NIS2 requirements for companies: These 5 specific points are mandatory

- Expanded scope – NIS2 now also applies to medium-sized and large companies in critical sectors. Approximately 29,500 companies in Germany are affected.
- Stricter security requirements – Risk management, protective measures, and reporting obligations are mandatory.
- Supply chain security – Companies are liable for the IT security of their service providers.
- Employee training – Raising awareness of cyber risks is essential. Mandatory management training in accordance with NIS2.
- Heavy penalties – The BSI monitors compliance, and violations are costly. The law has been in effect since December 6, 2025 – with no transition period.
Why do companies need to address NIS2 requirements?
The NIS2 Directive and its national implementation promote the cyber resilience of European companies and institutions facing increasingly complex cyber threats.
The new NIS2 Directive
- expands the scope of the previous NIS1 Directive – while the original directive focused primarily on operators of critical infrastructure, it now also includes medium-sized and large enterprises in various sectors such as digital infrastructure and transport. In Germany, around 29,500 companies are affected – an increase from the previous 4,500 regulated organizations.
- tightens security requirements for affected companies to reduce potential vulnerabilities and better protect data and IT systems from attackers.
Anyone affected by NIS2 should address the new requirements immediately to minimize security risks to internal data and IT systems and avoid sanctions. The German NIS2 implementation act has been in effect since December 6, 2025 – with no transition period. Affected companies must act immediately. The focus should be on the following five key areas of requirements of the NIS2 Directive.
What new requirements does NIS2 impose on companies?
NIS2 requirements concern, on the one hand, the management of cyber risks. On the other hand, the directive requires affected companies to implement targeted security measures . NIS2 does not only set technical requirements; it also demands that organizational processes be adapted and legal aspects be integrated into everyday business operations.
1. Risk management and security measures
To meet NIS2 requirements, companies must first establish systematic risk management . This means that companies must regularly conduct risk analyses and develop security strategies. This helps them identify potential threats at an early stage.
In addition to technical protective measures, such as firewalls, encryption, and access controls, organizational measures also play a crucial role in a security strategy. This includes implementing business continuity management: This ensures that your company can react quickly in the event of a cyberattack and that your teams remain operational.
2. Handling security incidents
The NIS2 directive not only requires companies to detect security incidents early but also to document them thoroughly. Furthermore, it must be ensured that the relevant authorities are informed about specific incidents and attempted attacks within defined deadlines . If companies fail to comply with reporting obligations, they face severe sanctions.
If your company falls victim to a cyberattack, you must not only report it, but also be able to initiate damage mitigation measures and ensure that similar incidents do not recur in the future.
Reporting obligations and regulatory oversight: What you need to watch out for
Security incidents generally do not just harm a single company; they have far-reaching consequences. This is why companies and authorities should view cybersecurity as a collective responsibility . Authorities can help you deal with an attack, and by reporting an incident, you can protect other companies from similar attacks. The Federal Office for Information Security (BSI) acts as the central supervisory authority and point of contact for reports.
3. Supply chain and service provider management
Supply chains are increasingly becoming gateways for cybercriminals , yet few companies keep this risk in mind. NIS2 therefore draws attention to security within the supply chain.
When companies work with external service providers and partners, they must ensure that all stakeholders along the supply chain implement appropriate security measures. This can be achieved through contractual agreements, regular audits, and continuous risk assessments.
4. Training and awareness
Technical protective measures are only effective if everyone in the company knows what to do and why. For this reason, NIS2 requires companies to raise awareness of cybersecurity risksamong their employees.
Regular training can raise awareness of IT security and help establish a security culture that views IT security as a shared responsibility. In such training sessions, your employees will learn, for example, to
- better identify phishing emails,
- use passwords correctly, and
- understand the dangers posed by social engineering attacks.
Particularly important: Mandatory management training in accordance with NIS2. Responsibility for the implementation and monitoring of cybersecurity measures lies with the management – cybersecurity is now firmly a matter for the executive level. In the event of violations, members of the management board can be held personally liable.
5. Authentication and access control
The better your IT systems and data are protected, the harder it is for hackers to access them. An important NIS2 requirement is therefore to implement stricter authentication measures.
In practical terms, this means, for example,
- preventing unauthorized access to systems by using multi-factor authentication.
- establishing clear rules for rights management so that only authorized individuals have access to critical IT systems.
- regularly reviewing and adjusting permissions to avoid vulnerabilities.
Recommended reading: In our magazine, you will find 10 simple measures for better information security.
NIS2 requirements: Checklist for efficient implementation
To ensure your company meets the requirements of the NIS2 directive, various Steps necessary. The following checklist provides an overview of key to-dos regarding NIS2 requirements and shows you how to proceed step by step:
- Check your status: Determine whether your company qualifies as an "essential entity" or an "important entity." Use the Proliance NIS2 check for an initial assessment.
- Register with the BSI: Register immediately via the BSI portal. Essential entities have 3 months (until March 6, 2026), while important entities must register without delay.
- Conduct a gap analysis: Get an overview of the current state of your existing security measures to ensure compliance with NIS2, ISO 27001, and similar standards.
- Perform a risk assessment as the basis for selecting measures: The initial inventory for your NIS2 implementation includes identifying all IT systems, processes, and potential vulnerabilities. A detailed risk analysis helps you define priorities and develop appropriate protective measures.
- Establish a security concept: Based on the risk analysis, companies should develop a comprehensive security concept. This includes implementing clear security policies, integrating measures into existing business processes, and defining responsibilities and resources. A Statement of Applicability (SoA) can be helpful here. It is a component of an Information Security Management System (ISMS) and documents, among other things, which information security measures a company is taking.
- Conduct regular training: To ensure that security, NIS2, and compliance requirements are correctly implemented in your company, your employees must be trained accordingly. Mandatory management training is particularly important in this regard. Knowledge of data protection, information security, and legal cybersecurity requirements is essential for a resilient organization and for teams that actively contribute to identifying, reporting, and combating external threats.
- Establish reporting processes: Set up clear processes for reporting significant security incidents to the BSI (24-hour early warning, 72-hour full report, final report after one month).
- Implement Business Continuity Management (BCM): Ensure that your company remains operational in the event of a cyberattack.
- Document and continuously optimize measures: To respond to new threats and technological developments, all NIS2 and cybersecurity measures should be continuously documented and updated. The SoA simplifies this process. Conduct regular reviews and ensure that all security measures taken are reflected in your documentation.
What are the penalties for non-compliance with NIS2 requirements?
Companies that fail to comply with reporting obligations risk heavy fines and other sanctions. For example, essential entities face fines of up to 10 million euros or 2 percent of their total worldwide annual turnover. Important entities can be fined up to 7 million euros or 1.4 percent of their total worldwide annual turnover.
Furthermore, authorities are permitted to restrict the business operations of companies or sanction the management level. In the event of violations, members of the management board can be held personally liable, especially if they neglect their oversight and implementation duties. In Germany, the Federal Office for Information Security (BSI) oversees the monitoring and enforcement of the directive and acts as the point of contact for incident reporting.
Conclusion: How to master NIS2 requirements successfully and efficiently
The NIS2 Directive brings far-reaching changes for companies in terms of cybersecurity. The German implementation act has been in effect since December 6, 2025 – with no transition period. If your organization is among those affected, you should address the requirements immediately. This allows you to take the necessary stepsto improve your cybersecurity and avoid regulatory penalties. You will also benefit from higher security standards in the long term.
We are happy to support you, today and in operating securely in the future and strengthening your cyber defenses. Use the Proliance NIS2 check for an initial assessment of your current compliance status.
Still have questions? We have the answers.
Most NIS2 obligations are identical for essential and important entities. Differences may exist in the supervisory and enforcement regimes: For important entities, the Federal Office for Information Security (BSI) conducts inspections primarily on an ad-hoc basis following incidents and with justified directives; for essential entities, proactive, incident-independent, and more regular inspections are foreseen. In practice, this often also means stricter supply chain management and generally more in-depth inspections, including on-site audits.
Proportionality applies to risk management. For essential entities, due to higher risk exposure, a stricter assessment and correspondingly more far-reaching measures are expected.
Essentially, the following measures are relevant as a basis for implementing the NIS2 Directive:
- Information Security Management System (ISMS): Implementation and operation of an ISMS according to ISO 27001 or BSI Standard 200-1. Certification is not mandatory, but it increases the evidentiary value, among other things.
- Risk Management: Systematic identification, assessment, and treatment of risks (accept, avoid, reduce) as a continuous process
- IT Security: Operation of IT according to recognized frameworks such as ITIL and security measures such as access controls
- Continuous vulnerability management including regular penetration tests
- Backups: Resilient and recoverable backups as well as mandatory multi-factor authentication for sensitive access
Furthermore, new aspects include reporting obligations, Business Continuity Management, and executive liability.
Currently, a report to the Federal Office for Information Security (BSI) is required within 24 hours of an incident at the latest. However, in critical infrastructure (KRITIS) practice, six hours are considered more appropriate. Companies need clear processes for this and must define what is reported, when, and by whom – including an assessment of legal implications.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













