Knowledge Hub

NIS-2:Telling in 20 minutes whether it applies to you

NIS-2 is a directive, so the rules a German company follows are in the BSIG. No one writes to tell you that you are covered. This guide runs the three-step test: sector, size, exceptions and names the two sector entries people misread most, and covers what registration, the ten measures and the 24/72 hour/one month reporting clock require if you are in.

Louis Sieg

By Louis Sieg

Founder of ReadySecGoISO/IEC 27001 Lead Auditor for UKAS/DAkkS-accredited bodies

6 min read

Ask around your sector and you get plenty of opinions about NIS-2. Ask a specific company whether the law covers them and you usually get a shrug.

The answer is available. It sits in two sector lists, a size test with a trap in it, and a short list of exceptions. Twenty minutes and your last two annual accounts are enough.

The BSI also runs a free self-check that walks the same path, the NIS-2-Betroffenheitsprüfung. Run it alongside this. The BSI says plainly that its result is guidance and has no legal weight.

First, what NIS-2 actually is

NIS-2 is an EU law about keeping important services running when someone attacks them. It replaced a narrower 2016 law and pulled in far more companies.

It is a directive, so it binds no one directly. Each member state writes its own version. Germany's is the NIS2UmsuCG, and its main job was rewriting an existing law, the BSI Act (BSIG). When a German company says NIS-2 applies to them, the rules they follow are in the BSIG.

Nobody tells you that you are covered. The BSI sends no letters. You work it out, register yourself, and keep your reasoning, because the BSI can add you to the register later and ask how you got there.

Step one: find your sector

The BSIG carries two sector lists, Anlage 1 and Anlage 2. Use those if you operate in Germany. The EU directive's annexes are organised differently and every member state wrote its own list, so a group with entities in several countries runs this test once per country.

Anlage 1, where an outage does the most damage: energy, transport, finance and insurance, health, water and wastewater, IT and telecommunications, space.

Anlage 2, the rest: postal and courier services, waste management, chemicals, food, manufacturing, digital services, research.

One thing people look for and do not find is a public administration sector. Federal bodies sit under a separate provision, and the sixteen Länder, Germany's federal states, regulate their own authorities themselves.

Everything else that goes wrong here goes wrong the same way. A sector name means something narrower in the law than in ordinary speech, someone reads it in the ordinary sense, and rules themselves out. Two cases come up constantly.

"Digital services" in Anlage 2 sounds like anyone selling something digital. In the law it means online marketplaces, search engines and social networks, nothing else. A managed service provider that checks that entry and does not recognise itself is reading the wrong line. There is no separate ICT service management sector in the German lists. Managed services and managed security services sit in IT and telecommunications in Anlage 1, next to data centres, cloud, CDNs, DNS and trust services.

"Manufacturing" sounds like a factory floor. In the law it is a fixed list: medical devices and in-vitro diagnostics, computers and electronic and optical products, electrical equipment, machinery, motor vehicles and parts, and other vehicle construction, which takes in shipbuilding and bicycles as well as aircraft. A firm building control electronics is on that list whether or not it calls itself a manufacturer.

So read the entries, not the headings. Find yourself and go to step two. Find nothing and you are out on sector, which still leaves you the work in "If you are not in scope" below.

Step two: check your size

Sector alone is not enough. Size decides whether you are in, and which category you land in.

Larger threshold: at least 250 employees. Or turnover above 50 million euros together with a balance sheet total above 43 million.

Smaller threshold: at least 50 employees. Or turnover and balance sheet total each above 10 million. Read that twice. The German says jeweils, meaning each. Turnover of 12 million with a balance sheet of 6 million does not clear it.

Anlage 1 over the larger threshold makes you a besonders wichtige Einrichtung, a particularly important entity. Anlage 1 over the smaller one, or Anlage 2 over either, makes you a wichtige Einrichtung, an important entity. Below the smaller threshold you are out, unless step three catches you. Full wording in § 28 BSIG.

Two rules bend this, and both catch people.

You do not count only yourself. The test uses the EU size definition in Recommendation 2003/361/EC, which adds partner and linked companies. A 30-person subsidiary of a 4,000-person group is not a 30-person company here. The way out is narrow: genuine independence in how your IT systems and processes are designed and run.

One good year does not do it. Status only changes after a threshold is crossed in two consecutive financial years, and the same applies on the way back down.

Step three: check the exceptions

Some entity types are in scope at any size, and the law also fixes which category they land in.

Particularly important entities regardless of size: operators of critical installations, qualified trust service providers, TLD name registries and DNS service providers.

Important entities regardless of size: non-qualified trust service providers.

Providers of public communications networks and services are always in scope, but here size still sets the category, so a small telecoms provider is an important entity and a large one is particularly important.

"Critical installation", kritische Anlage, is a defined term rather than a description. A facility qualifies only above a capacity threshold in the KRITIS rules, usually supply to 500,000 people. So a regional energy supplier can be in scope on the size test and still not be a critical installation, which matters because the heavier duties and a separate registration ride on that status.

If you are in scope

Register with the BSI. Two steps: an account at Mein Unternehmenskonto, then the BSI-Portal. You give your legal details, sector and entity type, the member states you serve, your size figures, your public IP ranges and a named contact. Changes are due within two weeks (§ 33 BSIG, BSI guide).

Put the measures in place. § 30 BSIG names ten, covering risk analysis, incident handling, continuity, supply chain, secure development and procurement, effectiveness testing, training, cryptography, access control and multi-factor authentication. They must be documented and proportionate. Your management has to approve them, supervise them and attend training, and cannot delegate that away (§ 38).

Report significant incidents on a three-stage clock. Twenty-four hours for a short first alert, which can flag a suspected criminal act. Seventy-two hours for an assessment covering severity, impact and indicators of compromise. One month for the final report with cause, response and cross-border effect. The BSI can ask for interim updates, and if the incident is still open at one month the final report is due a month after it closes. Sometimes you also have to tell affected customers (§ 32, § 35).

Register first, and expect to be late. The law took effect on 6 December 2025 with registration due within three months, so 6 March 2026. The BSI kept accepting registrations until 31 July without pursuing the delay, which is why that date gets called an extension. It was never one. By the end of June, 17,729 entities had registered against a BSI estimate of roughly 29,500 in scope. The duty keeps running, and a company that grows into scope has three months from that point.

Two things to check before you build anything. Operators of critical installations have an extra registration with the BBK under the KRITIS-Dachgesetz. And § 28 (5) and (6) BSIG exempt some entities from the main duties because sector law already covers them: telecoms and energy network operators under §§ 5c to 5e EnWG, financial entities under DORA, and the healthcare telematics infrastructure under § 311 SGB V.

If you are not in scope

Supply chain security is one of the ten duties, and it travels. It reaches suppliers as questionnaires, evidence requests and contract clauses. No certificate makes those stop.

There is no official supplier questionnaire. Buyers build theirs from § 30 BSIG, because that is what they are measured against, so use it as your list. Be ready to show:

  • Access. What systems and data exist, who can reach each one, how access is granted and removed, where MFA is enforced.
  • Vulnerabilities. Where you get information, how fast you patch by severity, what you do when you cannot patch.
  • Incidents. A written process, named roles, out-of-hours contacts, and how fast you can tell a customer. NIS-2 clauses usually push a 24 hour notification duty down to suppliers, so this gets read closely.
  • Recovery. Backups, when you last restored one, and your real recovery time rather than the policy number.
  • Owners, and your own suppliers. A name per item, and the same questions one level down for anyone with access to your systems.

Keep a one-page record

This part is for everyone who ran the test, whether it put you in scope or out of it. The result is only useful if you can show later how you reached it.

Do it before you close the tab, because the two-year rule means you run this again next year and will want to know what you assumed. One page holds it: whether you came out in scope or out, the sector entry you matched or ruled out, the size figures with the two financial years and whether partner and linked companies are included, the date and who ran it, the sources you used, and anything ambiguous with your reasoning.

Put a reminder on it for when your next accounts are signed off. Nobody sends you a letter either way, so this page is the only record of how you decided.

What's next?

If you came out as not in scope but your customers are in it, the questionnaire lands on you anyway, and your incident process is the control they ask about first. And because reporting runs on a 24 hour clock, an asset inventory that holds up is what tells you what was actually affected when you have one day to say so.

ArticleEUGovernance & ComplianceNIS-2
NIS-2 & BSIG

Not sure whether NIS-2 applies to you?

The BSI sends no letters. We run the scope test with you, document the reasoning so it holds up next year, and build the ten measures § 30 BSIG actually asks for.

  • By active auditors
  • 50+ Compliant clients
  • Scope test documented in one page
Book a free consultation