# NIS2 in the mid-market: check whether you are in scope, meet the duties, hold the evidence

> Whether your company falls under the new German BSI Act, which duties follow, how risk management, reporting and supply chain are implemented, and what applies personally to management.

URL: https://techport.ai/en/it-beratung/sicherheit-und-resilienz/nis2-und-cybersicherheit

---

1.  [IT Consulting](/en/it-beratung)/
2.  [Security and Resilience](/en/it-beratung/sicherheit-und-resilienz)/
3.  NIS2 and cyber security

[Security and Resilience](/en/it-beratung/sicherheit-und-resilienz) · Focus topic

# NIS2 and cyber security

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

With the German NIS2 implementation act, the circle of companies obliged to manage cyber security has widened considerably. It is no longer only operators of critical infrastructure but many mid-sized companies from sectors such as manufacturing, logistics, waste management, food, chemicals, mechanical engineering and digital services, generally from fifty employees or from ten million euros in turnover and balance sheet total.

The obligation applies whether or not a company has registered, and it applies to management personally. Anyone who has not checked whether they are in scope has not established that they are out of it.

## How you notice it

*   It is unclear whether the company falls under the new duties and there is no documented assessment.
*   Customers ask for evidence of information security as part of their own supply chain obligations.
*   Security measures exist but there is no documentation that would stand up to an audit.
*   Nobody knows who reports a significant incident within twenty-four hours.

## Why this happens

The requirements are new, they sit in an act that is not self-explanatory, and the allocation to a sector is not obvious in individual cases. Many companies therefore wait for a notification that never comes: the classification is a self-assessment. On top of that, security in the mid-market was long treated as a technical task for IT, whereas the act assigns it explicitly to management, including duties to supervise and to be trained.

## How we go about it

1.  **Check scope on the record.** We check on the basis of sector, activity, headcount and turnover whether your company counts as an essential or an important entity, and record the result with reasoning. A negative result belongs documented too.
2.  **Establish the gaps against the duties.** We compare your current state with the required risk management measures: risk analysis, incident handling, business continuity, supply chain, access control, cryptography, training, effectiveness review. The result is a prioritised list of measures with effort.
3.  **Deliver and make it evidenced.** We implement the measures and make sure each one produces evidence: a policy, a log, a test report, a training record. What is not documented counts as absent in an audit.
4.  **Set up reporting and registration.** We establish the reporting route to the German Federal Office for Information Security, with responsibilities, templates and deadlines, and rehearse it. Registration and reporting must not depend on who happens to be in the building.

## What you gain

*   A solid statement about whether and how you are in scope.
*   Evidence you can present to customers and authorities.
*   A security posture that not only meets the duty but actually lowers the risk.

## From our projects

Most companies underestimate the supply chain. Even those not in scope themselves receive the requirements via customers, because companies in scope have to include the security of their suppliers in their risk management. In practice that means questionnaires, evidence and sometimes contract clauses. Those who are prepared answer in days, those who are not answer in weeks, and in case of doubt that decides a contract. The second recurring finding concerns documentation: almost all companies already do more for their security than they can demonstrate. The first step is therefore often not a technical one but writing down what already happens.

## Good to know

The German NIS2 implementation act came into force on 6 December 2025. The duties have applied directly since then to companies meeting the thresholds, irrespective of registration. The registration portal of the Federal Office for Information Security has been available since January 2026, the regular deadline has passed, and the obligation to register remains. Central are the risk management measures under Section 30 BSIG, the reporting duties under Section 32 BSIG with an initial report within twenty-four hours, a follow-up report after seventy-two hours and a final report after one month, and the registration duty under Section 33 BSIG. Management must approve the measures and supervise their implementation, is obliged to undergo training and is liable for breaches. That responsibility cannot be delegated, the execution can.

## Häufige Fragen

How do we find out whether we are in scope?

Through three questions: does your activity fall under one of the sectors listed in the annexes to the BSI Act, do you meet the thresholds for headcount or for turnover and balance sheet total, and are there special rules for your industry. The classification is a self-assessment by the company. It should exist in writing, with a date and reasoning, and be reviewed when you grow or change your business.

Is an ISO 27001 certification sufficient?

It covers a large part of the required measures and makes evidence considerably easier, but it does not replace the statutory assessment. Reporting and registration duties in particular, and the duties of management, have to be met in their own right. Conversely a certification is not a precondition: an appropriate management system without a certificate can meet the requirements if it is documented and effective.

## Let us talk about NIS2 and cyber security

In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

[Arrange an initial call](/en/kontakt)[Our consulting](/en/so-funktionierts)

## Further reading

[Security and ResilienceBuilding information securityAn information security management system that fits your size: scope, risks, policies, evidence and the route to certification when customers require it.](/en/it-beratung/sicherheit-und-resilienz/isms-und-zertifizierung)[Security and ResilienceEmergency management and recoveryWhat happens when IT stops: determine critical processes and time targets, write the emergency plan, rehearse recovery, settle crisis communication and learn from exercises.](/en/it-beratung/sicherheit-und-resilienz/notfallmanagement)[IT Governance and ComplianceIT obligations at a glanceWhich IT related obligations affect your company, who owns them, which evidence is needed and how a register of obligations gets you prepared for every audit.](/en/it-beratung/it-governance-und-recht/it-compliance)[KnowledgeIT regulatory radarWhat applies, what is coming, what to do now.](/en/it-beratung/regulatorik-radar)[KnowledgeIT maturity checkKnow where your IT stands in ten minutes.](/en/it-beratung/reifegrad-check)

Back to the field [Security and Resilience](/en/it-beratung/sicherheit-und-resilienz)

## Sources

*   [Section 30 BSIG, risk management measures (in German)](https://www.gesetze-im-internet.de/bsig_2025/__30.html)
*   [Section 32 BSIG, reporting duties (in German)](https://www.gesetze-im-internet.de/bsig_2025/__32.html)
*   [Section 33 BSIG, registration duty (in German)](https://www.gesetze-im-internet.de/bsig_2025/__33.html)
*   [NIS-2 regulation, German Federal Office for Information Security](https://www.bsi.bund.de/dok/nis-2-regulierung)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

This page reflects the position at the date given and does not replace legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
