/ What is NIS2
What is NIS2? Background on the EU Directive and the Implementing Act
The increasing interconnectivity of business processes, supply chains, and critical infrastructure is constantly expanding the attack surface for cyber threats. At the same time, today’s attackers operate in a highly professional manner, working in coordinated teams and deploying significant resources.

Ransomware, targeted sabotage, and supply chain attacks are no longer isolated incidents but rather an ongoing risk for businesses and public institutions.
Organizations whose failure would have far-reaching consequences are therefore a particular focus of regulatory requirements.
Cyber Resilience as a Strategic Priority
Against this backdrop, cyber resilience is becoming increasingly important: the ability not only to prevent security incidents, but also to limit their impact and quickly restore business operations.
The EU’s NIS2 Directive and the national implementing law establish a significantly expanded regulatory framework for this purpose. Companies are required to
- systematically establish cybersecurity
- manage risks in a structured manner
- report security incidents transparently
This makes information security a business-critical discipline—and a clear responsibility at the management level.
NIS2 goes beyond purely technical measures: it requires a holistic approach that encompasses organization, processes, and technologies in equal measure.
Which companies are affected?
Whether a company falls under the NIS2 regulation must generally be determined independently. The law distinguishes between important and critical infrastructure operators—a classification that can be complex in detail.
As a general guideline, the following are particularly affected:
- KRITIS operators
- Trust service providers (e.g., qualified digital signature providers)
- Operators of DNS services and TLD registries
- Providers of public telecommunications services and networks
- Companies with 50 or more employees or with more than €10 million in revenue and total assets in defined sectors
An official classification test is provided by the Federal Office for Information Security (BSI).
Overview of Relevant Sectors
The NIS2 Directive covers a wide range of industries, including:
- Energy supply
- Transportation and traffic
- Finance
- Healthcare and medical technology
- Water and wastewater management
- Digital services and IT infrastructure
- Food industry
- Chemical and manufacturing industries
- Research institutions
As a result, NIS2 affects a significant portion of the German economy—estimates suggest that around 30,000 companies are affected.
Key Obligations for Companies
Companies subject to NIS2 must meet a number of specific requirements. These include, in particular:
Registration and Record-Keeping
- Registration with the BSI
- Documentation of implemented security measures
- Record-keeping obligations (e.g., through audits of KRITIS operators)
Risk Management and Security Measures
- Conducting structured risk analyses
- Implementing business continuity and crisis management processes
- Deploying technical measures such as encryption and multi-factor authentication
- Training and raising awareness among employees
Reporting and Information Obligations
- Immediate reporting of significant security incidents to the BSI
- Ongoing reporting on incident management
- Notification of customers or partners upon order of the authorities
Consequences of violations
- Ensuring and monitoring the measures
- Mandatory training
- Personal liability for breaches of duty
KRITIS operators are also subject to additional requirements, such as restrictions on the use of certain critical components.
Consequences of violations
The NIS2 regulation provides for graduated sanctions, some of which are substantial. Fines can amount to up to €10 million or 2% of global annual turnover—whichever is higher.
Furthermore, liability can be extended to management. Violations can result not only in regulatory consequences but also in personal liability risks for board members and executives.
Implementation: Holistic and Practical
The requirements of NIS2 apply not only to IT systems but to the entire organization—from technical safeguards and processes to physical security.
ASTRUM IT helps companies implement these requirements in a structured and sustainable manner—as part of a holistic, future-proof IT strategy.
This includes, among other things:
- Custom software development that integrates security from the very beginning
- Fully managed hosting and operations on GDPR-compliant, ISO 27001-certified infrastructures in Germany
- Solutions such as VISIT, which make a significant contribution to physical access control—for example, in visitor management and yard management.
This creates a comprehensive approach that combines digital and physical security and lays the foundation for digital vitality.
Would you like to implement NIS2 requirements in a structured and sustainable manner?
Talk to us about customized solutions for secure, scalable, and future-proof IT infrastructures.




