NIS2 consulting: turning a law into a management system.

Germany's NIS2 Implementation Act has been in force since 6 December 2025 — with no transition period. Roughly 29,500 companies have been under BSI supervision ever since; before, it was about 4,500. We start by determining whether you are one of them, complete a missed registration, and build the measures required under Section 30 BSIG so that they hold up as evidence when it matters — not merely as documentation.

29,500 entities under supervision
more than before
70–80% covered by ISO 27001
€10M maximum fine
Current situation

A law with no grace period — and a long fuse.

The obligations have applied from day one. What most companies lack is not the will, but the clarity that they are the ones being addressed.

Both registration deadlines have passed

The statutory deadline ended on 6 March 2026. The grace period the BSI granted to latecomers expired on 31 July 2026. Anyone not registered now is operating without any protective cover — and the missing registration is subject to a fine in its own right.

About half believe they are out of scope

The Cyber Security Report 2026 shows that roughly 48 percent of the companies surveyed underestimate their own regulatory exposure. The most expensive mistake under NIS2 is not an incomplete measure — it is the assumption that none of this applies to you.

The supply chain passes the duty on

Section 30 BSIG explicitly requires regulated entities to manage the security of their supply chain. That is why security questionnaires increasingly land with service providers who are not regulated themselves — and they still have to be answered.

Executive management is personally liable

Under Section 38 BSIG, executive management must approve the measures and oversee their implementation; it is personally liable for culpable breaches, and a waiver of liability is void. The work can be delegated — the responsibility cannot.

Classification

Two classes, two supervisory regimes.

You are in scope if you operate in one of the 18 sectors and meet the size thresholds. The class determines how strictly the authority inspects and how high the fines can run.

Criterion Essential entity Important entity
Size 250 or more employees, or more than €50M revenue and more than €43M balance sheet total 50 or more employees, or more than €10M revenue and balance sheet total
Supervision Proactive — the BSI may inspect without cause Reactive — inspection upon indications of violations
Maximum fine up to €10M or 2% of global annual revenue up to €7M or 1.4% of global annual revenue
Registration Mandatory, regardless of class Mandatory, regardless of class
Measures under Section 30 Identical — the catalog applies equally to both classes Identical — the catalog applies equally to both classes

The size thresholds are only half the story: certain entities — qualified trust service providers, TLD registries, or DNS services, for instance — fall under the law regardless of their size. Nor does a sector protect you by itself: what counts is the actual activity, not the self-description in the commercial register.

The shortest path

At its core, NIS2 asks for an ISMS. That we know how to build.

Behind the ten areas of measures in Section 30 BSIG stands nothing other than a functioning information security management system. If you already run ISO/IEC 27001:2022, you have met the bulk of the requirements — the remaining gap is largely regulatory rather than technical.

  • Risk analysis and security policies — congruent with Annex A
  • Business continuity, backup, and crisis management — present, usually only to be extended
  • Cryptography, multi-factor authentication, access control — technically identical
  • Genuinely new: registration, the 24-hour reporting chain, and the training duty for executive management
Services

What we take on for your NIS2 implementation.

From the first assessment to the point where you can face a supervisory inquiry without flinching.

Scope

First settle the question that decides everything else.

We test your actual activity against the 18 sectors, the size thresholds, and group-wide attribution — with a written result that holds up even when it reads “out of scope.” Because that finding needs evidence too.

Gap analysis

The distance between where you are and Section 30, measured in weeks.

We match your existing measures against all ten requirement areas of the law — prioritized by risk and effort, not by the order in which the statute happens to list them.

Registration

The filing with the BSI — complete rather than fast.

Preparation of the details for the BSI portal, designation of contact points, and setting up the round-the-clock reachability the law presumes. Late registrations we complete in a structured way.

Incident reporting

24 hours is shorter than it sounds.

A rehearsed sequence for the initial report within 24 hours, the follow-up after 72 hours, and the final report after one month — including a decision tree covering who reports, when, and what belongs in a report.

Implementation

Measures that survive daily operations.

Technical and organizational implementation of the ten areas — on Apple fleets enforced directly through Mosyle MDM rather than asserted in a policy: encryption, patch level, access control, device compliance.

Evidence

Documentation that stands up to scrutiny.

Evidence for supervisors and customers, preparation of executive management for its approval and oversight duty, and solid answers to supply chain questionnaires.

Process

Four steps from uncertainty to demonstrable compliance.

1

Classify

Scope analysis with a written result: in scope, out of scope, or bound through the supply chain — and in which class.

2

Secure

Registration with the BSI, contact points designated, reporting path defined. What carries a deadline comes first — everything else after.

3

Close

Gap analysis against Section 30 and closure of the gaps, prioritized by risk. Technical measures are enforced, not recommended.

4

Demonstrate

Documentation, training for executive management, a dry run of the reporting process, and an annual rhythm for reviewing effectiveness.

For suppliers and service providers

Being out of scope does not exempt you from answering.

A large share of our clients — creative studios, film production companies, architecture firms, IT service providers — do not fall under the law themselves. They get asked regardless, because their clients have to ask. Those who have a structured answer ready win contracts while others are still assembling documents.

  • Answer security questionnaires from large clients with substance
  • Review contractual security requirements before they are signed
  • Build a lean ISMS that matches the size of your company
  • Prepare the evidence before the first client asks for it
FAQ

Frequently asked questions about NIS2.

As of August 2026. Legal position under the German NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG).

Has the registration deadline with the BSI expired?

Yes, both of them. The statutory deadline ended on 6 March 2026, three months after the NIS2 Implementation Act took effect. The BSI subsequently announced that it would tolerate late registrations until 31 July 2026 and refrain from taking action during that period. That was a discretionary decision by the authority, not an extension of the statutory deadline — and even that window has now closed. Anyone still unregistered should complete it immediately: registration is a standalone obligation, failing to register is a standalone offense subject to fines, and a late registration is in every case better than none.

We already have ISO 27001 — is that enough for NIS2?

It covers most of the distance, but it is not the finish line. Experience shows that a functioning ISMS under ISO/IEC 27001:2022 covers 70 to 80 percent of the requirements in Section 30 BSIG, because both rest on the same principle: manage by risk rather than tick off measures. What ISO 27001 does not bring with it are the specifically regulatory parts — registration with the BSI, the reporting chain with its 24-hour initial notification, the formal training and oversight duty of executive management under Section 38 BSIG, and the duty to provide evidence to the supervisory authority. That gap can usually be closed in weeks, not months.

We are not directly in scope for NIS2. Why is our client asking anyway?

Because Section 30 BSIG explicitly counts supply chain security among the obligations of the regulated entity. A regulated company has to assess and manage the security of its service providers — and passes that requirement on to you contractually. This hits IT service providers, cloud and hosting providers, maintenance firms, and agencies with access to systems or unreleased material particularly hard. For you this creates no statutory obligation, but a contractual one: you are asked, you have to answer, and the quality of your answer decides the contract.

Is executive management personally liable?

Yes. Section 38 BSIG requires executive management to approve the risk management measures and to oversee their implementation, and provides for personal liability for culpable breaches of duty. A waiver of the company's claims for damages is excluded by law. The operational work can be delegated — to an internal or external information security officer — but the oversight duty itself cannot. In practice this means executive management must be informed regularly and verifiably, and that evidence must exist in documented form.

How long does a NIS2 implementation take?

That depends almost entirely on the starting point. The scope analysis and a solid registration are a matter of days. A company with an existing ISMS usually closes the remaining gaps in four to eight weeks. Without a documented security management system, expect four to nine months to reach an audit-proof state — with the critical items, above all registration, the reporting process, and emergency contacts, standing right at the beginning rather than at the end of the project.

Do you provide legal advice on NIS2?

No. We work technically and organizationally: assessing scope, building the measures under Section 30 BSIG, structuring evidence, rehearsing reporting processes. The binding legal assessment — particularly where sector classification is unclear, group structures are involved, or supervisory proceedings are already running — belongs in the hands of a specialized law firm. In those cases we work alongside them and supply the technical basis on which the legal decision is made.

Read next

Related