The European NIS 2 Directive is a further development of the original NIS Directive from 2016 and was created to strengthen cybersecurity in Europe. It aims to create a uniform level of security for network and information systems and increase resilience against cyberattacks.
Compared to the previous version, NIS-2 extends the scope to additional sectors such as energy, transport, health, digital infrastructure and public administration. In addition, cooperation between EU Member States will be improved in order to respond to cyber incidents more quickly and in a more coordinated manner.
With the NIS-2 Implementation Act, which came into force on December 6, 2025, the requirements are now legally binding in Germany. Affected companies must now take action to comply with the legal requirements and avoid fines.
The NIS-2 Directive applies to public and private entities in 18 sectors with at least 50 employees or an annual turnover of at least EUR 10 million . Some, such as parts of the digital infrastructure and public administration or critical installations, are affected regardless of their size.
Even if you are not directly affected by the NIS-2 Implementation Act, affected business partners or customers may request proof from you as a supplier as part of the required supply chain security management.
According to the new BSI Act (§ 30), you must implement at least the following cybersecurity measures to manage the security risks to your information systems and to prevent or minimize the consequences of security incidents. This requires the protection of IT systems as well as their physical environment.
Management is responsible for monitoring the implementation of measures and is personally liable for any violations. In addition, it is obligated to participate in cybersecurity training and ensure that this training is also offered regularly to employees.
Early warning within 24 hours of knowledge:
An early warning must be sent to the BSI within 24 hours of the incident becoming known. This includes an assessment of whether the incident is due to an unlawful or malicious act and whether it has cross-border implications.
Detailed report within 72 hours of knowledge:
A detailed report must be submitted within 72 hours of becoming aware of the incident. This report includes an initial assessment of the security incident, including its severity, impact and, if applicable, indicators of compromise.
Progress/final report one month after notification:
A progress or final report must be submitted one month after the incident is reported. This report contains a detailed description of the incident, information on the nature of the threat, its causes, the remedial measures taken and, if applicable, the cross-border impact.
In accordance with Section 33 of the new BSI Act, affected institutions must register with the Federal Office for Information Security (BSI).
Our focus is to be at your side as experts and to provide you with comprehensive support on your way to NIS-2 compliance. With our managed service, you receive the comprehensive, worry-free package and are on the safe side.
with individual adaptation to your needs
Price on request
Is my company assigned to one of the affected sectors? Are my customers significant or critical entities affected by the provisions of the NIS 2 Directive?
We check which measures are still missing in your company. Which measures are suitable or appropriate?
We implement the identified measures.
We regularly check and evaluate your measures and adjust them if necessary.
We would be happy to advise you personally on the NIS 2 directive and create an individual offer that suits your requirements.
Stefan Milde
Key Account Manager
Manfred Schuster
Consultant
Find out everything you need to know about the NIS 2 directive and how we support companies in implementing it.
We look forward to your inquiry! Simply leave us a message and we will contact you immediately.
To enable us to help you most easily via remote maintenance, please download the TeamViewer program here and contact our support team.
Our support team will then support you directly in setting up the tool.
You are currently viewing placeholder content from Vimeo . To access the actual content, click the button below. Please note that this will involve sharing data with third parties.
More informationYou are currently viewing placeholder content from YouTube . To access the actual content, click the button below. Please note that this will involve sharing data with third parties.
More informationYou need to load the reCAPTCHA content to submit the form. Please note that this involves exchanging data with third-party providers.
More informationYou are currently viewing placeholder content from hCaptcha . To access the actual content, click the button below. Please note that this will involve sharing data with third parties.
More informationYou need to load the reCAPTCHA content to submit the form. Please note that this involves exchanging data with third-party providers.
More informationYou are currently viewing placeholder content from Turnstile . To access the actual content, click the button below. Please note that this will involve sharing data with third parties.
More information