NIS2 takes effect, because digitalisation needs clear minimum standards
With the German NIS2 implementation act, binding minimum standards for IT security are now law for around 30,000 companies in Germany. The registration deadlines have passed, but those who review and act treat security not as a checkbox but as a quality feature of their own operations. Beyond the tipping point where enough value creation is digital, it becomes a business question anyway.
Many people in Germany like to make fun of the country’s digitalisation. But for all the irony, one simple truth remains: it is the foundation of our modern life, because energy, health, transport, public administration, communication and the economy only work as long as the digital infrastructure behind them runs reliably.
That is exactly why it is right that we are getting binding minimum standards for this area, not as an end in themselves, but as an expression of responsibility. It is about handling our data properly, about the quality of IT operations and about transparency when something goes wrong and one of the central security objectives is violated, that is confidentiality, integrity or availability. Such incidents never affect just one company or one product, but always us as users too.
With the German NIS2 implementation act, this aspiration is no longer a theoretical ideal but applicable law. For around 30,000 companies in Germany, it means a reality of mandatory registration, mandatory reporting and risk management that is clearly defined, verifiable and binding. The real reason for this lies deeper than the law: as soon as the digital share of value creation reaches a tipping point, IT security turns from a technical question into a business one, and NIS2 draws exactly this line for a large part of the economy.
Who wants what from whom, and on what basis
When a new law comes into force, it is always worth looking at the simplest of all legal guiding questions: who wants what from whom, and on what basis. It immediately separates the emotions from the facts and helps to place the topic properly.
The who is the state, represented by the BSI, Germany’s Federal Office for Information Security, which gets a clear supervisory role with NIS2: it monitors, advises, receives reports, audits and can intervene in an emergency.
The what is three things the BSI requires of affected companies: first, registration as a NIS2 company; second, the reporting of significant security incidents; and third, proof of systematic risk management that meets the state of the art and is reviewed regularly.
The from whom is the companies classified under NIS2 as essential or important, that is around 30,000 organisations in Germany, many of which have so far had no contact whatsoever with state-regulated IT security.
The on what basis is the NIS2 implementation act and the European legal framework behind it: while the previous rules for critical infrastructure (KRITIS) were a specialist topic for a few thousand operators, the obligations now affect a considerably broader part of the economy.
This look at the basic logic shows that this is not about a recommendation but about a clear legal situation, not a nice-to-have but obligations that must be met, and not only about individual business risks but about the stability of the digital infrastructure that we as a society depend on.
Where we stand today
When this compendium took up the topic, the law had just come into force and the deadlines still lay in the future. They have since passed, which is why the starting point for an affected company has shifted: it is no longer about preparing early, but about catching up with a state of affairs that already applies.
In practice this means: the two-step registration route via “Mein Unternehmenskonto”, the German government’s company account, and the BSI portal is ready, the obligation to register, to report significant incidents and to manage risk already applies, and the BSI’s initial leniency ended with the grace period. That is no reason for alarm, just the plain state of affairs: anyone who is affected should now catch up on what was already legally due, instead of putting it off any longer.
Checking whether you are affected
The next sensible step is therefore to check whether you are affected, if that has not happened yet. The BSI provides a detailed overview of which sectors, entities and company sizes fall under the law and which criteria are used for the classification, and you can find this overview directly on the BSI website in the section on NIS2-regulated companies.
For many companies the topic is new, and there is no automatic notification, so it is every company’s own responsibility to check whether it counts as essential or important under NIS2. The thresholds relate, among other things, to sector, number of employees, turnover and the importance of the services offered for society.
An important note: the target groups are expected to be extended over the coming years, both for the defined sectors and for the requirements on supply chains and service providers. Even if a company is not yet obliged today, it is worth investing in security, because security is not a checkbox but a mark of quality that builds trust and reduces risks. Those who start now will have considerably less effort later and more control over their own digital stability.
From understanding to action
Checking whether you are affected is the first step, but regardless of the result, the decisive question remains what to do now in concrete terms. Security does not come from knowing your obligations, but from implementing them, and NIS2 does not demand perfection, but a structured approach with which a company can show that it knows, prioritises and controls its risks. This is where the practical work begins.
This work does not end with a one-off measure, because an effective level of security comes from continuous improvement. Technical systems change, new vulnerabilities appear, business processes evolve and new services are added, so security is not a project with an end date, but part of ongoing quality management, in which small regular steps have more effect than hectic one-off actions.
The pragmatic way in
The way in is not through abstract frameworks, but through a very concrete question: which products do we offer, and on which infrastructure components do they run? A complete overview is the simplest and at the same time most effective starting point, because only once it is clear which systems exist can you judge where risks may arise.
Further core questions follow from this, such as how we make sure we recognise new vulnerabilities as soon as they are published. Are there processes or tools that inform us about new CVEs, and how do we make a decision when action is needed? Do our employees know how to deal with such alerts, whom to inform and which steps follow?
Just as important is that everyone involved can raise security concerns, simply, with a low threshold and without fear of consequences, which applies to internal employees as much as to customers. That requires a clear route for how such tip-offs feed into day-to-day processes, be it prioritisation, incident response or change management, because security only becomes effective when tip-offs do not fizzle out but are processed systematically.
NIS2 changes not only rules, but also awareness of how much of our value creation is now digital. For many years we have worked with companies whose products were digital from the start, and there high security standards are a matter of course, because they were part of the business model from the beginning. In recent years, more and more companies have joined them that do not come from IT and where the digital share of processes, services or products has reached a tipping point. By then at the latest, IT security is no longer a technical question, but a business one.
Frequently asked questions
Is this article legal advice?
No. We discuss the legal situation from a technical perspective, so you can judge what it means for running your product. For a binding assessment of your individual case, please consult a lawyer.
From when does NIS2 apply to my company?
The German NIS2 implementation act came into force on 6 December 2025 and has applied since then. There is no automatic notification; every company has to check for itself whether it is affected, based on sector, number of employees, turnover and importance to society. The BSI provides an overview for this.
The registration deadline passed long ago, what now?
The statutory registration deadline with the BSI was 6 March 2026, the grace period granted afterwards 31 July 2026, and both have passed. Anyone who is affected and not yet registered is therefore in default and should catch up on the registration via “Mein Unternehmenskonto” and the BSI portal promptly, instead of waiting any longer.
What does NIS2 require in concrete terms?
Three things: registration as a NIS2 company, the reporting of significant security incidents and proof of systematic risk management according to the state of the art that is reviewed regularly.
How do I get started pragmatically?
Not with abstract frameworks, but with a concrete inventory: which products do we run, on which infrastructure components do they run, how do we learn about new vulnerabilities and who then decides what. Only this overview makes risks assessable.
Related topics
The best policy is useless if it sits in a folder
Security and internal rules are often treated like a document: written once, filed, ticked off. But a policy does not become effective by existing; it becomes effective when its knowledge is within reach at the decisive moment. A real-life reporting odyssey shows how quickly even people who want to help run into a dead end, and why knowledge of internal rules belongs where the work actually happens.
Read more →Why “we scan after the git commit” is not enough for supply chain security
A compromised npm package does not become dangerous when it lands in the repository, but the moment a developer installs it locally. Anyone who takes the supply chain seriously should therefore not ask “Did we scan?” but “Can we determine our blast radius within minutes?”, and that is an organisational question, not merely a tooling one.
Read more →