First, what NIS-2 actually is
NIS-2 is an EU law about keeping important services running when someone attacks them. It replaced a narrower 2016 law and pulled in far more companies.
It is a directive, so it binds no one directly. Each member state writes its own version. Germany's is the NIS2UmsuCG, and its main job was rewriting an existing law, the BSI Act (BSIG). When a German company says NIS-2 applies to them, the rules they follow are in the BSIG.
Nobody tells you that you are covered. The BSI sends no letters. You work it out, register yourself, and keep your reasoning, because the BSI can add you to the register later and ask how you got there.
Step one: find your sector
The BSIG carries two sector lists, Anlage 1 and Anlage 2. Use those if you operate in Germany. The EU directive's annexes are organised differently and every member state wrote its own list, so a group with entities in several countries runs this test once per country.
Anlage 1, where an outage does the most damage: energy, transport, finance and insurance, health, water and wastewater, IT and telecommunications, space.
Anlage 2, the rest: postal and courier services, waste management, chemicals, food, manufacturing, digital services, research.
One thing people look for and do not find is a public administration sector. Federal bodies sit under a separate provision, and the sixteen Länder, Germany's federal states, regulate their own authorities themselves.
Everything else that goes wrong here goes wrong the same way. A sector name means something narrower in the law than in ordinary speech, someone reads it in the ordinary sense, and rules themselves out. Two cases come up constantly.
"Digital services" in Anlage 2 sounds like anyone selling something digital. In the law it means online marketplaces, search engines and social networks, nothing else. A managed service provider that checks that entry and does not recognise itself is reading the wrong line. There is no separate ICT service management sector in the German lists. Managed services and managed security services sit in IT and telecommunications in Anlage 1, next to data centres, cloud, CDNs, DNS and trust services.
"Manufacturing" sounds like a factory floor. In the law it is a fixed list: medical devices and in-vitro diagnostics, computers and electronic and optical products, electrical equipment, machinery, motor vehicles and parts, and other vehicle construction, which takes in shipbuilding and bicycles as well as aircraft. A firm building control electronics is on that list whether or not it calls itself a manufacturer.
So read the entries, not the headings. Find yourself and go to step two. Find nothing and you are out on sector, which still leaves you the work in "If you are not in scope" below.
Step two: check your size
Sector alone is not enough. Size decides whether you are in, and which category you land in.
Larger threshold: at least 250 employees. Or turnover above 50 million euros together with a balance sheet total above 43 million.
Smaller threshold: at least 50 employees. Or turnover and balance sheet total each above 10 million. Read that twice. The German says jeweils, meaning each. Turnover of 12 million with a balance sheet of 6 million does not clear it.
Anlage 1 over the larger threshold makes you a besonders wichtige Einrichtung, a particularly important entity. Anlage 1 over the smaller one, or Anlage 2 over either, makes you a wichtige Einrichtung, an important entity. Below the smaller threshold you are out, unless step three catches you. Full wording in § 28 BSIG.
Two rules bend this, and both catch people.
You do not count only yourself. The test uses the EU size definition in Recommendation 2003/361/EC, which adds partner and linked companies. A 30-person subsidiary of a 4,000-person group is not a 30-person company here. The way out is narrow: genuine independence in how your IT systems and processes are designed and run.
One good year does not do it. Status only changes after a threshold is crossed in two consecutive financial years, and the same applies on the way back down.
Step three: check the exceptions
Some entity types are in scope at any size, and the law also fixes which category they land in.
Particularly important entities regardless of size: operators of critical installations, qualified trust service providers, TLD name registries and DNS service providers.
Important entities regardless of size: non-qualified trust service providers.
Providers of public communications networks and services are always in scope, but here size still sets the category, so a small telecoms provider is an important entity and a large one is particularly important.
"Critical installation", kritische Anlage, is a defined term rather than a description. A facility qualifies only above a capacity threshold in the KRITIS rules, usually supply to 500,000 people. So a regional energy supplier can be in scope on the size test and still not be a critical installation, which matters because the heavier duties and a separate registration ride on that status.
If you are in scope
Register with the BSI. Two steps: an account at Mein Unternehmenskonto, then the BSI-Portal. You give your legal details, sector and entity type, the member states you serve, your size figures, your public IP ranges and a named contact. Changes are due within two weeks (§ 33 BSIG, BSI guide).
Put the measures in place. § 30 BSIG names ten, covering risk analysis, incident handling, continuity, supply chain, secure development and procurement, effectiveness testing, training, cryptography, access control and multi-factor authentication. They must be documented and proportionate. Your management has to approve them, supervise them and attend training, and cannot delegate that away (§ 38).
Report significant incidents on a three-stage clock. Twenty-four hours for a short first alert, which can flag a suspected criminal act. Seventy-two hours for an assessment covering severity, impact and indicators of compromise. One month for the final report with cause, response and cross-border effect. The BSI can ask for interim updates, and if the incident is still open at one month the final report is due a month after it closes. Sometimes you also have to tell affected customers (§ 32, § 35).
Register first, and expect to be late. The law took effect on 6 December 2025 with registration due within three months, so 6 March 2026. The BSI kept accepting registrations until 31 July without pursuing the delay, which is why that date gets called an extension. It was never one. By the end of June, 17,729 entities had registered against a BSI estimate of roughly 29,500 in scope. The duty keeps running, and a company that grows into scope has three months from that point.
Two things to check before you build anything. Operators of critical installations have an extra registration with the BBK under the KRITIS-Dachgesetz. And § 28 (5) and (6) BSIG exempt some entities from the main duties because sector law already covers them: telecoms and energy network operators under §§ 5c to 5e EnWG, financial entities under DORA, and the healthcare telematics infrastructure under § 311 SGB V.
If you are not in scope
Supply chain security is one of the ten duties, and it travels. It reaches suppliers as questionnaires, evidence requests and contract clauses. No certificate makes those stop.
There is no official supplier questionnaire. Buyers build theirs from § 30 BSIG, because that is what they are measured against, so use it as your list. Be ready to show:
- Access. What systems and data exist, who can reach each one, how access is granted and removed, where MFA is enforced.
- Vulnerabilities. Where you get information, how fast you patch by severity, what you do when you cannot patch.
- Incidents. A written process, named roles, out-of-hours contacts, and how fast you can tell a customer. NIS-2 clauses usually push a 24 hour notification duty down to suppliers, so this gets read closely.
- Recovery. Backups, when you last restored one, and your real recovery time rather than the policy number.
- Owners, and your own suppliers. A name per item, and the same questions one level down for anyone with access to your systems.
Keep a one-page record
This part is for everyone who ran the test, whether it put you in scope or out of it. The result is only useful if you can show later how you reached it.
Do it before you close the tab, because the two-year rule means you run this again next year and will want to know what you assumed. One page holds it: whether you came out in scope or out, the sector entry you matched or ruled out, the size figures with the two financial years and whether partner and linked companies are included, the date and who ran it, the sources you used, and anything ambiguous with your reasoning.
Put a reminder on it for when your next accounts are signed off. Nobody sends you a letter either way, so this page is the only record of how you decided.
What's next?
If you came out as not in scope but your customers are in it, the questionnaire lands on you anyway, and your incident process is the control they ask about first. And because reporting runs on a 24 hour clock, an asset inventory that holds up is what tells you what was actually affected when you have one day to say so.
