Skip to content

NIS 2 and BSIG

With the incorporation of the NIS 2 Directive on cybersecurity into the German BSI Act, companies now face a number of obligations. TÜV NORD CERT supports you in implementing information security across your organisation.

Request an Offer
Technische Anlagenprüfung

What is NIS 2?

NIS-2 (Network and Information Security Directive 2) is the expanded EU directive on cybersecurity for businesses and organisations in the European Union. It is designed to provide better protection for network and information systems against cyberattacks and IT failures. Compared with previous regulations, NIS-2 affects significantly more organisations and applies to organisations with 50 or more employees, or an annual turnover and balance sheet total of 10 million euros, across 14 sectors.

How is NIS-2 being implemented in Germany?

In Germany, NIS-2 is implemented through the BSI Act (BSIG). This sets out the responsibilities and powers of the Federal Office for Information Security (BSI), as well as specifying requirements for corporate cybersecurity:

  • Comprehensive risk management
  • Obligation to register with the BSI
  • Obligation to report security incidents and associated deadlines
  • Supervisory and training obligations of senior management
  • Obligations regarding evidence, documentation and controls
  • Raising staff awareness of cyber risks

The BSIG has been in force since 6 December 2025. Organisations should immediately determine whether they fall within the scope of NIS-2, what obligations this entails and how they can fulfil them.

Request an Offer

Which organisations are covered by NIS-2?

NIS-2 applies to organisations in 14 industries/sectors with 50 or more employees, or with an annual turnover and annual balance sheet total of 10 million euros. The BSI Act also distinguishes between particularly important entities and important entities.

Appendix 1 to the BSIG – Main categories pursuant to Section 2(1) of the BSIG

Particularly Important Entities

Particularly important entities are organisations in seven sectors that have at least 250 employees or an annual turnover of 50 million euros and total assets of more than 43 million euros. Regardless of size and turnover, operators of critical infrastructure are automatically classified as particularly important entities. The sectors are listed in Annex 1 of the BSIG:

  1. Energy
  2. Transport and traffic
  3. Finance
  4. Healthcare
  5. Water
  6. Digital infrastructure
  7. Space

Under the BSIG, organisations classified as particularly important facilities must fulfil particularly extensive cybersecurity obligations. Among other things, regular audits are carried out by the BSI. TÜV Nord can assist you in preparing for these audits.

Important Entities

Important entities are companies in a further seven sectors with at least 50 employees or an annual turnover and total assets exceeding 10 million euros. The sectors or industries are set out in Annex 2 to the BSIG:

  1. Postal and courier services
  2. Waste management
  3. Chemical industry
  4. Food industry
  5. Manufacturing
  6. Digital service providers
  7. Research

Comprehensive cybersecurity requirements also apply to important organisations, although in some respects these are less stringent than those for BwE. For example, an audit by the Federal Office for Information Security (BSI) is only required at the authority’s instigation.

BSIG vs. the KRITIS Framework Act: An Overview of Scope and Requirements

Operators of critical infrastructure (KRITIS) are subject not only to NIS-2 and the BSIG, but also to the KRITIS Framework Act (KRITISDachG). To avoid inconsistencies or double compliance burdens, certain requirements of the BSIG do not apply to all organisational classes. The following table provides an overview:
BSIGContentsCritical infrastructure (KRITIS)Particularly important entity (excluding KRITIS)Important entity
§30Risk management measuresApplicableApplicableApplicable
§31Specific requirements for risk managementApplicableNot applicableNot applicable 
§32Reporting obligationsApplicableApplicableApplicable
§33Registration obligationsApplicableApplicableApplicable
§34Special registration requirementsApplicableNot applicableNot applicable
§35Information obligationsApplicableApplicableApplicable
§38Duties of the managementApplicableApplicableApplicable
§39Duties of disclosureApplicableNot applicableNot applicable
§41Prohibition on the use of critical componentsApplicableNot applicableNot applicable
§61Supervisory and enforcement measures by the Federal Ministry for Economic Affairs and Energy (BwE)Not applicableApplicableNot applicable
§62Supervisory and enforcement measures wENot applicableNot applicableApplicable

How are organisations implementing NIS 2?

Before your organisation implements NIS-2, you should check whether you fall within the scope of the Directive or the BSIG. To this end, the Federal Office for Information Security has set up a NIS 2 impact assessment.

If the result is positive, you should review and assess the current state of your information security and compare it with the legal requirements. The following questions are particularly important in this regard:

  • How is our organisation classified under the BSIG, and what obligations does this entail?
  • Are the responsibilities for information security clearly defined?
  • Are cyber risks systematically identified and assessed?
  • Are there suitable technical and organisational security measures in place?
  • Are there effective backup, emergency and recovery processes in place?
  • Has a procedure been established for dealing with a security incident?
  • Are the statutory registration and reporting obligations known?
  • Is the entire supply chain adequately secured?
  • Are staff regularly made aware of IT security risks?

Following this assessment, you must take measures to close any security gaps. These must be regularly reviewed and updated. Depending on your company’s classification, you must report evidence of cybersecurity measures to the BSI either regularly or on request; furthermore, the authority may carry out inspections.

It is therefore important that you document all cybersecurity measures in a traceable manner. This includes risk analyses, security policies, contingency and backup plans, defined responsibilities, training records and audit logs relating to security measures.

FAQ about NIS 2

NIS-2 is a European directive which must be transposed into national law by the Member States. In Germany, this is done through the BSI Act (BSIG). Companies’ specific obligations therefore arise from the relevant provisions of the BSIG.

KRITIS refers to operators of critical infrastructure whose failure could have a significant impact on society. NIS-2 and the BSIG also apply to numerous other companies and organisations. Operators of critical infrastructure must comply with additional legal requirements on top of those set out in the BSIG.

Affected organisations must, amongst other things, establish appropriate risk management procedures, report security incidents, define responsibilities, raise staff awareness, and implement and document technical and organisational security measures.

Organisations should document all relevant measures. These include, for example, risk analyses, security policies, contingency plans, training records and evidence of the effectiveness of technical and organisational security measures.

Do you have any further questions? Our team, led by Felix Rehbein and Toheeb Ajibola, is on hand to assist you, together with the auditors.

ISMS Sales & Projectmanagement, TÜV NORD CERT GmbH

Competent, international, TÜV NORD CERT

TÜV NORD CERT GmbH

TÜV NORD CERT is an internationally recognised and reliable partner for testing and certification services. Our experts and auditors possess in-depth knowledge and are all permanently employed by TÜV NORD. This ensures independence, impartiality and continuity in the support we provide to our clients. The benefit for you is clear: our auditors guide and support the development of your business and provide you with objective feedback.

You might also be interested in this