NIS2
What NIS2 actually requires of your organisation
The German NIS2 implementation act has applied since 6 December 2025, and the BSI registration deadline expired on 6 March 2026. Articles, templates and a checker help you place your organisation; the legal assessment stays with you.
Where to start
01
Knowledge Hub
Articles on scope, duties, accountability and practical implementation.
Browse articles02
Template Library
49 adaptable Word and Excel starting points for policies, registers, incident forms and supplier reviews.
Download templates03
NIS2 Compliance Checker
Structured questions on scope and maturity with an orientation report by email.
Start the checker04
For energy utilities
How energy utilities implement NIS2, Section 30 BSIG and the BNetzA IT security catalogue in one system, IT and OT included.
Read the sector pageWhat to clarify first
- Under Section 28 BSIG you are an important entity from 50 employees or more than 10 million euros in both annual turnover and balance sheet total, and a particularly important entity from 250 employees or more than 50 million euros in turnover together with more than 43 million euros in balance sheet total. For operators of public telecommunications networks the lower figures already apply in the upper category.
- Registration with the BSI was due on 6 March 2026 under Section 33(1) BSIG, three months after the law entered into force. Organisations that have not registered yet should do that first.
- The ten minimum measures are set out in Section 30 BSIG, the reporting cascade of 24 hours, 72 hours and 30 days in Section 32, and the personal duty of the management body in Section 38.
- This page is orientation, not legal advice. The binding classification of your organisation belongs in a professional and legal review.
The legal frame
The frame moved. The certificate folder did not.
Management approves, oversees and is liable.
The management bodies of essential and important entities must approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements. Members of those bodies are required to follow training.
Reporting deadlines run in hours, not weeks.
An early warning within 24 hours of becoming aware, an incident notification within 72 hours, a final report within one month. Assembling the facts during the incident does not meet that clock.
Continuity sits in the same list of duties as cryptography.
Business continuity, backup management, disaster recovery and crisis management are part of the minimum measures, not an annex for later.
AI literacy has been mandatory since February 2025.
Providers and deployers of AI systems must ensure a sufficient level of AI literacy among their staff. The duty applies regardless of the system's risk class.
Scope settled, what now?
Once the classification stands, the work starts: ten measures under Section 30 BSIG, reporting routes, the supply chain and the evidence the BSI expects. We go through your case and tell you what is still open.