NIS2 Implementation Act

The NIS2 Regulation is more than just another piece of legislation—it marks a significant shift in the cybersecurity landscape that affects businesses across the EU. With stricter requirements and expanded reporting obligations, many companies are now required to comprehensively secure their IT infrastructure. But what does this mean specifically for your business? And how can you prepare for the new requirements? Translated with DeepL.com (free version) Act to Implement the NIS 2 Directive and to Regulate Fundamental Aspects of Information Security Management in the Federal Administration (hereinafter: NIS2UmsuCG-E) transposes Directive (EU) 2022/2555 into national law and simultaneously reforms key provisions of the BSI Act. For practical purposes, this means a significant expansion of obligations for companies and stronger enforceability of state supervision.

Starting situation and objectives

The NIS 2 Directive aims to ensure a high level of cybersecurity across Europe. The background to this is growing threats such as ransomware, supply chain attacks, hacktivism, and state-sponsored cyber operations, which are no longer limited to critical infrastructure in the narrower sense. According to Bitkom, cyberattacks caused damage of around 266.6 billion euros in Germany alone in 2024. This dimension illustrates that information security is no longer solely a technical challenge but an integral part of corporate and administrative security.

Lawmakers face the task of addressing this threat landscape through binding minimum standards and clear reporting obligations. At the same time, the Federal Office for Information Security (BSI) is to be granted expanded supervisory powers so that it can act not only in an advisory capacity but also with strong enforcement capabilities.

Extended scope of application

One of the central changes compared to the IT Security Act 2.0 is the significant expansion of the material and personal scope. While previously primarily operators of critical infrastructures (§ 2 Para. 10 BSIG a. F.) were covered, the NIS2UmsuCG-E introduces the categories of „especially important entities“ and „important entities“ (§ 28 BSIG-E). The classification is based on sector affiliation, company size, and importance for supply security. In addition to energy and water suppliers, transport and health services, this also covers companies in waste management, digital service providers, and selected manufacturing companies.

It is particularly relevant that the classification does not necessarily presuppose an immediate KRITIS characteristic. Companies without an exposed public utility function can also fall within the scope of application if they are classified as relevant for overall resilience due to their size or sector.

Risk Management and Security Measures

The law obliges affected entities to implement comprehensive risk management (§ 30 BSIG-E). The catalog of minimum security measures anchored in Art. 21 (2) NIS-2 is adopted into national law almost verbatim. These include, in particular, conducting regular risk analyses, implementing backup and recovery strategies, encrypting sensitive data, and ensuring the physical and logical security of network and information systems. It is remarkable that the legislator has explicitly provided for a proportionality clause. The intensity of the measures to be implemented should be based on the classification as „important“ or „especially important.“ Nevertheless, it is clear from the justification for the law that a purely formal minimum standard is not sufficient: the measures must be effective and adapted to the specific threat situation. This opens up scope for action on the one hand, but on the other hand requires continuous review and adaptation of the security architecture.

Reporting obligations and information exchange

Another core change is the three-stage reporting procedures (§ 32 BSIG-E), which replaces the previous one-time notification. In the future, security incidents must be reported within 24 hours in an initial report, within 72 hours in an interim report, and at the latest after one month in a final report. The reporting requirement covers not only actual significant security incidents, but also so-called „near misses“ that would have had significant potential consequences.

The BSI will be expanded into a central reporting office and will also receive the competence to coordinate information exchange between affected companies, authorities, and selected third parties (§ 6 BSIG-E). In practice, this means that companies will have to implement clear internal processes and escalation levels to meet the strict deadlines.

Management Responsibility

A particularly practical innovation is found in Section 38 of the BSIG bill: The management of the affected entities are personally obligated to ensure the implementation and compliance with the security requirements. This includes not only the provision of the necessary resources but also active monitoring of implementation and the training of relevant managers. Violations can lead to personal liability, especially if it can be proven that no adequate organizational measures were taken.

From a corporate perspective, this means that cybersecurity must be anchored as a component of corporate governance. Compliance management systems should explicitly include an information security compliance module to meet the requirements.

Sanctions mechanisms

The provisions on administrative fines (Section 65 BSIG-E) are based on the GDPR in terms of their amounts: For particularly important organizations, fines of up to 10 million euros or 2% of global annual turnover may be imposed; for important organizations, fines of up to 7 million euros or 1.4% of turnover may be imposed. These sanctions are to be understood cumulatively with any fines under the GDPR, provided that a security incident also constitutes a data breach within the meaning of Article 4(12) of the GDPR.

In practice, this results in a considerable financial risk that goes beyond purely technical security aspects and also affects strategic decisions—for example, the question of whether individual business areas should be restructured due to disproportionate compliance costs.

Outlook and Recommended Action

The law is currently planned to come into effect in December 2025 or January 2026. Given the breadth of the sectors affected and the complexity of the obligations, the remaining period is tight. Companies should immediately examine whether they fall within the scope of application and, on this basis, conduct a gap analysis. This involves evaluating not only the technical security architecture but also the organizational framework – from management responsibility and internal reporting lines to contractual relationships with service providers.

From a legal perspective, the NIS2UmsuCG-E represents a paradigm shift: information security becomes a legally enforceable organizational obligation with clear liability consequences. Those who take this obligation seriously can not only avoid sanctions but also significantly increase their own resilience against an increasingly complex threat landscape.

Get in touch