Security and Resilience · Focus topic
NIS2 and cyber security
By Redaktion techport.ai, IT-Beratung · Last updated on
With the German NIS2 implementation act, the circle of companies obliged to manage cyber security has widened considerably. It is no longer only operators of critical infrastructure but many mid-sized companies from sectors such as manufacturing, logistics, waste management, food, chemicals, mechanical engineering and digital services, generally from fifty employees or from ten million euros in turnover and balance sheet total.
The obligation applies whether or not a company has registered, and it applies to management personally. Anyone who has not checked whether they are in scope has not established that they are out of it.
How you notice it
- It is unclear whether the company falls under the new duties and there is no documented assessment.
- Customers ask for evidence of information security as part of their own supply chain obligations.
- Security measures exist but there is no documentation that would stand up to an audit.
- Nobody knows who reports a significant incident within twenty-four hours.
Why this happens
The requirements are new, they sit in an act that is not self-explanatory, and the allocation to a sector is not obvious in individual cases. Many companies therefore wait for a notification that never comes: the classification is a self-assessment. On top of that, security in the mid-market was long treated as a technical task for IT, whereas the act assigns it explicitly to management, including duties to supervise and to be trained.
How we go about it
- Check scope on the record. We check on the basis of sector, activity, headcount and turnover whether your company counts as an essential or an important entity, and record the result with reasoning. A negative result belongs documented too.
- Establish the gaps against the duties. We compare your current state with the required risk management measures: risk analysis, incident handling, business continuity, supply chain, access control, cryptography, training, effectiveness review. The result is a prioritised list of measures with effort.
- Deliver and make it evidenced. We implement the measures and make sure each one produces evidence: a policy, a log, a test report, a training record. What is not documented counts as absent in an audit.
- Set up reporting and registration. We establish the reporting route to the German Federal Office for Information Security, with responsibilities, templates and deadlines, and rehearse it. Registration and reporting must not depend on who happens to be in the building.
What you gain
- A solid statement about whether and how you are in scope.
- Evidence you can present to customers and authorities.
- A security posture that not only meets the duty but actually lowers the risk.
From our projects
Most companies underestimate the supply chain. Even those not in scope themselves receive the requirements via customers, because companies in scope have to include the security of their suppliers in their risk management. In practice that means questionnaires, evidence and sometimes contract clauses. Those who are prepared answer in days, those who are not answer in weeks, and in case of doubt that decides a contract. The second recurring finding concerns documentation: almost all companies already do more for their security than they can demonstrate. The first step is therefore often not a technical one but writing down what already happens.
Good to know
The German NIS2 implementation act came into force on 6 December 2025. The duties have applied directly since then to companies meeting the thresholds, irrespective of registration. The registration portal of the Federal Office for Information Security has been available since January 2026, the regular deadline has passed, and the obligation to register remains. Central are the risk management measures under Section 30 BSIG, the reporting duties under Section 32 BSIG with an initial report within twenty-four hours, a follow-up report after seventy-two hours and a final report after one month, and the registration duty under Section 33 BSIG. Management must approve the measures and supervise their implementation, is obliged to undergo training and is liable for breaches. That responsibility cannot be delegated, the execution can.
Häufige Fragen
How do we find out whether we are in scope?
Through three questions: does your activity fall under one of the sectors listed in the annexes to the BSI Act, do you meet the thresholds for headcount or for turnover and balance sheet total, and are there special rules for your industry. The classification is a self-assessment by the company. It should exist in writing, with a date and reasoning, and be reviewed when you grow or change your business.
Is an ISO 27001 certification sufficient?
It covers a large part of the required measures and makes evidence considerably easier, but it does not replace the statutory assessment. Reporting and registration duties in particular, and the duties of management, have to be met in their own right. Conversely a certification is not a precondition: an appropriate management system without a certificate can meet the requirements if it is documented and effective.
Let us talk about NIS2 and cyber security
In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.
Further reading
Back to the field Security and Resilience