21.05.2026/

/ NIS2 Measures

NIS2: Measures and Obligations for Businesses

If critical or particularly critical infrastructure, as defined by the NIS2 Directive, fails—for example, as a result of a cyberattack—this can have far-reaching consequences for supply chains, partner companies, and public services. The requirements placed on affected organizations are correspondingly high.

Serverraum, der mit NIS2-Maßnahmen geschützt werden muss.

The NIS2 Directive requires organizations to systematically manage and sustainably safeguard their information security. A key component of this is structured, effective risk management.

At the same time, NIS2 explicitly addresses senior management: it bears overall responsibility for the implementation, monitoring, and continuous improvement of security measures.

Specifically, this means:

  • Mandatory training for management and the board of directors
  • Personal liability for breaches of duty
  • Fines of up to €10 million or up to 2% of annual revenue

Responsibility can be delegated—but liability cannot.

Registration and Reporting Requirements

Companies must independently determine whether they fall under the NIS2 regulation. The Federal Office for Information Security (BSI) provides appropriate assessment procedures for this purpose.

Affected organizations are required to:

A three-month deadline applies to newly affected companies.

In addition, there are clear reporting requirements for security incidents:

  • Within 24 hours: Initial report to the BSI
  • Within 72 hours: Detailed assessment of the incident
  • After 30 days: Final or progress report

A security incident is considered significant if it:

  • leads to operational disruptions
  • causes financial damage
  • has an impact on third parties

In addition, the BSI may require companies to actively inform affected customers or partners.

NIS2 Risk Management: Structured Security as a Strategic Priority

Risk management lies at the heart of the NIS2 requirements. The goal is to identify security risks early on, implement appropriate measures, and strengthen the organization’s resilience in the long term.

This involves not only prevention but also the ability to maintain operations or quickly restore them in the event of an emergency.

Basic Principles of Effective Risk Management

Companies are required to implement appropriate technical and organizational measures and to document them in a transparent manner.

The design is based on:

  • Risk exposure
  • Company size and structure
  • Probability of incidents occurring
  • Potential impacts
  • Economic feasibility

This risk-based approach ensures that security measures are implemented in a targeted and efficient manner.

Objectives of the NIS2 Measures

Effective risk management aims, in particular, to achieve the following objectives:

  • Ensuring availability, integrity, and confidentiality
  • Minimizing the impact of security incidents
  • Ensuring the stable and secure operation of critical processes

In doing so, all relevant systems, processes, and dependencies must be taken into account—including external service providers and supply chains.

Alignment with the State of the Art

The NIS2 Directive explicitly requires alignment with the current state of the art as well as with established norms and standards, including:

  • ISO/IEC 27001
  • ISO 9001
  • industry-specific security standards

For companies, this means that information security must be continuously reviewed and improved—both technically and organizationally.

Overview of Minimum Requirements

The directive sets out specific requirements for risk management. These include, in particular:

Systematic identification, assessment, and prioritization of risks, as well as the development of appropriate safety strategies.

Clear processes for detecting, analyzing, and responding to security incidents.

Ensuring operational continuity through contingency plans, backups, and recovery strategies.

Incorporating security requirements into collaboration with service providers and partners.

Implementation of security by design and structured vulnerability management.

Regular audits and continuous improvement of measures.

Building security awareness within the company—including mandatory training for management.

Protection of sensitive data during storage and transmission.

Clear regulations for digital and physical access, as well as complete transparency regarding all IT assets.

In this context, VISIT can make a significant contribution:

Through NIS2-compliant visitor management softwareand the control of access and logistics processes via Dock and Yard Management, the solution helps implement physical security requirements in a structured and NIS2-compliant manner.

Use of multi-factor authentication and securing all communication channels—even in an emergency.

Identifying the Need for Action Early On

Implementing the NIS2 requirements is not a one-time project, but an ongoing process. Companies that act early on not only ensure regulatory compliance but also strengthen their digital resilience and future viability.

Would you like to implement NIS2 requirements in a structured and efficient manner?

We support you with customized solutions—from analysis and implementation to hosting and operation on GDPR-compliant, ISO-certified infrastructures.

Would you like us to call you back? Please enter your telephone number and the desired time period.
Indicates required field