NIS2
NIS2 (Directive (EU) 2022/2555) sets cybersecurity duties for essential and important entities in 18 sectors. Scope, ten measures, reporting deadlines, German law.
Updated This page as Markdown
In short
NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It obliges essential and important entities in 18 sectors (energy, transport, health, digital infrastructure, manufacturing and others) to implement the risk-management measures of Article 21, to report significant incidents within 24 and 72 hours (Article 23) and makes management personally responsible (Article 20). Germany transposed it with the NIS2UmsuCG, in force since 6 December 2025.
What is NIS2?
NIS2 is the EU directive on a high common level of cybersecurity, Directive (EU) 2022/2555. It replaced the first NIS Directive of 2016, widened the scope from a few hundred critical operators to tens of thousands of companies, and gave the duties teeth: minimum security measures, strict incident reporting, personal responsibility of management and fines in the range of the GDPR. As a directive it binds the member states, who transpose it into national law; companies are bound by that national law.
Who is in scope follows from sector and size (Article 2 and Annexes I and II). Annex I lists eleven sectors of high criticality, among them energy, transport, banking, health, drinking water, digital infrastructure and public administration. Annex II lists seven other critical sectors, including postal services, waste, chemicals, food, manufacturing of machinery, vehicles, electronics and medical devices, digital providers and research. In these sectors, medium-sized companies (50 employees or 10 million euro turnover and up) are in. Large companies in Annex I sectors are essential entities, the rest are important entities.
Where is it defined?
The directive is on EUR-Lex. The key articles: Article 20 (governance: the management body approves the measures, oversees them, is liable for breaches and must attend training), Article 21 (risk-management measures, with ten mandatory areas in paragraph 2: policies and risk analysis, incident handling, business continuity, supply chain security, secure acquisition and development including vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, HR security and access control, multi-factor authentication and secure communications), Article 23 (reporting of significant incidents: early warning within 24 hours, incident notification within 72 hours, final report within a month) and Article 34 (fines of up to 10 million euro or 2 percent of worldwide turnover for essential entities, 7 million euro or 1.4 percent for important ones).
Germany transposed NIS2 with the NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), which rewrote the BSI Act (BSIG) and has applied since 6 December 2025. German law speaks of “besonders wichtige” and “wichtige Einrichtungen”; the BSI estimates around 29,000 affected companies, which had to register with the BSI within three months.
What it means in practice
NIS2 does not tell you which firewall to buy. It asks for a risk-based, documented and tested security programme and for proof that it works. What that means for the companies we work with:
- Find out if you are in scope, in writing. Many manufacturers are surprised: an electronics or machine builder with 60 employees is an important entity under Annex II.
- Article 21(2)(f) is where testing comes in. “Policies and procedures to assess the effectiveness” means regular penetration tests, scans and audits, with results tracked to closure.
- Supply chain security (Article 21(2)(d)) reaches your products. Essential entities push security requirements, questionnaires and test reports down to their suppliers. If you sell into energy, health or transport, expect them.
- 24 hours is short. The early warning needs a process that works at night: who decides, who reports, what the template says. A managed SOC such as Zyberdome gives you detection and a prepared workflow for exactly that.
Common misunderstandings
NIS2 is not a product regulation; that is the Cyber Resilience Act. It does not require a certification, and Zyberum does not certify against it; ISO 27001 or IT-Grundschutz can serve as evidence but are not mandated. And it is not only for KRITIS: KRITIS operators remain a stricter subset, but the majority of entities newly in scope have never been regulated before.
FAQ
Frequently asked questions
How do I know whether my company falls under NIS2?
Check sector and size. If your main activity is in one of the sectors of Annex I or II and you have at least 50 employees or more than 10 million euro in annual turnover and balance sheet total, you are in scope (Article 2(1)), with exceptions for some providers regardless of size. The BSI offers a self-check, and our NIS2 check does the same in a short conversation.
What are the reporting deadlines under NIS2?
For a significant incident: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours with an initial assessment, and a final report within one month (Article 23(4)). The authority may request intermediate updates. In Germany the reports go to the BSI.
Does NIS2 require a penetration test?
Not by name. Article 21(2)(f) requires policies and procedures to assess the effectiveness of your security measures, and Article 21(2)(e) requires vulnerability handling. Regular penetration tests and scans are the standard way to meet both and the evidence auditors ask for.
Sources
Related pages
- GlossaryCyber Resilience Act (CRA)The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements. Scope, duties, classes, 2026 and 2027 deadlines.
- GlossaryKRITISKRITIS means critical infrastructures: facilities in Germany whose failure would cause supply shortages. Who counts, what the BSIG requires and what changed with NIS2.
- ComparisonsNIS2 vs Cyber Resilience Act: Which One Applies to You, and What Each DemandsNIS2 regulates operators of essential services; the CRA regulates products with digital elements. Who falls under which, duties, deadlines and penalties side by side.
- InsightsNIS2 in Germany: Who Is Affected and What to Do NowThe German NIS2 law has applied since 6 December 2025. A practical checklist: scope, registration, the ten risk measures, reporting deadlines and first steps.
- InsightsThe Ten NIS2 Measures of Article 21(2), ExplainedNIS2 Article 21(2) lists ten risk management measures every affected entity must implement. What each one means, how they map to German law, and where to start.
- ServicesNIS2 without the paper mountain.NIS2 applies in Germany since December 2025. Find out if you are affected and implement risk management, incident reporting and testing with hands-on experts.
