Since December 6, 2025, Germany's NIS2 implementation law has been in force — with no grace period. Roughly 29,500 companies now fall under the supervision of the BSI (Germany's federal cybersecurity agency), up from around 4,500 before. The BSI registration deadline already passed on March 6, 2026. If you assumed this only applies to energy providers and hospitals, this article is worth reading carefully.

Who Is Actually Covered?

NIS2 significantly widens the circle of regulated companies. It no longer just covers classic critical-infrastructure operators, but "essential" and "important" entities across 18 sectors — from manufacturing and food production to pharmaceuticals, logistics, and digital services. Classification largely depends on company size: companies with 50+ employees or €10 million+ in annual revenue can be covered, regardless of industry. Market observations suggest close to half of affected companies currently underestimate whether they're covered at all.

What the Law Actually Requires

The NIS2 implementation law was structured as an amendment to Germany's BSI Act. Five provisions matter most in practice:

  • § 28 — defines who qualifies as a covered entity
  • § 30 — requires "appropriate, effective, and proportionate" technical and organizational risk-management measures reflecting the state of the art
  • § 32 — sets out incident reporting obligations
  • § 38 — anchors personal obligations for company management
  • § 65 — sets fines of up to €10 million or 2% of global annual revenue
What matters now isn't whether "something is being done," but whether your measures, processes, and investments can be measured against the statutory checklist of obligations.

Why This Is Now a Board-Level Issue

Section 38 stands out in particular: responsibility for cybersecurity measures now explicitly sits with company management — it can't simply be delegated to the IT department. That's a genuine cultural shift: cybersecurity moves from a technical matter to a compliance obligation with personal accountability at the leadership level.

What to Do Now

If you haven't yet checked whether your company is covered, do it soon — the registration obligation applies regardless of whether the deadline has already passed. In practice, NIS2 compliance usually means building a structured information security management system (ISMS), often aligned with ISO 27001. A penetration test is a recognized building block for demonstrating and documenting the required "effectiveness" of technical measures — not as a one-off exercise, but as a recurring part of risk management.

Conclusion

NIS2 isn't something you can wait out anymore. With no grace period, if you're covered, you're covered now. The sensible first step is a sober assessment: am I actually affected, and if so, where do I stand relative to the statutory minimum requirements?