/ NIS2 Measures
NIS2: Measures and Obligations for Businesses
If critical or particularly critical infrastructure, as defined by the NIS2 Directive, fails—for example, as a result of a cyberattack—this can have far-reaching consequences for supply chains, partner companies, and public services. The requirements placed on affected organizations are correspondingly high.

The NIS2 Directive requires organizations to systematically manage and sustainably safeguard their information security. A key component of this is structured, effective risk management.
At the same time, NIS2 explicitly addresses senior management: it bears overall responsibility for the implementation, monitoring, and continuous improvement of security measures.
Specifically, this means:
- Mandatory training for management and the board of directors
- Personal liability for breaches of duty
- Fines of up to €10 million or up to 2% of annual revenue
Responsibility can be delegated—but liability cannot.
Registration and Reporting Requirements
Companies must independently determine whether they fall under the NIS2 regulation. The Federal Office for Information Security (BSI) provides appropriate assessment procedures for this purpose.
Affected organizations are required to:
- register via “My Company Account”
- report to the BSI as a critical or highly critical facility
A three-month deadline applies to newly affected companies.
In addition, there are clear reporting requirements for security incidents:
- Within 24 hours: Initial report to the BSI
- Within 72 hours: Detailed assessment of the incident
- After 30 days: Final or progress report
A security incident is considered significant if it:
- leads to operational disruptions
- causes financial damage
- has an impact on third parties
In addition, the BSI may require companies to actively inform affected customers or partners.
NIS2 Risk Management: Structured Security as a Strategic Priority
Risk management lies at the heart of the NIS2 requirements. The goal is to identify security risks early on, implement appropriate measures, and strengthen the organization’s resilience in the long term.
This involves not only prevention but also the ability to maintain operations or quickly restore them in the event of an emergency.
Basic Principles of Effective Risk Management
Companies are required to implement appropriate technical and organizational measures and to document them in a transparent manner.
The design is based on:
- Risk exposure
- Company size and structure
- Probability of incidents occurring
- Potential impacts
- Economic feasibility
This risk-based approach ensures that security measures are implemented in a targeted and efficient manner.
Objectives of the NIS2 Measures
Effective risk management aims, in particular, to achieve the following objectives:
- Ensuring availability, integrity, and confidentiality
- Minimizing the impact of security incidents
- Ensuring the stable and secure operation of critical processes
In doing so, all relevant systems, processes, and dependencies must be taken into account—including external service providers and supply chains.
Alignment with the State of the Art
The NIS2 Directive explicitly requires alignment with the current state of the art as well as with established norms and standards, including:
- ISO/IEC 27001
- ISO 9001
- industry-specific security standards
For companies, this means that information security must be continuously reviewed and improved—both technically and organizationally.
Overview of Minimum Requirements
The directive sets out specific requirements for risk management. These include, in particular:
Identifying the Need for Action Early On
Implementing the NIS2 requirements is not a one-time project, but an ongoing process. Companies that act early on not only ensure regulatory compliance but also strengthen their digital resilience and future viability.
Would you like to implement NIS2 requirements in a structured and efficient manner?
We support you with customized solutions—from analysis and implementation to hosting and operation on GDPR-compliant, ISO-certified infrastructures.




