Category
ISMS & Compliance
Topic
NIS2 implementation in Germany
Audience
Companies & Management
Reading time
approx. 6 minutes

To meet the legal requirements in the field of IT security, compliance with the legislation relating to NIS2 is essential. In this article, we briefly outline the background to NIS2 in Germany and explain what companies now need to do.

Background to the NIS2 policy

The NIS2 Directive was adopted by the European Parliament and the Council at the end of 2022 and published in the Official Journal on 27 December 2022. As it is a directive, the implementation of the legislation into national law must be carried out. In Germany, the proposed name for this is the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG). You can find out more about the current status of the NIS2 Implementation Act on our website nis2-navigator.de.

Status as at early 2025: Due to the collapse of the ‘traffic-light’ coalition, it remains unclear whether and when the Bundestag will pass a corresponding law. Germany would have had to enact national legislation by 17 October 2024. We will provide updates on our blog as soon as there are any new developments.

Overview of the policy and the Implementation Act

Überblick zur NIS2-Richtlinie und zum Umsetzungsgesetz
With NIS2, the legislator aims to enhance cybersecurity. To this end, explicit minimum standards are set out in Section 30 of the latest draft of the NIS2UmsuCG. Furthermore, companies face heavy penalties if they fail to comply with relevant obligations, such as registration or other regulatory requirements.

Informationen zu NIS2 auf einen Blick
Who is affected by NIS2?

In total, up to 30,000 organisations in Germany are directly affected by NIS2. You can easily check whether you are affected using the sector overview; alternatively, we would be happy to advise you on this.

Übersicht über die NIS2 Sektoren
Key obligations under NIS2

If a company is affected, it is obliged to register independently with the BSI. In addition, further obligations apply:

1

Obligation to register with the BSI

Affected organisations must register with the Federal Office for Information Security on their own initiative.

2

Compliance with minimum standards

Under Section 30 of the latest draft of the NIS2UmsuCG, explicit minimum technical and organisational standards must be complied with.

3

Risk-based approach

Security measures should be tailored on a risk-based basis rather than being implemented across the board.

4

Timely reporting obligations

In the event of security incidents, reports must be submitted extremely promptly and in full detail.

The legislator has therefore laid down a whole range of obligations for businesses, which you should address promptly in order to be NIS2-compliant.

NIS2 Pflichten

“Get your business ready for the upcoming NIS2 legislation today.”
Mint Secure GmbH

Preparation timeline

A timeline to help organisations prepare for NIS2 looks something like this; we’d be happy to advise you on your specific situation if required.

NIS2 Timeline
Our Managing Director, Tim Philipp Schäfers, gave a presentation on the topic of NIS2 and the current status of the legislation at the German OWASP Day (GOD 2024); you can watch the presentation here
. Further information on NIS2 is available on our information page, the NIS2 Navigator
.

 

NIS2 Vortrag von Tim Philipp Schäfers

How Mint Secure supports you

We support you every step of the way, from the impact assessment right through to full NIS2 compliance.

📋

NIS2 Scoping Analysis

Assessing whether and to what extent your organisation is affected by the NIS2 policy.

🛡️

ISMS Implementation & Compliance

Support in establishing an Information Security Management System, including the required minimum standards.

💬

Consultancy

Tailored advice on registration requirements, reporting processes and the practical implementation of NIS2.

Ready to get started?

We offer a free initial consultation. Get in touch now.

Conclusion

NIS2 potentially affects up to 30,000 companies in Germany and entails far-reaching obligations, ranging from registration with the BSI and compliance with minimum standards to strict reporting deadlines for security incidents. Even though the national implementation of the NIS2UmsuCG in Germany is still pending, affected organisations should start preparing now.

By clarifying your own compliance status at an early stage and developing a risk-based security strategy, you can avoid time pressure and potential penalties later on.

Mint Secure supports you every step of the way, from the compliance analysis right through to full NIS2 compliance. Get in touch with us.