
Who is
affected?
The NIS2 Directive applies to companies and organizations considered critical or important infrastructures. These include sectors such as energy, transport, digital infrastructure, healthcare, and many more. Companies that are not classified as micro or small enterprises are particularly affected – meaning you have at least 50 employees and/or an annual turnover or annual balance sheet total of at least 10 million euros. In the future, you will need to implement strict IT security measures and report cyber incidents.
NIS2 expands the previous scope and now covers significantly more organizations responsible for the security of networks and information.
The companies to which NIS2 applies can generally be divided into two categories:
“Important entities” are organizations or companies that, pursuant to Section 28 (2) BSIG, must comply with certain registration, verification, and reporting obligations. These entities are identified based on criteria such as annual turnover or number of employees. The NIS2 Implementation Act entered into force on December 6, 2025, and amended the BSI Act accordingly. Since then, important entities must implement IT security risk management measures pursuant to Section 30 BSIG and report significant security incidents pursuant to Section 32 BSIG to ensure the protection of networks and information systems.

“Particularly important entities” are companies and organizations that, compared to important entities, are subject to stricter and more regular supervision by the BSI. They are also primarily determined based on thresholds such as turnover or number of employees; operators of critical facilities are always considered particularly important entities regardless of these values. The security measures they implement are regularly reviewed, for example through audits or certifications. In the event of violations, they also face higher fines than important entities.
Betroffenheitsprüfung des BSI

What obligations
apply?
In addition to classification as an important or particularly important entity, the focus in day-to-day operations is primarily on the risk management measures under Section 30 BSIG. The law requires, among other things, concepts for risk analysis and IT security, effective asset management as a foundation, access controls, and encryption of sensitive data. This is complemented by network protection through firewalls and intrusion detection systems, regular patch management to close known vulnerabilities, and continuous monitoring and logging to detect incidents at an early stage. A functioning incident management system ensures rapid response and recovery.
In addition, the reporting obligations under Section 32 BSIG apply: Significant security incidents must be initially reported within 24 hours, followed by an interim report with further assessment within 72 hours, and a final report within one month at the latest.
For operators of critical facilities, there is an additional obligation: the use of attack detection systems (Section 31 (2) BSIG). Early attack detection was one of the main reasons for NIS2, as attackers can often move undetected within unsecured networks for weeks before an incident becomes apparent.
It is also important to assess supply chain risks, including security requirements in contracts with third-party providers, as well as to conduct regular employee training sessions and audits, which should be firmly embedded in everyday business operations.
Under Section 38 BSIG, the management itself has an independent obligation: It must monitor the implementation of risk management measures, undergo regular training, and is personally liable if it fails to fulfill this supervisory duty.
What has applied
since when?
For companies affected by NIS2, the new BSIG has applied since December 6, 2025, without any transition period. This means that risk management measures (Section 30 BSIG), reporting obligations, and personal management liability (Section 38 BSIG) have been directly binding since then. Only the BSI registration was subject to a three-month deadline, which ended on March 6, 2026.
The BSI tolerates late registrations until July 31, 2026, without changing the statutory deadline (March 6, 2026) itself – the registration obligation and its exposure to fines therefore remain unchanged.
Background: NIS2 was originally only an EU directive, which Germany was required to transpose into national law by October 2024. This deadline was missed; the national law was only enacted at the end of 2025. Since then, however, the obligations apply immediately and without any grace period.
In the event of violations, fines of up to 10 million euros or 2% of global annual turnover may be imposed on particularly important entities, and up to 7 million euros or 1.4% for important entities, whichever amount is higher. In addition, management has been personally liable under Section 38 BSIG since December 6, 2025; violations may be made public, and in exceptional cases the BSI may impose a temporary professional ban. Companies should therefore act now to avoid consequences.


Do you need a customized solution
for your company?
Honicon offers tailored solutions aligned with the specific requirements of your company. Whether IT security measures, compliance management, or optimizing your Jira environment – we develop individual solutions that perfectly match your business model. Our expertise ranges from integrating specialized tools to automating key business processes. Through our practical approaches, we ensure that your IT infrastructure is not only secure but also efficient. Let us work together to find out how we can take your IT systems to the next level.
Contact us now!
Legal foundations
of NIS2
The NIS2 Directive is an important legislative act of the European Union aimed at strengthening cybersecurity across all Member States. “NIS” stands for “Network and Information Security.” This directive updates and expands the original NIS Directive from 2016 to address the growing challenges posed by cyber threats.
A key aspect is that NIS2 was formulated as an EU directive rather than a directly applicable EU regulation. A directive sets objectives that all Member States must achieve but leaves them flexibility in how they transpose these objectives into national law. This allows each country to adapt the requirements to its specific national circumstances. Member States can enact new laws or amend existing ones to effectively implement the directive. This flexibility is particularly important because each country has different technical infrastructures and security needs.
The legal basis of the NIS2 Directive is Article 114 of the Treaty on the Functioning of the European Union. This provision allows the EU to adopt measures to harmonize national regulations in order to improve the functioning of the internal market. By choosing a directive, national particularities can be taken into account, which is of great importance in sensitive areas such as cybersecurity.
For companies, this means they must prepare for stricter national laws that include higher security standards and reporting obligations. Member States are required to transpose the directive into national law within a specified period. For citizens, this increases the security of digital services, as companies are better protected against cyberattacks.
The NIS2 Directive therefore represents an important step toward improving cybersecurity in the EU. By allowing provisions to be adapted to national circumstances, it ensures that the measures are effective and meet the specific needs of each country while pursuing a high common level of security.
Improve your IT security
together with us




