NIS2
Network and Information Security Directive 2
EU-Richtlinie über Netz- und Informationssicherheit 2
NIS2 is EU Directive (EU) 2022/2555 to raise the level of cybersecurity across the Union. It substantially broadens obligations compared with the first NIS directive: more sectors, mandatory risk management, staged reporting duties and personal accountability of senior management. In Germany it is transposed by the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), which fundamentally reforms the BSI Act.
History. The first NIS directive of 2016 was Europe's initial attempt at harmonised cybersecurity but remained patchy and inconsistently transposed. NIS2 entered into force at EU level in 2023; the transposition deadline for member states expired on 17 October 2024. Germany missed it considerably — the NIS2UmsuCG was passed by the Bundestag only on 13 November 2025 and entered into force on 6 December 2025 with no transition period.
Facts. Roughly 29,500 entities across 18 sectors are affected, broadly from 50 employees or €10m turnover, split into „essential“ and „important“ entities. Core duties are the risk-management measures under § 30 BSIG-new (incident handling, business continuity, supply-chain security, cryptography, access control, and more), the reporting chain of 24-hour early warning / 72-hour notification / one-month final report, and mandatory registration with the BSI (deadline 6 March 2026). Senior management is personally liable; fines reach up to €10m or 2 % of worldwide annual turnover.
Outlook & recommendation. NIS2 moves cybersecurity decisively from the IT department into the responsibility of the executive. Any entity not yet registered should remedy this immediately — failure to register is a standalone offence. A working ISO 27001 ISMS is a strong basis but does not replace the specific evidence required. NEOSEC, led by an ISO 27001 Lead Auditor, supports gap analysis, technical measures and the reporting chain — the first step is always a defensible inventory of one's own IT.