NIS2 Is Here – What Companies Need to Know Now

The digital world is becoming more complex, cyber threats more sophisticated – and the EU is responding. With the NIS2 Directive (Network and Information Security Directive 2), a new era of cybersecurity has begun. Since December 6, 2025, Germany’s NIS2 implementation law has been in force, and for around 30,000 companies, this means one thing: act now.

Why NIS2?

The original 2016 NIS Directive was an important first step toward protecting critical infrastructures. But it quickly became clear that cyberattacks no longer target only energy providers or hospitals.

Today, supply chains, cloud services, logistics, and digital platforms are all interconnected—and therefore vulnerable. The EU has reacted by significantly expanding the scope of NIS2.

Who Is Affected?

NIS2 applies to medium and large enterprises in 18 critical sectors, including:

  • Energy and utilities
  • Transport and logistics
  • Banking and financial market infrastructures
  • Healthcare
  • Digital services (cloud services, online marketplaces)
  • Public administration

Thresholds:

  • From 50 employees or €10M revenue“Important Entity”
  • From 250 employees or €50M revenue“Essential Entity”

The 6 Core Requirements of NIS2

  1. Management Accountability: Executives bear personal responsibility for cybersecurity.
  2. Risk Management: Implementation of structured processes and adequate protective measures.
  3. Incident Reporting: Security incidents must be reported within 24 hours, with a detailed report due within 72 hours.
  4. Supply Chain Security: Security obligations extend across your entire supply chain.
  5. Technical Measures: Including encryption, multi‑factor authentication, and secure communication.
  6. Strict Penalties: Up to €10M or 2% of global annual revenue for non‑compliance.

What Companies Must Do Now

  • Register with the German Federal Office for Information Security (BSI) by March 6, 2026
  • Establish an Information Security Management System (ISMS)
  • Conduct risk assessments and develop incident response & continuity plans
  • Provide cybersecurity training for executives and employees
  • Document all security measures for audits and regulatory checks

Why Act Now?

NIS2 is more than another compliance requirement—it is a paradigm shift. Cybersecurity becomes a strategic priority, embedded at the management level. Organizations that act early not only achieve compliance but also strengthen their long‑term resilience and competitiveness.

Our Offer to You

At D‑Cyber Security, we support you in assessing your company’s NIS2 relevance and conducting a comprehensive maturity assessment of your information security. This ensures you fulfill all requirements—from incident reporting and risk management to organizational and technical security measures.

Let’s work together to define the next steps and secure your company’s digital future.

Related Articles