Introduction
The NIS2 Directive marks the next major step in Europe's cyber and IT security regime. It affects not only large enterprises and critical infrastructure but also many mid-sized companies and digital service providers.
With the NIS2 Implementation and Cybersecurity Act, passed by the Bundestag on November 13, 2025, the EU requirements have now been transposed into binding German law. The Federal Office for Information Security (BSI) had previously issued an extensive position paper that provided important input for shaping the law — even though not all its demands made it into the final legislation.
2026 is therefore clearly the year of implementation: companies must adapt their processes, structures, and security architecture to the new requirements. How can this be done efficiently? Which obligations are now legally binding? And which BSI recommendations remain relevant?
What Is the NIS2 Directive?
The NIS2 Directive (EU) 2022/2555 is the central EU law on cybersecurity, replacing the earlier NIS Directive from 2016. It sets binding standards for how companies and public institutions must protect their IT systems, assess risks, and report security incidents. The goal is to significantly increase digital resilience across Europe — so that critical infrastructure, digital services, and supply chains remain operational even in a crisis.
With the new NIS2UmsuCG, the rules are now legally binding in Germany.
The BSI is granted additional supervisory and enforcement powers to monitor companies and sanction violations.
The directive applies to "essential" and "important" entities — including energy, health, transport, digital services, cloud providers, postal services, finance, waste management, public administration, and other sectors.
What's Changing Now
Cybersecurity is no longer just an IT department's job — it is now a legally mandated leadership and management responsibility.
With the NIS2UmsuCG now in force, minimum standards, reporting obligations, technical requirements, and supervisory powers have been established.
Before the law was passed, the BSI made clear in its position paper how important strong legislation is for national resilience. Many of these demands were incorporated into the final law.
Companies must now:
- Systematically assess risks
- Report incidents within the required deadlines
- Demonstrate governance structures
- Document technical and organizational measures
- More closely vet their supply chains
The transition period is short — which is why the rule now is: implementation is mandatory, not optional preparation.
Specific Obligations for Companies
a) Scope & Classification
Check whether your company qualifies as "essential" or "important" under the new law — a classification defined by sector, size, interconnectivity, and market role.
Suppliers, IT service providers, and EU subsidiaries may also be affected.
b) Reporting and Documentation Obligations
The law prescribes fixed deadlines:
- 24 hours: Early warning
- 72 hours: Incident report
- 30 days: Final report
Companies must fully document all security measures, audit logs, risk analyses, and incident processes.
c) Governance & Responsibility
Management and supervisory bodies bear direct liability for cybersecurity.
Their obligations include:
- Security strategy
- Training
- Risk assessments
- Regular reviews
- Establishing clear roles and escalation paths
d) Technical Requirements & Supply Chain
Mandatory measures are based on, among other things, ISO 27001 and BSI Grundschutz:
- Monitoring & detection
- Network segmentation
- Backup & recovery
- Patch management
- Vendor assessment and due diligence
The Most Important BSI Demands at a Glance
The following points come from the BSI's position paper (October 10, 2025). Some were incorporated into the law, while others serve as technical guidance:
- "Federal CISO" — central security officer for federal administration
- Expanded technical powers for resilience scans, C2 tracking, and warning notices
- Improved botnet and phishing defense
- Stronger BSI role in the energy sector
- Legal certainty for SMEs (clear definition of thresholds)
- Building an expanded cyber sensor network & data base
- Enshrining the CVD process in law — protection for security research
- National resilience program "CyberGovSecure"
These demands have not been fully enacted into law, but they offer important guidance for a robust security strategy.
Practical Steps for Implementation
| Phase | Measure | Goal |
|---|---|---|
| 1. Analysis | Review scope, assess risks, analyze the supply chain | Create an overview |
| 2. Strategy | Define governance framework, responsibilities, and policies | Clear responsibilities |
| 3. Implementation | Establish security policies, controls, and monitoring | Ensure compliance |
| 4. Automation | Use tools for documentation, reporting, and monitoring | Make processes efficient |
| 5. Training | Raise awareness among C-level executives & employees | Strengthen security culture |
Common Mistakes and How to Avoid Them
- Unclear responsibilities
- Missing or incorrect scope analysis
- Insufficient preparation for 24/7 reporting obligations
- Gaps in supply chain documentation
- One-off instead of continuous security measures
- Missing management training despite liability risk
Continuous Compliance Through Automation
NIS2 requires ongoing assessment, documentation, and improvement of your security posture.
With heyData, you can:
- Audit
- Personal consultation
- Employee training
- Vendor Risk Management
- Complete documentation
This way, compliance is achieved without overhead — and stays continuously up to date.
Looking Ahead: 2026 and Beyond
With NIS2, a new phase of regulated IT security begins in Europe. Other regulations such as the EU AI Act, CSRD, or Switzerland's nFADP follow the same pattern: automated, integrated compliance is becoming the standard.
Companies that invest in cybersecurity and governance now will strengthen their long-term resilience and competitiveness.
Conclusion
The NIS2 Directive makes cybersecurity a binding management obligation. The new German law sets clear standards, mandatory reporting deadlines, and comprehensive requirements for governance, technology, and documentation.
Digital, automated solutions like heyData can reduce the workload involved — while significantly strengthening your ability to demonstrate compliance to authorities, partners, and customers.
FAQ
Are we even affected by NIS2?
Are we even affected by NIS2?
NIS2 applies to companies in critical and important sectors above a certain size — and its scope is broader than many think. In the quick check, heyData clarifies whether and how NIS2 applies to you, and shows which measures are specifically required.
By when do the EU member states have to transpose NIS2 into national law?
By when do the EU member states have to transpose NIS2 into national law?
The EU member states must transpose the NIS2 Directive into national law by October 17, 2024.
What's the main difference between NIS1 and NIS2?
What's the main difference between NIS1 and NIS2?
NIS2 expands the scope to more sectors and smaller organizations and introduces stricter requirements as well as faster reporting obligations.







