Skip to content

We answer fast and to the point.

NIS2 — who is affected and what the directive requires

Sector, size, special cases: three criteria decide whether a company falls under the NIS2 Directive. Who is affected, which duties follow, which deadlines apply and what infringements can lead to.

NIS2WHO 01

The NIS2 Directive — Directive (EU) 2022/2555 — has considerably widened the circle of companies that have to organise their cybersecurity in a way they can prove. Its predecessor of 2016 applied to operators of essential services and some digital service providers; NIS2 covers 18 sectors, from energy suppliers to machinery manufacturers. In Germany it has been applicable law since 6 December 2025, implemented in the BSI Act (BSIG).

Almost every NIS2 project therefore begins with the same question: are we affected? This article answers that first — and then what NIS2 requires, which deadlines apply to companies and what infringements can lead to.

Who is affected by NIS2?

Whether a company falls under NIS2 is decided by three criteria: the sector in which it operates, its size and — in some cases — the nature of its service. No authority will tell you the result: every company checks for itself whether it is affected, and then registers.

1. The sector

The directive names 18 sectors in two annexes. Annex I lists the sectors of high criticality:

  • Energy
  • Transport
  • Banking
  • Financial market infrastructures
  • Health
  • Drinking water
  • Waste water
  • Digital infrastructure — including cloud computing and data centre services, DNS services and trust services
  • ICT service management (business-to-business) — managed service providers and managed security service providers
  • Public administration
  • Space

Annex II names the other critical sectors:

  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacturing — medical devices, computer, electronic and optical products, electrical equipment, machinery, motor vehicles and other transport equipment
  • Digital providers — online marketplaces, online search engines and social networking services platforms
  • Research

What counts is not the industry a company considers itself part of, but the type of entity described in the annexes — in German law, in Annexes 1 and 2 to the BSIG. Business activities that are negligible in relation to the company’s activity as a whole may, under § 28 BSIG, be disregarded in the classification.

2. The size

As a rule, medium-sized and large enterprises are covered. The thresholds come from the EU’s SME Recommendation (2003/361/EC):

CriterionMedium-sized enterpriseLarge enterprise
Employees at least 50at least 250
or financial figures annual turnover and annual balance sheet total each above €10 millionannual turnover above €50 million and annual balance sheet total above €43 million

Reaching one of the two thresholds is enough: the number of employees or the financial figures. In groups of companies, the figures of partner enterprises and linked enterprises are counted in as a rule; the German BSIG allows an exception where the company operates its IT systems independently of the group.

3. Essential or important?

Sector and size determine the category. The directive distinguishes between essential and important entities; the German BSIG calls the essential ones “besonders wichtige Einrichtungen” (particularly important entities).

CriterionEssential entitiesImportant entities
In the German BSIG “besonders wichtige Einrichtungen” (particularly important entities)“wichtige Einrichtungen” (important entities)
Who large enterprises in the sectors of Annex I; plus certain types of entity regardless of their sizemedium-sized enterprises in the sectors of Annex I; medium-sized and large enterprises in the sectors of Annex II
Supervision ex ante and ex post — also without any particular cause, for example through audits and on-site inspectionsex post — when there are indications of an infringement
Fines of up to €10 million or 2% of the total worldwide annual turnover€7 million or 1.4% of the total worldwide annual turnover

The duties themselves — risk management, reporting, registration — are essentially the same for both categories. The difference lies in the supervision and in the level of the fines.

4. Regardless of size

Some entities fall under NIS2 even if they do not reach the thresholds:

  • Providers of public electronic communications networks or of publicly available electronic communications services
  • Trust service providers
  • TLD name registries, DNS service providers and entities providing domain name registration services
  • The sole provider in a Member State of a service which is essential for critical societal or economic activities
  • Entities where a disruption of their service could have a significant impact on public safety, public security or public health, or could induce a systemic risk
  • Critical entities within the meaning of Directive (EU) 2022/2557 — in Germany the “Betreiber kritischer Anlagen” (operators of critical facilities)
  • Public administration entities, depending on national law

Not affected — and asked all the same

Even those who meet none of these conditions come across NIS2: as a supplier. Companies that are affected must ensure the security of their supply chain, and they pass the requirements on to their service providers in contracts, questionnaires and audits. For IT service providers, software vendors and suppliers it therefore pays to be able to evidence their own security measures before the first customer asks.

The applicability check in four steps

  1. Record the activities. Which services does the company provide, which goods does it produce — and which of them correspond to a type of entity in Annex I or II?
  2. Determine the size. Establish the number of employees, annual turnover and annual balance sheet total in accordance with the SME Recommendation, including partner enterprises and linked enterprises.
  3. Check the special cases. Does one of the rules that apply regardless of size fit — or does sector-specific legislation take precedence, such as DORA for financial entities?
  4. Document the result. The result “not affected” belongs in the records too, with reasons and date. If the size or the business changes, the check is repeated.

For the German legal framework, the BSI offers an online self-assessment, the NIS-2-Betroffenheitsprüfung, which is available in German. It gives a first orientation; its result is not legally binding.

What does NIS2 require?

The NIS2 requirements fall into four groups. For each, the article of the directive and the section of the German BSIG are given:

  • Risk management measures (Art. 21, § 30 BSIG): appropriate and proportionate technical, operational and organisational measures — in line with the state of the art, and compliance with them must be documented.
  • Reporting duties (Art. 23, § 32 BSIG): significant security incidents must be reported within fixed deadlines.
  • Registration (Art. 3, § 33 BSIG): entities that are affected register themselves with the competent authority and keep their details up to date.
  • Responsibility of management (Art. 20, § 38 BSIG): management implements the measures, oversees their implementation and itself takes part in training regularly.

The ten risk management measures

Art. 21(2) of the directive names ten areas that the measures must cover as a minimum:

  1. Policies on risk analysis and information system security
  2. Incident handling
  3. Business continuity — backup management, disaster recovery — and crisis management
  4. Supply chain security, including the relationships with direct suppliers and service providers
  5. Security in the acquisition, development and maintenance of IT systems, including vulnerability handling and disclosure
  6. Policies and procedures to assess the effectiveness of the measures
  7. Basic cyber hygiene practices and cybersecurity training
  8. Policies and procedures regarding the use of cryptography and, where appropriate, encryption
  9. Human resources security, access control and asset management
  10. Multi-factor authentication or continuous authentication, secured voice, video and text communications and, where appropriate, secured emergency communications

The list names topics, not finished measures: what is appropriate depends on the risk, on the size of the company and on the possible consequences of an incident. For certain types of digital entity — such as cloud providers, data centres and managed service providers — Implementing Regulation (EU) 2024/2690 sets out the requirements in detail.

Anyone who already runs an ISMS in line with ISO 27001 does not start from zero: what is documented there can — where it fits in substance — be used for the corresponding NIS2 requirements. A certificate, however, replaces neither registration nor the reporting duties.

Reporting deadlines for significant security incidents

  • Within 24 hours of becoming aware: the early warning — in the German BSIG, the “frühe Erstmeldung” (early initial report).
  • Within 72 hours: the incident notification, with an initial assessment of severity and impact.
  • At the request of the authority: intermediate reports on the status.
  • No later than one month after the incident notification: the final report. If the incident is still ongoing, a progress report takes its place for the time being.

The deadlines run from the moment the company becomes aware of the incident — at night and at the weekend too. Anyone who waits for the emergency to settle who reports and who decides has, as a rule, already used up the 24 hours.

Which NIS2 deadlines apply to companies?

The dates in the directive are addressed to the Member States, not to companies:

  • 16 January 2023: the directive enters into force.
  • 17 October 2024: deadline for transposition into national law. On the following day the old NIS Directive (EU) 2016/1148 is repealed.
  • 17 April 2025: the Member States establish a list of essential and important entities and update it at least every two years.
  • 17 October 2027: the Commission reviews the directive for the first time, and every 36 months thereafter.

For companies, what counts is the national law — and the day on which it enters into force. Many Member States did not meet the transposition deadline, which is why the state of play differs from country to country.

In Germany the new BSIG has applied since 6 December 2025; it provides for no general transition period for the duties. For registration with the BSI, affected entities had three months under § 33 BSIG — that deadline has passed. Anyone who is affected and not yet registered should make up for it without delay. Anyone who falls under the law for the first time later on, because the company grows or a line of business is added, again has three months from that point.

NIS2 fines and management liability

Infringements of the duties on risk management and reporting can be expensive. The directive sets maximum amounts that every Member State must provide for as a minimum:

  • Essential entities: €10 million or 2% of the total worldwide annual turnover in the preceding financial year — whichever is higher.
  • Important entities: €7 million or 1.4% of the total worldwide annual turnover.

The German BSIG adopts these amounts in § 65; there, the turnover-based range applies to companies with a total turnover of more than €500 million. A missed registration can be penalised as well — with up to €500,000.

Personal responsibility often weighs heavier than the fine. The members of the management bodies can be held liable for infringements; in Germany they are liable to their company under the rules of company law. Authorities can also order that an infringement be made public. As a last resort — and only for essential entities — the directive provides that persons at management level may temporarily not exercise their functions until the deficiency has been remedied.

Why implementing NIS2 pays off

NIS2 is a law, but the measures it requires are the same ones that prevent an attack or limit its consequences:

  • Recognise risks early: those who know their systems, dependencies and vulnerabilities act before damage occurs.
  • Keep the business running: tested backups, recovery plans and a well-rehearsed crisis team decide whether an incident costs hours or weeks.
  • Respond faster: fixed reporting channels create clarity in an emergency — and the reports to the authorities help to warn other companies in time.
  • Prove trustworthiness: customers and partners ask for evidence. Those who can present it stay in the supply chain.

Implementing NIS2 with Complaica

Complaica is NIS2 software — at its core ISMS software that comes with the NIS2 requirement catalogue. Scope, assets, requirements, risks, measures, security incidents and evidence sit in one data set; dashboards show management how far the implementation has come and where the gaps are.

Open security incidents with deadlines and owners in Complaica

Added to this is consulting, as far as you need it: from the applicability check through the gap analysis to ongoing evidence. Whether the duties are met is, in the end, judged by the competent authority — Complaica keeps the evidence for that ready.

Would you like to know whether your company is affected? Request a free 20-minute checkup.

Conclusion

Whether NIS2 applies to a company is settled by sector, size and special cases — and nobody takes that check off its hands. The duties are essentially the same for essential and important entities: risk management, reporting, registration and the responsibility of management. In Germany they already apply. The sensible first step is therefore a documented applicability check, the second a gap analysis against the ten risk management measures.

NIS2WHO 03

What do you think?

Write to us — which of these is you?

✓Would you like more posts on this topic?
✓Would you like to share material of your own on it?
✓Will you leave us your contact details?
✓Will you follow us on social media?
Request price list