Skip to content

Basics & Compliance

How to check whether NIS2 applies to your organisation

Sector, size threshold, exceptions, entity type, registration deadline: in five concrete steps, determine whether your organisation is subject to NIS2, with updated BSIG references (§§ 28, 33, 65).

8 min read · Published 18 February 2026

By the end of this guide, you will have a reasoned assessment of whether your organisation falls under NIS2 and, if so, as which type of entity. That is the prerequisite for every subsequent implementation step.

Since 6 December 2025, Germany's NIS2 implementation law (NIS2UmsuCG) has been in force. The Federal Government estimates that roughly 29,000 to 30,000 organisations are affected. Many of them do not yet know this.

Important: you must initiate the applicability check yourself. The BSI does not send notifications. Organisations that fail to register when required risk fines of up to EUR 500,000 under § 65(5) no. 5 BSIG.

Step 1: Check your sector, Annex 1 or Annex 2?

The BSIG 2025 covers only entities in defined sectors. Check whether your primary activity falls within one of the listed sectors.

Annex 1: high-criticality sectors

Companies in Annex 1 sectors may be classified as either especially important entities (bwE) or important entities (wE) depending on size:

  • Energy: electricity, district heating and cooling, oil and fuel, gas, hydrogen
  • Transport: aviation, rail, maritime, road
  • Financial sector: credit institutions, trading venues, central counterparties
  • Health: healthcare providers within the meaning of Directive 2011/24/EU (including hospitals), EU reference laboratories, pharmaceutical manufacturers, pharmaceutical R&D
  • Water: drinking water suppliers, wastewater companies
  • Digital infrastructure: cloud providers, data centres, DNS services, TLD registries, IXPs, CDNs, MSPs, MSSPs, trust service providers, public electronic communications networks
  • Space: operators of ground-based infrastructure for space-based services

Annex 2: other critical sectors

Companies in Annex 2 sectors can only be classified as important entities (wE):

  • Postal and courier services
  • Waste management
  • Chemicals (manufacture and distribution under REACH)
  • Food (wholesale and industrial production or processing, not retail)
  • Manufacturing: medical devices; computers and electronics (NACE 26); electrical equipment (NACE 27); machinery (NACE 28); motor vehicles and parts (NACE 29); other transport equipment (NACE 30)
  • Digital service providers: online marketplaces, online search engines, social networks
  • Research institutions

Your primary activity is what matters, not the sector your IT systems serve. A machinery manufacturer falls under Annex 2 "Manufacturing" regardless of how complex its IT infrastructure is. A food producer with a strong IT department falls under Annex 2 "Food", not Digital Infrastructure.

If your primary activity is in none of these sectors, you are not directly subject to NIS2, subject to the exceptions in Step 3. Note, however, that if you supply critical services to affected entities, security requirements may be contractually passed down the supply chain. See the article Supply Chain Security Under NIS2 for details.

Step 2: Check the size thresholds

Sector membership alone is not sufficient. The BSIG 2025 uses the EU enterprise size definitions from Commission Recommendation 2003/361/EC.

Thresholds for especially important entities (bwE)

You meet the size criterion for bwE if:

  • at least 250 employees (annual average, full-time equivalents), OR
  • annual turnover over EUR 50M AND balance sheet total over EUR 43M

Thresholds for important entities (wE)

You meet the size criterion for wE if:

  • at least 50 employees (annual average, full-time equivalents), OR
  • annual turnover over EUR 10M AND balance sheet total over EUR 10M

Three typical errors in the size check

Error 1, OR logic between headcount and financial metrics is missed: Headcount and financial metrics are OR-linked. 60 employees and EUR 7M turnover: covered (headcount threshold exceeded). 40 employees, EUR 12M turnover and EUR 11M balance sheet: covered (turnover and balance sheet thresholds exceeded). Turnover and balance sheet, by contrast, are AND-linked with one another.

Error 2, group consolidation is ignored: For linked enterprises (majority-owned subsidiaries), figures from all group companies are generally consolidated. A subsidiary with 30 employees of its own may exceed the 250-employee threshold through group consolidation. The exception under § 28(4) second sentence BSIG applies only if the entity is demonstrably independent of its partner or linked enterprises in terms of the nature and operation of its IT systems, components and processes. Invoking this exception requires documented IT independence.

Error 3, only own figures considered: Review both your own entity and the consolidated group perspective. Document the result with a date. This document is proof of the deadline start.

Exception: small entities can still be covered

Certain entities fall under NIS2 regardless of size, directly as bwE:

  • Operators of critical installations under the BSI-KritisV (typically supply facilities serving at least 500,000 people)
  • Qualified trust service providers (eIDAS Regulation)
  • TLD registries (for example DENIC for .de)
  • DNS service providers (excluding root nameserver operators)

Step 3: Check for exceptions and lex specialis rules

Even if sector and size apply, your entity may be excluded.

Categorical exclusions

Entities whose activities are carried out exclusively in national security, national defence, public security or law enforcement are excluded. This applies to relevant authorities, not to private companies that occasionally carry out contracts in these fields.

Financial sector: DORA takes precedence

The Regulation (EU) 2022/2554 (DORA) has applied since 17 January 2025 and displaces the NIS2 core obligations for financial entities. § 28(6) BSIG makes this explicit: for financial entities within the meaning of Art. 2(2) DORA, §§ 30, 31, 32, 35, 36, 38 and 39 BSIG do not apply. Supervision for DORA obligations lies with BaFin. However, the BSI registration obligation under § 33 BSIG remains: DORA-regulated financial entities must still register with the BSI.

Negligibility exception (§ 28(3) BSIG)

When assigning an entity to an entity type under Annex 1 or 2, activities that are "negligible" (vernachlässigbar) relative to the entity's overall business may be disregarded. The term is not legally defined. Anyone invoking this exception must document the decision thoroughly.

Step 4: Determine entity type, bwE or wE?

Organisations covered after Steps 1 to 3 must still determine which type they are. This affects supervisory intensity, not the substance of security obligations: these are identical for both types.

Especially important entity (bwE)

  • Large organisations (≥ 250 employees or turnover > EUR 50M AND balance sheet > EUR 43M) in Annex 1 sectors
  • Qualified trust service providers, TLD registries, DNS services, public communications networks (size-independent)
  • Operators of critical installations under BSI-KritisV (size-independent, with additional obligations)

Important entity (wE)

  • Medium organisations (≥ 50 employees or turnover > EUR 10M AND balance sheet > EUR 10M) in Annex 1 sectors that do not qualify as bwE
  • Medium and large organisations in Annex 2 sectors

What differs between the two types

BSI supervision: bwE are supervised proactively and without specific cause (ex ante, § 61 BSIG). wE are audited only on substantiated grounds (ex post, § 62 BSIG).

Maximum fines (§ 65 BSIG): for serious breaches of §§ 30, 32 BSIG, bwE may face fines of up to EUR 10M, wE up to EUR 7M. For groups with total turnover above EUR 500M, turnover-based caps additionally apply: 2 per cent (bwE) or 1.4 per cent (wE) of worldwide annual turnover.

Security obligations (§ 30 BSIG): identical for both types. All 10 minimum measures set out in § 30(2) nos. 1 to 10 BSIG apply in full.

Step 5: Determine the registration deadline and plan ahead

Once applicability is assessed, the next obligation is BSI registration under § 33 BSIG.

Deadlines

  • Entities already covered on 6 December 2025: registration deadline was 6 March 2026, three months after the law entered into force (§ 33(1) BSIG). The deadline has passed; entities not yet registered should do so without delay.
  • Entities that become covered later (for example through growth over thresholds): registration is required within three months of the entity first or subsequently qualifying as a bwE or wE (§ 33(1) BSIG).

What you need to prepare

  • Commercial register extract (not older than 3 months)
  • ELSTER corporate account, activation code arrives by post, allow 1 to 2 weeks lead time
  • Designate a primary and deputy contact for BSI (functional mailbox recommended)
  • Document the sector assignment (Annex 1 or 2 BSIG)

Output you should have after this guide

  • Sector (Annex 1, Annex 2, or not covered) is determined and documented
  • Size threshold is checked, headcount, turnover and balance sheet recorded with date
  • Lex specialis rules (DORA, sector-specific regimes) are checked
  • Entity type (bwE or wE) is established
  • Registration deadline is calculated and entered in the project plan

Use the applicability checklist from the Template Library for this process, or start with the Pre-Check, an 18-screen gap analysis that reconciles your applicability assessment with ISO 27001 and BSI IT-Grundschutz.

What comes next?

With the assessment complete, BSI registration is next. The article BSI Registration Step by Step guides you through the entire MUK process including ELSTER verification.

For the legal background, particularly edge cases involving group structures, the IT-independence exception and mixed activities, see article Section 28 BSIG: Which Organisations Are Actually Subject to NIS2. For the subsequent implementation of the ten minimum measures under § 30 BSIG, see The 10 Minimum Measures Under Section 30(2) BSIG Explained. The NIS2 Guide walks you through all eight implementation chapters in a structured way.

This article does not constitute legal advice. For questions about the specific legal classification of your situation, in particular for group structures, mixed activities, or lex specialis constellations, consult a lawyer specialised in IT law.

This article is orientation, not legal advice. Verify scope, deadlines and notification routes against the rules in force for your organisation.

Back to the Knowledge Hub