. Member States are obliged to transpose the provisions of the NIS-2 Directive into national law. In Germany, this is done through the ‘Act Implementing the NIS 2 Directive and Regulating the Essential Principles of Information Security Management in the Federal Administration’ (NIS 2 Implementation Act), which came into force on 6 December 2025.

Which companies are affected by this?

The NIS 2 Implementation Act applies to organisations classified as ‘particularly important entities’ and ‘important entities’, as well as operators of critical infrastructure (KRITIS). The organisations and entities affected are defined on the basis of specific criteria and thresholds. The NIS 2 Implementation Act is primarily aimed at medium-sized and large organisations in critical and legally defined sectors. These organisations must significantly improve their cybersecurity measures and meet stricter requirements.

Does the current legislation provide for any transitional periods?

The NIS 2 Implementation Act does not provide for a general transition period.

Affected organisations must, in principle, fulfil their obligations from the date the Act comes into force, for example registration, risk management and reporting obligations.

However, specific deadlines apply to registration with the BSI:

Under the BSIG, particularly important and important organisations, as well as providers of domain name registry services, are obliged to submit certain information to the BSI via the BSI portal. This must be done no later than three months after a company is first or again classified as such an organisation or begins offering the relevant services.

The same applies to companies that fall into one of the categories of organisations specified in Section 60(1), first sentence, of the BSIG, e.g. providers of cloud computing services, providers of data centre services, providers of online marketplaces and online search engines.

How can you check whether your business is affected?

An initial assessment can be carried out using the BSI Scope Assessment Tool. However, this does not provide a definitive assessment of NIS 2 compliance. Our GKK IT Consulting team can assist you in carrying out a NIS 2 compliance analysis tailored to the specific characteristics of your organisation.

What requirements must be met if my company is affected by the NIS-2 Implementation Act?

Depending on the specific organisation, appropriate technical and organisational measures (state of the art) must be implemented, for example in the form of a risk management system. In addition, affected organisations are subject to registration and reporting obligations towards the Federal Office for Information Security.

Overview of key requirements:

  • Stricter cybersecurity requirements: Organisations must implement comprehensive measures and requirements to protect their networks, IT systems and data. These include establishing a cyber risk management framework, contingency plans and incident response processes.
  • Reporting obligations: In future, security incidents must be reported to the Federal Office for Information Security (BSI) in several stages. This includes an initial report, an interim report, a progress report where applicable, and a final report, each within the statutory time limits. In addition, the BSI may request evidence and reports relating to IT security. Affected companies should therefore continuously document the technical and organisational measures they have implemented and be able to submit them to the competent authority upon request.
  • Liability risks: Breaches of duty may result in both fines being imposed on the company and personal liability claims against the management. In particularly serious cases, and depending on the type of institution, fines of up to 10 million euros or 2 per cent of global annual turnover may be imposed.
  • The management of affected organisations is obliged to implement the risk management measures required under Section 30 of the BSIG (as amended) and to monitor their implementation. Furthermore, there is an obligation to attend regular information security training sessions in order to acquire the knowledge necessary to fulfil their duties. Employees should also attend regular awareness training sessions in accordance with the new regulation.
Is proof required if a company does not fall within the scope of the NIS-2 regulations?

Under Sections 61 and 62 of the BSIG (as amended), organisations may be required, at the request of the BSI, to demonstrate that they comply with the NIS-2 requirements applicable to them. The NIS-2 impact assessment provides an initial starting point for providing this evidence quickly and transparently. We would be happy to assist you with this.

What penalties can companies expect if they fail to implement the NIS 2 requirements, or do not implement them in full?

Organisations that fail to fulfil their obligations under the NIS-2 Implementation Act face significant penalties. These may include both financial fines and other legal and organisational consequences:

1. Financial fines

Critical infrastructure operators: Fines of up to EUR 10 million or, where total turnover (within the meaning of Section 65(8) of the BSIG, as amended) exceeds EUR 500 million, up to 2 per cent of the previous year’s global annual turnover.

Important organisations: Fines of up to EUR 7 million or, where total turnover (within the meaning of Section 65(8) of the BSIG, as amended) exceeds EUR 500 million, up to 1.4 per cent of the previous year’s global turnover.

2. Liability of senior management (Section 38 of the BSIG, as amended)

The management is obliged to implement the risk management measures to be taken under Section 30 and to monitor their implementation.

Management bodies that breach their duties are liable to their organisation for any damage caused through fault in accordance with the rules of company law applicable to the organisation’s legal form. Under this Act (BSIG, as amended), they are liable only if the provisions of company law applicable to the institution do not contain a liability provision in accordance with the first sentence.

3. Possible additional consequences

Damage to image and reputation: Security incidents or failure to comply with legal requirements can undermine the trust of customers and partners.

You might also be interested in:

Everything you need to know about our IT consultancy services.

GKK IT-Consulting

Protect your business from liability risks and cyber attacks.

Further services in the field of IT compliance and security

Build trust with customers, auditors and regulatory authorities.

Certificates & Attestations

We showcase practical and successful case studies.

Case Studies
CAREER
Scroll down Scroll down