Act Statutory · EU, Germany
Directive on measures for a high common level of cybersecurity across the Union (NIS2).
The NIS2 Directive (Directive (EU) 2022/2555) obliges operators in critical and important sectors to manage risk and report significant security incidents. As an EU directive, it does not have direct effect but works via national transposition laws - in Germany via the NIS2 Implementation Act (NIS2UmsuCG), in force since 6 December 2025. NIS2 affects Swiss companies via an EU establishment, via the representative obligation for certain digital services under Art. 26, or because EU customers must demonstrate their supply chain security and pass this requirement on.
01 Triggers
When does NIS2 apply to you?
NIS2 may apply to you if one of these triggers applies. The Regulatory Check tests them against your details. Triggers marked “only together with industry or activity” only count if a trigger on industry or activity applies at the same time.
- Activity: Critical infrastructure (Likely applies): You state that you operate critical infrastructure - the NIS2 sector lists in Annex I (including energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space) and Annex II (including postal/courier services, waste management, chemicals, food, manufacturing, digital services, research) are a strong indication that NIS2 is relevant to you.
- Industry: Energy (Likely applies): Energy supply is one of the eleven sectors of high criticality in Annex I of the NIS2 Directive - as an operator in this sector, NIS2 checks whether you reach the size threshold for 'important' or 'essential' entities.
- Industry: Software / SaaS (Recommend individual review): Digital infrastructure and certain digital services (cloud, data centres, managed services, online marketplaces, search engines, social networks) fall under Annex I or II of the NIS2 Directive - whether your specific offering is covered depends on the exact type of service.
- Employees: from 50 (applies if additionally: Industry: Energy, Software / SaaS) (Recommend individual review): From around 50 employees and the associated revenue or balance-sheet thresholds, companies in the NIS2 sectors generally count as an 'important entity' - what additionally matters is whether your activity is assigned to a sector under Annex I or II at all. Outside these sectors, the number of employees alone does not trigger NIS2.
- Markets: EU (only together with industry or activity) (Recommend individual review): If, as a provider of certain digital services (e.g. DNS, cloud, data centre, content delivery, managed service or managed security service, online marketplace, search engine, social network), you offer your services in the EU without being established there, you must appoint a representative in an EU member state under Art. 26(3) NIS2.
Exceptions
- Micro and small enterprises (below the thresholds for medium-sized enterprises under Recommendation 2003/361/EC) generally do not fall under NIS2 - unless they belong to the exemptions from the size rule named in Art. 2(2) NIS2 (including providers of public electronic communications networks/services, trust service providers, TLD name registries and DNS service providers, sole providers of a service important to society in a member state, certain public administration bodies, entities identified as critical under the CER Directive (EU) 2022/2557).
- Member states can additionally extend the scope to local administrative units and certain educational institutions with critical research activity.
02 Obligations
What does NIS2 require?
- Implement state-of-the-art cybersecurity risk management measures, at minimum: risk analysis/security policy, incident handling, business continuity/backup/disaster recovery/crisis management, supply chain security, security in system acquisition/development/maintenance including vulnerability management, assessment of the effectiveness of measures, cyber hygiene and training, cryptography/encryption policy, personnel security/access control/asset management, multi-factor authentication (Art. 21(2) NIS2).
- Take into account security in the supply chain, including relationships with direct suppliers and service providers (Art. 21(3) NIS2).
- Report significant security incidents to the competent authority: early warning within 24 hours, notification within 72 hours, final report within one month (in Germany, to the BSI).
- In Germany: register as a NIS2 company via 'Mein Unternehmenskonto' and the BSI portal.
- Where Art. 26(3) applies: appoint in writing a representative in a member state where the services are offered.
03 Evidence
What evidence is needed?
- Documented risk management framework under Art. 21(2).
- Evidence of registration (in Germany: the BSI portal).
- Reporting logs for security incidents.
- Supply chain assessment of security-relevant suppliers and service providers.
- Evidence of the representative appointment under Art. 26(3), where applicable.
04 Deadlines
Which deadlines apply?
- Deadline for transposing the NIS2 Directive into national law (Art. 41 NIS2) - missed by several member states, including Germany.
- The German NIS2 Implementation Act (NIS2UmsuCG) enters into force.
- The BSI portal for NIS2 registration goes live.
Information as of: 24 September 2026. Past dates are grey, upcoming ones highlighted (as of when the page was built).
05 Penalties
What are the consequences of violations?
Under Art. 34 NIS2, the fine ranges for 'essential entities' must be at least EUR 10 million or 2% of worldwide annual turnover (whichever is higher), and for 'important entities' at least EUR 7 million or 1.4% of worldwide annual turnover. The specific implementation and fine amount is governed by national law, in Germany by the NIS2 Implementation Act.
06 Related
What is connected with it?
- Reporting obligation for cyberattacks on critical infrastructure (Information Security Act, ISG): Since 1 April 2025, the authorities and organisations individually listed in Art.
- ICT Minimum Standard under the Electricity Supply Ordinance (StromVV, Art. 5a): Since 1 July 2024, the recommendations of the Minimum Standard for Improving ICT Resilience (ICT Minimum Standard, May 2023 edition) have been binding, per the respective protection level under Annex 1a, under Art.
07 Open
What is still uncertain?
- The EUR-Lex primary text of Directive (EU) 2022/2555 was not retrievable in this session (empty/blocked response across several URL forms); article texts were verified via the secondary source nis-2-directive.com and sector lists via buzer.de, not via the Official Journal itself.
- The exact revenue/balance-sheet thresholds for 'essential' (per secondary sources approx. ≥250 employees or >EUR 50 million turnover or >EUR 43 million balance sheet total) and 'important' entities (approx. ≥50 employees or >EUR 10 million turnover/balance sheet total) were not verified directly against Art. 2 NIS2 or the underlying Recommendation 2003/361/EC.
- The German reporting deadlines (24h/72h/1 month) are the NIS2 reference values; the exact design in the German NIS2UmsuCG statutory text was not checked in full text.
08 Sources
Sources
Information as of: 24 September 2026.
- NIS-2-Umsetzungsgesetz ab morgen in Kraft (Pressemitteilung), Bundesamt für Sicherheit in der Informationstechnik (BSI), retrieved on 24 September 2026
- NIS 2 Directive, Article 21: Cybersecurity risk-management measures (Wortlaut-Spiegel), nis-2-directive.com, retrieved on 24 September 2026
- NIS 2 Directive, Article 26: Jurisdiction and territoriality (Wortlaut-Spiegel), nis-2-directive.com, retrieved on 24 September 2026
- NIS 2 Directive, Article 2: Scope (Wortlaut-Spiegel), nis-2-directive.com, retrieved on 24 September 2026
- NIS 2 Directive, Article 34: Administrative fines (Wortlaut-Spiegel), nis-2-directive.com, retrieved on 24 September 2026
- Sektoren mit hoher Kritikalität – Anhang I NIS2, buzer.de, retrieved on 24 September 2026
- Sonstige kritische Sektoren – Anhang II NIS2, buzer.de, retrieved on 24 September 2026
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
FAQ Answers
Questions about NIS2.
Does a Swiss company without an EU establishment have to implement NIS2 directly?
Only directly if it offers one of the digital services named in Art. 26(1)(b) (e.g. DNS, cloud, data centre, content delivery network, managed service/managed security service, online marketplace, search engine, social network) in the EU and must appoint a representative for that. Otherwise, NIS2 usually affects Swiss companies indirectly - via an EU establishment or via supply chain requirements from EU customers.
What is the difference between 'essential' and 'important' entities?
The classification depends on sector and size: in particularly critical sectors (Annex I), large companies generally count as an 'essential entity', medium-sized companies in Annex I or Annex II sectors generally as an 'important entity'. The same risk management and reporting obligations apply to both categories, but with different supervisory intensity and fine ranges.
Does NIS2 apply uniformly across the EU?
No. NIS2 is a directive and must be transposed into national law by each member state; details on sector demarcation, reporting deadlines and supervision can vary nationally. This file primarily covers the German transposition (NIS2UmsuCG).
Does NIS2 apply to you?
The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.
