Skip to content

Basics & Compliance

Which organisations NIS2 actually covers (Section 28 BSIG)

The applicability assessment in detail: all 18 sectors, EU SME size thresholds with the tightened AND operator, size-independent special categories under Section 28(1), the consolidation rule for corporate groups, and what a correct self-assessment under Section 33 BSIG actually requires.

12 min read · Published 02 March 2026

Section 28 BSIG defines the applicability assessment as a two-step test: sector affiliation and size threshold. Most errors do not arise because the criteria are unclear. They arise because organisations correctly classify their primary activity while missing a second regulated sector in which they also operate. The second most common mistake involves corporate group structures: the assessment is performed at group level, even though Section 28 BSIG assesses each legal entity individually while incorporating consolidated group figures for the size calculation.

The NIS2 Implementation Act (NIS2UmsuCG) has been in force since 6 December 2025. The BSI registration deadline expired on 6 March 2026. Organisations that have not yet assessed their applicability should do so without delay. The KaitoSec Vor-Check provides an initial assessment in minutes.

The Sector Structure – Annex 1 and Annex 2 of the BSIG

Section 28 BSIG covers entities in 18 regulated sectors, divided into two annexes. The assignment, together with entity size, determines whether an organisation is classified as an essential entity ("besonders wichtige Einrichtung") or an important entity ("wichtige Einrichtung").

Annex 1 – Sectors of High Criticality (11)

  • Energy (electricity, gas, district heating, oil, hydrogen)
  • Transport (air, rail, maritime, road)
  • Banking
  • Financial market infrastructure
  • Health (hospitals, laboratories, pharmaceutical companies, medical device manufacturers)
  • Drinking water
  • Wastewater
  • Digital infrastructure (DNS providers, TLD registries, cloud computing, data centres, CDNs, trust service providers, public telecoms networks)
  • ICT service management (B2B), in particular MSPs and MSSPs
  • Public administration
  • Space (operators of ground infrastructure)

Annex 2 – Other Critical Sectors (7)

  • Postal and courier services
  • Waste management
  • Chemicals (manufacture, production, distribution)
  • Food (production, processing, distribution)
  • Manufacturing (limited to NACE divisions 26–30: electronics, optical products, machinery, motor vehicles, other transport equipment)
  • Digital providers (online marketplaces, online search engines, social networking platforms)
  • Research

Classification Matrix

  • Large enterprise + Annex 1 → essential entity
  • Large enterprise + Annex 2 → important entity
  • Medium enterprise + Annex 1 or 2 → important entity

Activity-based classification: Sector affiliation is determined by actual function, not by trade register classification. The sector definitions are predominantly activity-based, but individual sectors reference NACE codes explicitly. The manufacturing sector in Annex 2 maps to NACE divisions 26 through 30. Multi-sector entities must assess all business activities.

The Size Thresholds – EU SME Recommendation in Detail

Section 28(4) BSIG refers to EU Recommendation 2003/361/EC for size classification, with a critical tightening of the financial test.

Threshold 1 – Large Enterprise

  • ≥ 250 employees (standalone condition, financial figures irrelevant)
  • OR: annual turnover > EUR 50 million AND annual balance sheet total > EUR 43 million (both must be met simultaneously)

Threshold 2 – Medium Enterprise

  • ≥ 50 employees (standalone condition)
  • OR: annual turnover > EUR 10 million AND annual balance sheet total > EUR 10 million

Below the medium threshold (fewer than 50 employees, turnover and balance sheet each ≤ EUR 10 million), entities are generally not covered. Exceptions (size-independent categories) follow in the next section.

The AND operator – a deliberate tightening by the German legislator

For the financial test, both turnover AND balance sheet must exceed the threshold. This is a deliberate tightening by the BSIG compared to EU Recommendation 2003/361/EC, which uses OR. A company with EUR 65 million turnover but only EUR 38 million balance sheet total is not a large enterprise under the BSIG. It qualifies as medium-sized.

This tightening means that organisations with high turnover but low balance sheet totals (or vice versa) are classified one tier lower than under the EU Recommendation.

Assessment logic: ≥ 250 employees → large enterprise. Under 250 employees → financial test: turnover > EUR 50 million AND balance sheet > EUR 43 million → large enterprise. One or both tests fail → check if ≥ 50 employees or turnover > EUR 10 million AND balance sheet > EUR 10 million → medium enterprise.

Size-Independent Coverage and Special Categories

Certain entities fall under the BSIG regardless of their size. The list is shorter than commonly presented.

Size-independent as essential entity (Section 28(1))

  • Operators of critical facilities under Section 28(1) no. 1
  • Qualified trust service providers under Section 28(1) no. 2
  • TLD registries under Section 28(1) no. 2
  • DNS service providers under Section 28(1) no. 2

Reduced threshold as essential entity (Section 28(1) no. 3)

Public telecommunications service providers and operators of public telecommunications networks with at least 50 employees or more than EUR 10 million annual turnover. The threshold is significantly lower than for standard Annex 1 entities.

Size-independent as important entity (Section 28(2) no. 1)

  • Non-qualified trust service providers – covered as important entities regardless of size

Common misconception

Many overviews list cloud computing providers, data centres, managed service providers and online marketplaces as size-independent. This is incorrect. These entity types are listed in Annex 1 (digital infrastructure) or Annex 2 (digital providers) but are subject to the standard size thresholds of Section 28. A cloud provider with 20 employees and EUR 5 million turnover is not covered.

The Consolidation Rule – Corporate Group Structures

Classification: per legal entity. Size calculation: with aggregation of linked enterprises under Annex I of EU Recommendation 2003/361/EC (Section 28(4) BSIG).

When enterprises qualify as "linked"

  • Majority holding: One enterprise holds, directly or indirectly, a majority of voting rights in another enterprise.
  • Appointment right: One enterprise has the right to appoint or remove a majority of the administrative, management or supervisory body.
  • Contractual influence: One enterprise exercises dominant influence over another pursuant to a contract.

What aggregation means in practice

All employees and financial figures of linked enterprises are added together. A subsidiary with 30 employees and EUR 8 million turnover is not automatically excluded if the group as a whole has 600 employees and EUR 300 million turnover. The consolidated group figures apply for the threshold assessment.

The subsidiary is independently covered if it operates in a regulated sector. Its compliance obligations (Sections 30–38 BSIG), registration obligation (Section 33 BSIG) and management liability (Section 38 BSIG) rest with the subsidiary, not with the parent company.

IT independence exception (Section 28(4))

If an entity can demonstrate that it is fully independent from linked enterprises in terms of the nature and operation of its IT systems, the consolidation rule may not apply. The burden of proof lies with the entity. In practice, full IT independence within a corporate group is rarely given.

Common group misconception: "The group headquarters is already registered under NIS2 and holds ISMS certification. Our 28-person subsidiary is not covered." – Incorrect. If the group meets the size threshold, the subsidiary is independently covered: its own governing body, its own registration, its own ISMS.

Federal Government Entities – Section 29 BSIG

Public administration is governed by Section 29 BSIG, not Section 28. This is a separate provision with its own rules. Federal government entities are explicitly excluded from the scope of Section 28(1) and (2).

Federal entities: Classified as essential entities under Section 29 BSIG, regardless of size. They are subject to the obligations under Sections 30–38 BSIG.

State and municipal entities: The BSIG only covers federal administration. State and municipal entities fall under state-level legislation.

Public entities in regulated sectors (e.g. municipal energy utilities): These are covered under the sector provision in Section 28, not under Section 29. A municipal energy utility that exceeds the size threshold is classified as an energy sector entity.

Self-Assessment – What Section 33 BSIG Requires

The BSIG operates on a self-assessment principle. There is no BSI notification telling you whether you are covered. You must determine and document this yourself.

Four steps

  • Assess sector affiliation – activity-based, covering all business areas. Secondary activities can also trigger coverage.
  • Calculate size threshold – including aggregation of linked enterprises under the consolidation rule. Check both tiers (large and medium).
  • Determine and document classification – essential or important entity. The documentation must be defensible in writing.
  • Complete BSI registration – the registration deadline under Section 33 BSIG expired on 6 March 2026. Organisations that have not yet registered should do so without delay.

Risk of misclassification

"Not covered" when in fact covered: The most serious scenario. No registration, no ISMS, no risk management. Potential fines of up to EUR 10 million under Section 65 BSIG. The turnover-based ceiling of 2% of worldwide annual turnover applies only to entities with turnover exceeding EUR 500 million.

"Important" when in fact essential: The ex-ante supervisory gap means BSI does not proactively review. The entity operates under false security until an incident exposes the misclassification.

The self-assessment must be documented in writing. Record which sectors were assessed, how the size threshold was calculated, and what conclusion was reached. The KaitoSec NIS2 Guide walks you through this process in Chapter 1.

Essential vs. Important – The Operational Difference

The classification determines the supervisory regime and penalty ceilings. The security obligations themselves are identical for both categories.

BSI supervision

  • Essential entities: ex-ante supervision (Section 61 BSIG). BSI may proactively audit, inspect, and request evidence without a prior incident.
  • Important entities: ex-post supervision (Section 62 BSIG). BSI acts only when an incident is reported or concrete evidence of non-compliance exists.

Fines under Section 65 BSIG

  • Essential entities: up to EUR 10 million. For entities with worldwide annual turnover exceeding EUR 500 million, alternatively up to 2% of turnover.
  • Important entities: up to EUR 7 million. For entities with worldwide annual turnover exceeding EUR 500 million, alternatively up to 1.4% of turnover.

Management liability under Section 38 BSIG

Section 38(1) requires management bodies to approve risk management measures under Section 30 and oversee their implementation. Under Section 38(2), management bodies are personally liable for damages resulting from a breach of these obligations, in accordance with applicable corporate law. This liability applies equally to both categories. Section 38(3) establishes a training obligation for management bodies.

Reporting obligations under Section 32 BSIG

Identical for both categories: initial notification within 24 hours, follow-up notification within 72 hours, final report within one month of the incident.

The most significant operational difference is the ex-ante supervision for essential entities. You must be able to demonstrate compliance with Section 30 BSIG requirements at any time. The KaitoSec NIS2 Guide maps this entire implementation path across 8 chapters.

Where This Article Fits in the NIS2 Guide

This article provides the detailed background for Chapter 1, Step 1-1 of the NIS2 Guide (applicability assessment and registration). Related articles:

  • B-01: Self-assessment and registration (operational checklist, step by step)
  • A-42: Supervisory authority and reporting channels
  • A-44: NIS2 in corporate group structures and the principal establishment principle
  • A-01: NIS2 vs. NIS1: What changed with the NIS2UmsuCG

This article does not constitute legal advice. For a binding determination of coverage under Section 28 BSIG, particularly for group structures or entities with mixed activities, consult a lawyer specialising in cybersecurity law.

This article is orientation, not legal advice. Verify scope, deadlines and notification routes against the rules in force for your organisation.

Back to the Knowledge Hub