Pandorex
Regulation & Law

NIS2 in the DACH Region: What Applies Now, Who Is Affected, and What Must Happen by October

Published Pandorex Redaktion·9 min read
—

NIS2 (Network and Information Security Directive 2) is the most comprehensive cybersecurity regulation the EU has ever adopted. Member states should have transposed it into national law by October 2024. Germany passed the NIS2 Implementation Act (NIS2UmsuCG) in December 2025, with a transition period until October 2026. Switzerland, as a non-EU state, is not directly affected but aligns with similar standards through the revised Information Security Act (ISG). Austria finalized the NIS2 transposition in March 2026.

Who Is Affected

NIS2 massively expands the scope compared to the predecessor directive NIS1. Companies in 18 sectors are affected, divided into "essential" and "important" entities:

Essential Entities: Energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management (B2B), public administration, space.

Important Entities: Postal services, waste, chemicals, food, manufacturing (certain sub-sectors), digital services (marketplaces, search engines, social media), research.

The threshold: companies with 50 or more employees OR 10 million EUR or more in annual revenue in the named sectors. In Germany, this affects an estimated 30,000 companies. Many of them mid-sized businesses that previously did not have to observe specific cybersecurity regulations.

What NIS2 Concretely Requires

The requirements are defined in Article 21 of the directive. For companies, this concretely means:

  • Risk analysis and security concept: Documented analysis of IT risks, with measures derived from it. Not as a one-time exercise but as an ongoing process.
  • Incident handling: Processes for detection, analysis, containment, and recovery from security incidents. Reporting obligation: initial notification within 24 hours to the competent authority (BSI in Germany), detailed report within 72 hours, final report within one month.
  • Business continuity: Backup management, disaster recovery, crisis management.
  • Supply chain security: Assessment of supplier and service provider security. Security requirements in contracts.
  • Vulnerability management: Systematic patch management, vulnerability scanning.
  • Cryptography: Encryption where appropriate.
  • Access control: Multi-factor authentication, least privilege, identity management.
  • Training: Regular cybersecurity training for all employees, including management.

Executive Liability: The New Risk

The most politically sensitive point: NIS2 introduces personal liability for management. Article 20 requires that governing bodies approve cybersecurity measures, oversee their implementation, and participate in training. For violations, fines of up to 10 million EUR or 2% of global annual revenue can be imposed (for essential entities).

This means: cybersecurity is no longer an IT topic that can be delegated to the CISO. It is a board-level issue. And executives who do not engage with the topic are acting negligently.

The Timeline Pressure

For German companies, the following applies:

  • Now: Check whether you are affected (sector + thresholds)
  • By June 2026: Gap analysis: What is missing compared to NIS2 requirements?
  • By October 2026: Measures implemented, documented, verifiable. Registration with BSI.
  • From October 2026: BSI can audit, reporting obligations apply, fines can be imposed.

Pragmatic Implementation

For most affected mid-sized companies, NIS2 is not rocket science. The required measures largely correspond to what is considered best practice in IT security. Those who have already implemented ISO 27001 or BSI IT-Grundschutz are 70-80% compliant.

The pragmatic approach:

  1. Applicability check: Am I affected? Which category?
  2. Gap analysis: What is missing? Documented ISMS? Incident response plan? Backup concept? MFA?
  3. Quick wins: Introduce MFA, formalize patch management, conduct backup tests, define reporting process.
  4. Documentation: NIS2 does not require perfection but verifiability. Document what you do and why.
  5. External support: For the gap analysis and implementation, a specialized partner is worthwhile. IT service providers like Nemonicon GmbH offer structured NIS2 readiness checks that deliver a clear roadmap in just a few days.

NIS2 is not a punishment. It is an opportunity to bring your own IT security to a level that is needed anyway. The regulation provides the impetus. Implementation is up to the companies.

Sources: EU Directive 2022/2555, NIS2UmsuCG (BGBl. 2025), BSI NIS2 FAQ, ENISA NIS2 Implementation Guidance.

Comments

Sign in to write a comment.

Swipe up
Next Article

FCC Plans D2D Expansion: 25 MHz Auction and 482 MHz for Satellite Coverage

Regulation & Law