NIS2
In force (staggered)Directive (EU) 2022/2555 on measures for a high common level of cybersecurity (NIS 2 Directive)
This applies to you if …
- Your entity falls into one of the 18 sectors (e.g. energy, transport, health, digital infrastructure, IT services, ICT service management).
- You are a medium or large company (from 50 employees or EUR 10 million annual turnover) in an in-scope sector.
- You provide a critical service (e.g. cloud, data centre, DNS, managed services), regardless of size.
Core obligations
- Introduce cybersecurity risk-management measures (technical and organisational, state of the art).
- Report severe security incidents within 24 hours (early warning) and 72 hours (notification) to the competent authority.
- Management responsibility: leadership is liable and must oversee and receive training on cybersecurity.
- Ensure supply-chain security and the security of network and information systems across the full lifecycle.
Keep reading — free
Unlock the full content
Enter and confirm your email address: you subscribe to the Signal Forge newsletter by FORGE and get instant access to this and all other registration-gated content. You can unsubscribe at any time.
Already registered? The link from your confirmation email unlocks this device again.
First steps
- Check whether the entity is classified as essential or important (sector + size).
- Compare existing cybersecurity measures against the NIS2 minimum requirements (gap analysis).
- Set up an incident-response and reporting process aligned with the 24h/72h deadlines.
- Check registration with the BSI — in Germany the registration deadline has already passed (06.03.2026); catch up on late registration and leadership training promptly.
Deadlines
- 2024-10-17EU deadline for transposition into national law (Germany initially missed this deadline)
- 2025-04-17Member States are to draw up lists of essential and important entities
- 2025-12-06Germany: NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) entered into force
- 2026-03-06Germany: end of the 3-month registration deadline for in-scope entities with the BSI
Penalty for non-compliance
Fines up to EUR 10 million or 2 % of worldwide annual turnover (essential entities) or up to EUR 7 million or 1.4 % (important entities); personal management liability possible.