NIS-2 directive

Binding measures for a high level of cybersecurity in the EU – the NIS-2 Implementation Act is now in force.

A smiling man looks over a monitor at a seated colleague. The scene is partially obscured by plants in the foreground, suggesting a lively and friendly working atmosphere. Bright and natural colors dominate the room.
A modern office with four people at standing desks working intently on their computers. The office is bright and decorated with abstract wall art and plants as a room divider, creating a creative and lively working atmosphere. People are dressed casually and professionally, indicating a relaxed but productive work environment.
Kutzschbach IT Consulting

NIS-2 directive
at a glance

The European NIS 2 Directive is a further development of the original NIS Directive from 2016 and was created to strengthen cybersecurity in Europe. It aims to create a uniform level of security for network and information systems and increase resilience against cyberattacks.

Compared to the previous version, NIS-2 extends the scope to additional sectors such as energy, transport, health, digital infrastructure and public administration. In addition, cooperation between EU Member States will be improved in order to respond to cyber incidents more quickly and in a more coordinated manner.

With the NIS-2 Implementation Act, which came into force on December 6, 2025, the requirements are now legally binding in Germany. Affected companies must now take action to comply with the legal requirements and avoid fines.

Who visites is affected

The NIS-2 Directive applies to public and private entities in 18 sectors with at least 50 employees or an annual turnover of at least EUR 10 million . Some, such as parts of the digital infrastructure and public administration or critical installations, are affected regardless of their size.

Even if you are not directly affected by the NIS-2 Implementation Act, affected business partners or customers may request proof from you as a supplier as part of the required supply chain security management.

What must you do now

According to the new BSI Act (§ 30), you must implement at least the following cybersecurity measures to manage the security risks to your information systems and to prevent or minimize the consequences of security incidents. This requires the protection of IT systems as well as their physical environment.

Management is responsible for monitoring the implementation of measures and is personally liable for any violations. In addition, it is obligated to participate in cybersecurity training and ensure that this training is also offered regularly to employees.

Early warning within 24 hours of knowledge:
An early warning must be sent to the BSI within 24 hours of the incident becoming known. This includes an assessment of whether the incident is due to an unlawful or malicious act and whether it has cross-border implications.

Detailed report within 72 hours of knowledge:
A detailed report must be submitted within 72 hours of becoming aware of the incident. This report includes an initial assessment of the security incident, including its severity, impact and, if applicable, indicators of compromise.

Progress/final report one month after notification:
A progress or final report must be submitted one month after the incident is reported. This report contains a detailed description of the incident, information on the nature of the threat, its causes, the remedial measures taken and, if applicable, the cross-border impact.

In accordance with Section 33 of the new BSI Act, affected institutions must register with the Federal Office for Information Security (BSI).

Our Solution to the NIS 2 guideline

Our focus is to be at your side as experts and to provide you with comprehensive support on your way to NIS-2 compliance. With our managed service, you receive the comprehensive, worry-free package and are on the safe side.

The right solution

with individual adaptation to your needs

Price on request

A concentrated man with tattoos sits in a modern rocking chair, a laptop on his knees, touching his head as if thinking or seeking a solution. He is dressed casually and is in a bright corner of the office next to a large potted plant that creates a calming atmosphere.

We support you

Our Team of experts for the NIS-2 directive

We would be happy to advise you personally on the NIS 2 directive and create an individual offer that suits your requirements.

NIS-2 Directive – New regulations for a high level of cybersecurity

Find out everything you need to know about the NIS 2 directive and how we support companies in implementing it.

Your direct line to us

We look forward to your inquiry! Simply leave us a message and we will contact you immediately.


Request white paper

Remote Maintenance

To enable us to help you most easily via remote maintenance, please download the TeamViewer program here and contact our support team.

Our support team will then support you directly in setting up the tool.