With the incorporation of the NIS 2 Directive on cybersecurity into the German BSI Act, companies now face a number of obligations. TÜV NORD CERT supports you in implementing information security across your organisation.
Request an Offer
NIS-2 (Network and Information Security Directive 2) is the expanded EU directive on cybersecurity for businesses and organisations in the European Union. It is designed to provide better protection for network and information systems against cyberattacks and IT failures. Compared with previous regulations, NIS-2 affects significantly more organisations and applies to organisations with 50 or more employees, or an annual turnover and balance sheet total of 10 million euros, across 14 sectors.
In Germany, NIS-2 is implemented through the BSI Act (BSIG). This sets out the responsibilities and powers of the Federal Office for Information Security (BSI), as well as specifying requirements for corporate cybersecurity:
The BSIG has been in force since 6 December 2025. Organisations should immediately determine whether they fall within the scope of NIS-2, what obligations this entails and how they can fulfil them.
NIS-2 applies to organisations in 14 industries/sectors with 50 or more employees, or with an annual turnover and annual balance sheet total of 10 million euros. The BSI Act also distinguishes between particularly important entities and important entities.

Particularly important entities are organisations in seven sectors that have at least 250 employees or an annual turnover of 50 million euros and total assets of more than 43 million euros. Regardless of size and turnover, operators of critical infrastructure are automatically classified as particularly important entities. The sectors are listed in Annex 1 of the BSIG:
Under the BSIG, organisations classified as particularly important facilities must fulfil particularly extensive cybersecurity obligations. Among other things, regular audits are carried out by the BSI. TÜV Nord can assist you in preparing for these audits.

Important entities are companies in a further seven sectors with at least 50 employees or an annual turnover and total assets exceeding 10 million euros. The sectors or industries are set out in Annex 2 to the BSIG:
Comprehensive cybersecurity requirements also apply to important organisations, although in some respects these are less stringent than those for BwE. For example, an audit by the Federal Office for Information Security (BSI) is only required at the authority’s instigation.
| BSIG | Contents | Critical infrastructure (KRITIS) | Particularly important entity (excluding KRITIS) | Important entity |
|---|---|---|---|---|
| §30 | Risk management measures | Applicable | Applicable | Applicable |
| §31 | Specific requirements for risk management | Applicable | Not applicable | Not applicable |
| §32 | Reporting obligations | Applicable | Applicable | Applicable |
| §33 | Registration obligations | Applicable | Applicable | Applicable |
| §34 | Special registration requirements | Applicable | Not applicable | Not applicable |
| §35 | Information obligations | Applicable | Applicable | Applicable |
| §38 | Duties of the management | Applicable | Applicable | Applicable |
| §39 | Duties of disclosure | Applicable | Not applicable | Not applicable |
| §41 | Prohibition on the use of critical components | Applicable | Not applicable | Not applicable |
| §61 | Supervisory and enforcement measures by the Federal Ministry for Economic Affairs and Energy (BwE) | Not applicable | Applicable | Not applicable |
| §62 | Supervisory and enforcement measures wE | Not applicable | Not applicable | Applicable |
Before your organisation implements NIS-2, you should check whether you fall within the scope of the Directive or the BSIG. To this end, the Federal Office for Information Security has set up a NIS 2 impact assessment.
If the result is positive, you should review and assess the current state of your information security and compare it with the legal requirements. The following questions are particularly important in this regard:
Following this assessment, you must take measures to close any security gaps. These must be regularly reviewed and updated. Depending on your company’s classification, you must report evidence of cybersecurity measures to the BSI either regularly or on request; furthermore, the authority may carry out inspections.
It is therefore important that you document all cybersecurity measures in a traceable manner. This includes risk analyses, security policies, contingency and backup plans, defined responsibilities, training records and audit logs relating to security measures.
NIS-2 is a European directive which must be transposed into national law by the Member States. In Germany, this is done through the BSI Act (BSIG). Companies’ specific obligations therefore arise from the relevant provisions of the BSIG.
KRITIS refers to operators of critical infrastructure whose failure could have a significant impact on society. NIS-2 and the BSIG also apply to numerous other companies and organisations. Operators of critical infrastructure must comply with additional legal requirements on top of those set out in the BSIG.
Affected organisations must, amongst other things, establish appropriate risk management procedures, report security incidents, define responsibilities, raise staff awareness, and implement and document technical and organisational security measures.
Organisations should document all relevant measures. These include, for example, risk analyses, security policies, contingency plans, training records and evidence of the effectiveness of technical and organisational security measures.
TÜV NORD CERT is an internationally recognised and reliable partner for testing and certification services. Our experts and auditors possess in-depth knowledge and are all permanently employed by TÜV NORD. This ensures independence, impartiality and continuity in the support we provide to our clients. The benefit for you is clear: our auditors guide and support the development of your business and provide you with objective feedback.