Skip to content
Zyberum Cyber Security Firm
Menu

NIS2 compliance

NIS2 without the paper mountain.

Germany’s NIS2 law has applied since 6 December 2025, with no transition period. Around 29,000 companies are in scope, and management is personally responsible. We check if you are affected, close the real gaps first and give you the evidence to prove it.

  • In force since 6 Dec 2025
  • Measures that actually protect
  • Pentest as proof

In short

NIS2 is the EU directive on cybersecurity for essential and important entities. Germany implemented it with the NIS2 Implementation Act, in force since 6 December 2025. It applies to companies in 18 sectors with at least 50 employees or more than €10 million in turnover and balance sheet total, requires risk-management measures, registration with the BSI and incident reporting within 24 hours, and makes management liable. Zyberum offers NIS2 applicability checks, gap analyses, implementation of the required measures, penetration tests and 24/7 monitoring.

Who is affected

Probably more companies than you think

NIS2 covers 18 sectors, including energy, transport, healthcare, water, digital infrastructure, IT service management, manufacturing (machinery, vehicles, electronics, medical devices), chemicals, food, waste and postal services.

As a rule, you are in scope if you work in one of these sectors and have at least 50 employees, or more than €10 million in both annual turnover and balance sheet total. Some entities are covered regardless of size. Suppliers feel it too, because affected customers must secure their supply chain.

Timeline

Where NIS2 stands in Germany

  1. EU deadline

    Member states had to transpose the NIS2 Directive into national law by this date.

  2. German law in force

    The NIS2 Implementation Act applies without a transition period. The obligations are binding.

  3. BSI registration

    Affected companies had three months to register with the Federal Office for Information Security (BSI).

  4. Measures and evidence

    Risk management must be implemented and documented. Management has to approve it, oversee it and get trained.

What the law requires

The obligations, in plain language

Risk management

Ten areas of measures, from risk analysis and incident handling to backups, supply chain security, cryptography and access control.

Incident reporting

Early warning within 24 hours, incident notification within 72 hours and a final report within one month.

Management duty

Management must approve and oversee the measures, attend training, and can be held personally liable.

Registration

Affected companies register themselves with the BSI. Nobody will tell you that you are in scope.

Supply chain

You must assess the security of your suppliers and service providers, and your customers will assess yours.

Proof of effectiveness

Measures must be reviewed for effectiveness. Audits and penetration tests are the way to show it.

How we help

From "are we affected?" to "we can prove it"

Applicability check

We determine whether you are in scope, in which category, and what that means for you.

Gap analysis

Your current security against the required measures, prioritised by real risk, not by chapter number.

Implementation

We put the missing measures in place with your team: incident process, backups, access control, supplier checks.

Penetration test

We attack your systems to show whether the measures hold, and you get evidence for the effectiveness review.

Penetration testing

24/7 monitoring

Zyberdome detects and handles incidents around the clock, so the 24-hour reporting deadline is realistic.

Zyberdome

Management training

The training that NIS2 requires for management, hands-on and in plain language.

Training

FAQ

NIS2 FAQ

Is my company affected by NIS2?

You are probably affected if you operate in one of the 18 NIS2 sectors and have at least 50 employees, or more than €10 million in both annual turnover and balance sheet total. Some entities, such as certain digital infrastructure providers, are covered regardless of size. Companies must assess this themselves.

Since when does NIS2 apply in Germany?

The German NIS2 Implementation Act entered into force on 6 December 2025 and applies without a transition period. The deadline for registering with the BSI was 6 March 2026.

What are the penalties?

Up to €10 million or 2% of worldwide annual turnover for especially important entities, and up to €7 million or 1.4% for important entities. In addition, management can be held personally liable for failing to implement the measures.

We are not in scope. Do we still need to act?

Often yes. Companies in scope must secure their supply chain, so they pass security requirements on to suppliers and service providers through contracts and questionnaires.

Does ISO 27001 certification cover NIS2?

It covers a large part of the risk-management measures, but not everything. Registration, the reporting deadlines and the management obligations come on top, and the scope of your ISO 27001 certificate must match the services that fall under NIS2.

Get started

Free NIS2 consultation: are you affected, and what is missing?

One hour with an expert. We check whether NIS2 applies to your company and where your biggest gaps are.

  • Clear answer: in scope or not, and in which category
  • Your biggest gaps against the ten required measures
  • A prioritised plan that starts with real risks
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usFree NIS2 consultation

Pick a time that suits you

Open in a new tab