Data Protection & Information Security
6 Mar 2026

NIS-2: Which companies are affected – assessment in 5 steps

Luca Blöcher
Reading time:
9
minutes
Managing director and IT manager check NIS-2 applicability on a laptop
Table of contents

NIS-2: Is your company affected? The short answer

Companies are affected by NIS-2 if they operate in one of the sectors listed in the BSI Act (BSIG) (Annexes 1 and 2) and reach the size thresholds under Section 28 BSIG – they are then considered an important or particularly important entity. The decisive law is the NIS-2 implementation act (NIS2UmsuCG, BGBl. 2025 I no. 301), which amended the BSIG and has been in force since December 6, 2025 without a transition period. The BSI thus supervises around 29,500 entities instead of around 4,500 previously.

Unlike under the earlier KRITIS (critical infrastructure) regulation, what matters is no longer exceeding facility thresholds but primarily sector and company size. Limit: Classification is carried out by statutory self-identification – the free BSI applicability check only provides a non-binding initial assessment and is not legally binding. The Data Protection & Information Security category offers a more in-depth classification of the topic area.

Which sectors does NIS-2 cover? Annex 1 and Annex 2 BSIG

The scope is tied to two sector lists in the BSIG. Annex 1 covers the sectors of high criticality, from which entities of corresponding size are as a rule classified as a particularly important entity. Annex 2 lists further critical sectors, which predominantly lead to important entities. A company's assignment depends on its actual activity, not on its self-description or its entry in the commercial register.

The sectors in Annex 1 include, in particular, energy, transport, banking and financial market infrastructures, healthcare, drinking water and wastewater, digital infrastructure, ICT service management (business-to-business), and parts of public administration and space. Annex 2 adds sectors such as postal and courier services, waste management, the production, manufacture, and trade of chemical substances, the production and distribution of food, manufacturing (for example medical devices, data processing equipment, mechanical engineering, motor vehicles), providers of digital services, and research institutions.

Assumption: These sector lists are summarized here by way of example; the complete and legally binding enumeration – including the precisely defined subgroups and types of entity in each case – follows exclusively from Annexes 1 and 2 of the BSIG. Anyone who can be assigned to a listed sector should check the size threshold in the next step.

Check applicability in 5 steps (checklist)

The following five steps replicate the assessment logic of Section 28 BSIG. As a rule, it is only the combination of sector affiliation and size threshold (the so-called size cap) that establishes applicability.

  1. Check the sector (Annexes 1 and 2 BSIG): Does your activity belong to one of the listed sectors – for example energy, transport, banking, health, drinking water, digital infrastructure, public administration (Annex 1) or postal/courier, waste, chemicals, food, manufacturing, digital services, research (Annex 2)? If not, you are not affected via the standard mechanism.
  2. Determine company size: Determine the number of employees, annual turnover, and annual balance sheet total. Linked and partner enterprises must be taken into account in the calculation in accordance with the principles of the EU SME definition; the individual legal entity alone is not decisive.
  3. Apply the size threshold under Section 28 BSIG (size cap): Important entity: from 50 employees or more than 10 million euros in annual turnover and balance sheet total. Particularly important entity: from 250 employees or more than 50 million euros in turnover and more than 43 million euros in balance sheet total (based on the EU SME definition).
  4. Assign the category: Classify yourself as an "important" or "particularly important entity" (Sections 28 and 29 BSIG). Important: Operators of critical facilities (KRITIS) are automatically considered particularly important entities – regardless of the size step.
  5. Check size-independent special cases: Qualified trust service providers, top-level domain name registries, and DNS service providers fall under the BSIG regardless of their size. Certain entities of the federal administration are also covered.

Limit/exception: The thresholds under Section 28 BSIG are presented here in simplified form; industry-specific particularities apply in individual cases. The wording of the law is always authoritative, not this checklist.

Important vs. particularly important entity: the difference

The BSIG distinguishes two categories of affected companies: particularly important entities and important entities. Both are subject to the same basic obligations – the difference lies in supervision and the sanctions framework.

FeatureImportant entityParticularly important entity
Size threshold (Section 28 BSIG)from 50 employees or >10 million euros turnover and balance sheet totalfrom 250 employees or >50 million euros turnover and >43 million euros balance sheet total
Supervisionevent-drivenproactive, even without a specific reason
Range of fineslower rangeup to 10 million euros or 2% of worldwide annual turnover
KRITIS operators–always particularly important

Particularly important entities are subject to proactive supervision (the BSI can also carry out checks without a specific reason) and the higher range of fines. Important entities are in principle supervised on an event-driven basis, i.e., in particular following indications or incidents. KRITIS operators are always particularly important entities.

Limit/exception: The category does not change anything about the obligation itself – important entities, too, must register, report incidents, and implement risk management. Differences primarily concern the depth of supervision and the maximum fine.

In practice, the classification is relevant above all for dealing with the supervisory authority: particularly important entities must expect the BSI to carry out checks even without a specific reason, for example through on-site inspections or requests for evidence. Although important entities are as a rule only inspected after an indication or incident, this does not relieve them of the substantive obligations. For both categories, it is advisable to document the implementation of the measures in such a way that it can be proven in the event of an inspection.

Which obligations apply to affected companies?

Affected companies are subject to three core obligations: registration with the BSI, reporting of significant security incidents, and implementation of risk management measures. These have applied since entry into force – without a grace or transition period.

Registration with the BSI

Registration takes place in two stages: first via the administrative platform „Mein Unternehmenskonto“ (MUK), then in the BSI portal activated for this purpose. Entities must provide the information required for contacting them. A deadline of three months applies to registration, starting from the point at which an entity is affected for the first time. Registration is not a formality but a prerequisite for the BSI to be able to send warnings and information to the entity in a targeted way. Because the deadline is linked to first-time applicability and not to a request from the authority, companies should document their self-identification early and record in a traceable way on what basis they assigned themselves to a category.

Reporting significant security incidents

Significant security incidents must be reported in stages under Section 32 BSIG. The staggering follows three stages:

  • Initial report within 24 hours: immediate early warning after becoming aware of the significant incident, where applicable with an indication of a suspected unlawful or malicious background.
  • Report within 72 hours: confirmation or update of the initial report with an initial assessment of the incident, including severity, impact, and – where available – indicators of compromise.
  • Final report no later than one month after the 72-hour report: detailed description of the incident, its cause, the remedial measures taken, and the cross-border impact.

An incident is significant, among other things, if it can cause serious operational disruption or financial losses or can affect other natural or legal persons by causing considerable material or non-material damage. The report does not replace other notification or information obligations, for example under data protection law: if an incident also affects the security of personal data, reporting obligations under the General Data Protection Regulation (GDPR) may apply in addition. Both regimes must be examined separately and do not exclude each other. For timely reporting, it is crucial in practice to document the time of becoming aware cleanly, as the 24-hour deadline is linked to this moment.

Risk management measures under Section 30 BSIG

At the core of the obligations is a catalog of at least ten technical and organizational areas of measures under Section 30 BSIG. Affected entities must cover these areas in line with the state of the art and a cross-hazard ("all-hazards") approach:

  • Concepts for risk analysis and for security in information technology
  • Handling of security incidents (incident response)
  • Maintaining operations, for example backup management, disaster recovery, and crisis management (business continuity)
  • Supply chain security, including relationships with suppliers and service providers
  • Security in the acquisition, development, and maintenance of information technology systems
  • Concepts and procedures for assessing the effectiveness of the risk management measures
  • Basic cyber hygiene practices and IT security training
  • Concepts and procedures for the use of cryptography and encryption
  • Personnel security, concepts for access control, and the management of facilities (assets)
  • Use of multi-factor authentication as well as secured voice, video, and text communication and secured emergency communication

Limit/exception: The scope of the measures must be determined proportionately – according to risk exposure, the size of the entity, implementation costs, and the probability of occurrence and severity of possible incidents. However, "proportionate" does not mean "optional": the ten areas of measures in Section 30 BSIG are mandatory in principle.

Management held liable: sanctions for violations

Management bears personal responsibility for implementing and monitoring the risk management measures (Section 38 BSIG). It must approve the measures, monitor their implementation, and take part in corresponding training – and is liable for culpable breaches of duty under the rules applicable to the respective legal form. Responsibility can be delegated organizationally, but the supervisory and monitoring duty of the management level remains.

Violations can result in considerable fines. For particularly important entities, the NIS-2 Directive provides for maximum amounts of up to 10 million euros or 2% of worldwide annual turnover (whichever is higher), transposed nationally in Section 65 BSIG; for important entities, the range is lower. In addition to the fine, the BSI can issue further orders as part of its supervision and enforce the implementation of the obligations. In practice, this means: involving the management level is not only a question of liability but also of internal governance – budget, responsibilities, and evidence should be anchored at management level and reviewed regularly.

Limit/exception: The exact amount and enforcement of sanctions depend on the individual case and the severity of the violation; the definition of significant incidents is continuously being specified in more detail by the BSI.

What affected companies should tackle now

Since no transition period applies, a structured approach makes sense. The following steps are to be understood as organizational guidance and do not replace an examination of the individual case:

  • Clarify and document applicability: record sector assignment and size threshold under Section 28 BSIG in a traceable way, include linked enterprises, and justify the classification as an important or particularly important entity.
  • Prepare registration on time: set up access via „Mein Unternehmenskonto“ and the BSI portal and keep an eye on the three-month deadline.
  • Gap analysis for risk management: compare the current status against the ten areas of measures in Section 30 BSIG and prioritize gaps.
  • Establish a reporting process: define internal procedures for the 24-hour, 72-hour, and final report under Section 32 BSIG, including responsibilities and availability.
  • Anchor training and awareness: cyber hygiene and awareness are expressly part of the catalog of measures – management, too, is obliged to take part in training under Section 38 BSIG.

Limit/exception: This list is general guidance, not an exhaustive implementation guide. Order, depth, and prioritization depend on the sector, size, and risk exposure of the respective entity.

Methodology & timeliness

This article evaluates primary sources exclusively: the NIS-2 implementation act (NIS2UmsuCG) as promulgated in BGBl. 2025 I no. 301, the amended provisions of the BSIG (in particular Sections 28, 29, 30, 32, 38, and 65), and the official information from the BSI. The figure of around 29,500 supervised entities and the entry into force on December 6, 2025 without a transition period come from the BSI press release of December 5, 2025. Assumption: The sector lists (Annexes 1 and 2) are summarized here by way of example – the complete enumeration follows from the annexes of the BSIG. As of 2 Jun 2026.

FAQ

Since when has NIS-2 applied in Germany?

NIS-2 has applied in Germany since December 6, 2025. On that day, the NIS-2 implementation act (NIS2UmsuCG) entered into force, promulgated on December 5, 2025 in BGBl. 2025 I no. 301. It amends the BSI Act. There is no transition period – the obligations apply immediately to all affected entities.

How many companies are affected by NIS-2?

According to the BSI's estimate, around 29,500 entities are affected. Previously, the BSI Act regulated only around 4,500 organizations, primarily KRITIS operators and providers of digital services. NIS-2 significantly expanded the scope: what matters now is sector affiliation under Annexes 1 and 2 BSIG as well as the size thresholds under Section 28 BSIG. Affected entities must register with the BSI.

From what company size does NIS-2 apply?

Companies from listed sectors are considered important entities from 50 employees or more than 10 million euros in turnover and balance sheet total. They are considered particularly important entities from 250 employees or more than 50 million euros in turnover and more than 43 million euros in balance sheet total (Section 28 BSIG). The wording of the law is always authoritative.

Is my company automatically exempt below the thresholds?

Not necessarily. Qualified trust service providers, top-level domain name registries, and DNS service providers fall under the BSIG regardless of their size. Operators of critical facilities (KRITIS) are also affected regardless of the size cap and are automatically considered particularly important entities. Anyone who is affected must register, report incidents, and implement risk management. The wording of the law is always authoritative, not a simplified checklist.

Which obligations must an affected company fulfill?

Affected companies must register with the BSI (within three months), report significant security incidents (24 hours initial report, 72 hours report, final report no later than one month after the 72-hour report), and implement risk management measures under Section 30 BSIG. These include, among other things, training, incident response, and multi-factor authentication.

Is management personally liable?

Yes. Under Section 38 BSIG, management must approve the risk management measures, monitor their implementation, and take part in training. In the event of culpable breaches of duty, it is liable under the rules applicable to the legal form. In addition, the entity faces fines – for particularly important entities, up to 10 million euros or 2% of worldwide annual turnover.

Sources

More blog posts

Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.

Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.