Skip to content
Zyberum Cyber Security Firm
Menu
NIS2Compliance

NIS2 in Germany: Who Is Affected and What to Do Now

The German NIS2 law has applied since 6 December 2025. A practical checklist: scope, registration, the ten risk measures, reporting deadlines and first steps.

Zyberum Security Team · Published · 7 min read

Germany was late with NIS2, and then it came all at once: the NIS2 Implementation Act has applied since 6 December 2025, without a transition period. Around 29,000 companies are in scope, most of them for the first time.

If you are not sure where you stand, this is the short version.

Step 1: Are you in scope?

Two questions decide it.

Sector. NIS2 lists 18 sectors. Besides the classic critical infrastructure (energy, transport, health, water, banking, digital infrastructure) it includes many that did not expect it: manufacturing of machinery, vehicles, electronics and medical devices, chemicals, food, waste management, postal and courier services, and IT service management.

Size.

Category Threshold
Important entity From 50 employees, or more than €10 million in both turnover and balance sheet total
Especially important entity From 250 employees, or more than €50 million turnover and more than €43 million balance sheet total

Some entities are covered regardless of size. And nobody will tell you: companies have to assess this themselves.

Step 2: Register

Affected companies had to register with the Federal Office for Information Security (BSI) by 6 March 2026. If you are in scope and have not registered, do it now.

Step 3: The ten measures

The law requires risk management in ten areas. In plain language:

  1. Risk analysis and security policies. Know what you have and what can go wrong.
  2. Incident handling. Detect, contain and recover.
  3. Business continuity. Backups that work, and a plan for a crisis.
  4. Supply chain security. Know how secure your suppliers and service providers are.
  5. Secure acquisition, development and maintenance. Including how you handle vulnerabilities.
  6. Effectiveness checks. Test whether your measures actually work.
  7. Cyber hygiene and training. For everyone, including management.
  8. Cryptography. Encrypt where it matters.
  9. Access control and asset management. Who may do what, and on which systems.
  10. Multi-factor authentication and secure communication. Also for emergencies.

The measures have to be appropriate to your risk and your size. A 60-person manufacturer does not need the programme of a bank. It does need to be able to explain its choices.

Step 4: Be able to report within 24 hours

For significant incidents the clock is tight:

  • 24 hours: early warning to the BSI
  • 72 hours: incident notification with a first assessment
  • One month: final report

You can only meet this if someone notices the incident in the first place. That means monitoring, a clear internal escalation path and people who know what to do at three in the morning.

Step 5: Management

Management has to approve the measures, oversee them and take part in training. It cannot delegate the responsibility away, and it can be held personally liable.

What it costs to ignore it

Fines go up to €10 million or 2% of worldwide turnover for especially important entities, and up to €7 million or 1.4% for important entities.

Where to start, practically

Our advice after the first projects:

  • Do not start with documents. Start with the things that stop real attacks: multi-factor authentication, tested backups, patching, monitoring.
  • Test it. A penetration test shows quickly where the gaps are, and gives you the effectiveness evidence the law asks for.
  • Write down what you do. Short and true beats long and copied.

We help with the scope check, the gap analysis, the implementation and the testing. See NIS2 compliance or book a free NIS2 check.

FAQ

Frequently asked questions

Is there a transition period for NIS2 in Germany?

No. The NIS2 Implementation Act has applied since 6 December 2025 without a transition period. The only deadline in the law was the registration with the BSI, which had to be done within three months.

Who checks whether a company is affected?

The company itself. There is no notification from the authorities. You have to assess your sector and size, and register with the BSI if you are in scope.

What should we do first?

Clarify whether you are in scope, register if you are, and then run a gap analysis against the ten required measures. Start with incident detection and reporting, backups and access control, because that is where real damage is prevented.

Call usBook a call

Pick a time that suits you

Open in a new tab