{"id":4667,"date":"2026-05-21T11:51:06","date_gmt":"2026-05-21T09:51:06","guid":{"rendered":"https:\/\/visit.astrum-it.de\/?post_type=news&#038;p=4667"},"modified":"2026-05-21T12:20:11","modified_gmt":"2026-05-21T10:20:11","slug":"what-is-nis2","status":"publish","type":"news","link":"https:\/\/visit.astrum-it.de\/en\/news\/what-is-nis2\/","title":{"rendered":"What is NIS2? Background on the EU Directive and the Implementing Act"},"content":{"rendered":"<p><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-1\"><p><img decoding=\"async\" class=\"alignnone size-large wp-image-3403\" src=\"https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/was-ist-nis2-1200x668.jpg\" alt=\"Im Matrix-Stil animiertes Bild eines Hackers, vor dem sich NIS2-betroffene Unternehmen sch\u00fctzen sollten.\" width=\"1200\" height=\"668\" srcset=\"https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/was-ist-nis2-200x111.jpg 200w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/was-ist-nis2-400x223.jpg 400w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/was-ist-nis2-600x334.jpg 600w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/was-ist-nis2-768x427.jpg 768w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/was-ist-nis2-800x445.jpg 800w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/was-ist-nis2-1200x668.jpg 1200w, https:\/\/visit.astrum-it.de\/wp-content\/uploads\/2026\/04\/was-ist-nis2-1536x855.jpg 1536w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/p>\n<p>Ransomware, targeted sabotage, and supply chain attacks are no longer isolated incidents but rather an ongoing risk for businesses and public institutions.<\/p>\n<p>Organizations whose failure would have far-reaching consequences are therefore a particular focus of regulatory requirements.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-2 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-background-color:var(--awb-color3);--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-1 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-2\"><h2>Cyber Resilience as a Strategic Priority<\/h2>\n<p>Against this backdrop, cyber resilience is becoming increasingly important: the ability not only to prevent security incidents, but also to limit their impact and quickly restore business operations.<\/p>\n<p>The EU\u2019s NIS2 Directive and the national implementing law establish a significantly expanded regulatory framework for this purpose. Companies are required to<\/p>\n<ul>\n<li>systematically establish cybersecurity<\/li>\n<li>manage risks in a structured manner<\/li>\n<li>report security incidents transparently<\/li>\n<\/ul>\n<p>This makes information security a business-critical discipline\u2014and a clear responsibility at the management level.<\/p>\n<p>NIS2 goes beyond purely technical measures: it requires a holistic approach that encompasses organization, processes, and technologies in equal measure.<\/p>\n<\/div><div class=\"fusion-text fusion-text-3\" style=\"--awb-margin-top:20px;\"><h2>Which companies are affected?<\/h2>\n<p>Whether a company falls under the NIS2 regulation <strong><a href=\"https:\/\/www.bsi.bund.de\/EN\/Themen\/Regulierte-Wirtschaft\/kritis-und-regulierte-unternehmen_node.html\" target=\"_blank\" rel=\"noopener\">must generally be determined independently<\/a><\/strong>. The law distinguishes between <strong>important and critical infrastructure operators<\/strong>\u2014a classification that can be complex in detail.<\/p>\n<p>As a general guideline, the following are particularly affected:<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/visit.astrum-it.de\/en\/news\/critical-infrastructure-strict-rules-for-kritis-companies\/\" target=\"_blank\" rel=\"noopener\">KRITIS operators<\/a><\/strong><\/li>\n<li>Trust service providers (e.g., qualified digital signature providers)<\/li>\n<li>Operators of DNS services and TLD registries<\/li>\n<li>Providers of public telecommunications services and networks<\/li>\n<li>Companies with 50 or more employees or with more than \u20ac10 million in revenue and total assets in defined sectors<\/li>\n<\/ul>\n<p>An official classification test is provided by the Federal Office for Information Security (BSI).<\/p>\n<\/div><div class=\"fusion-text fusion-text-4\" style=\"--awb-margin-top:20px;\"><h2>Overview of Relevant Sectors<\/h2>\n<p>The NIS2 Directive covers a wide range of industries, including:<\/p>\n<ul>\n<li>Energy supply<\/li>\n<li>Transportation and traffic<\/li>\n<li>Finance<\/li>\n<li>Healthcare and medical technology<\/li>\n<li>Water and wastewater management<\/li>\n<li>Digital services and IT infrastructure<\/li>\n<li>Food industry<\/li>\n<li>Chemical and manufacturing industries<\/li>\n<li>Research institutions<\/li>\n<\/ul>\n<p>As a result, NIS2 affects a significant portion of the German economy\u2014estimates suggest that around 30,000 companies are affected.<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"fusion-fullwidth fullwidth-box fusion-builder-row-3 fusion-flex-container has-pattern-background has-mask-background nonhundred-percent-fullwidth non-hundred-percent-height-scrolling\" style=\"--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;\" ><div class=\"fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap\" style=\"max-width:1456px;margin-left: calc(-4% \/ 2 );margin-right: calc(-4% \/ 2 );\"><div class=\"fusion-layout-column fusion_builder_column fusion-builder-column-2 fusion_builder_column_1_1 1_1 fusion-flex-column\" style=\"--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:20px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-order-medium:0;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-order-small:0;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;\"><div class=\"fusion-column-wrapper fusion-column-has-shadow fusion-flex-justify-content-flex-start fusion-content-layout-column\"><div class=\"fusion-text fusion-text-5\"><h2>Key Obligations for Companies<\/h2>\n<p>Companies subject to NIS2 must meet a number of specific requirements. These include, in particular:<\/p>\n<h3>Registration and Record-Keeping<\/h3>\n<ul>\n<li>Registration with the BSI<\/li>\n<li>Documentation of implemented security measures<\/li>\n<li>Record-keeping obligations (e.g., through audits of KRITIS operators)<\/li>\n<\/ul>\n<h3>Risk Management and Security Measures<\/h3>\n<ul>\n<li>Conducting structured risk analyses<\/li>\n<li>Implementing business continuity and crisis management processes<\/li>\n<li>Deploying technical measures such as encryption and multi-factor authentication<\/li>\n<li>Training and raising awareness among employees<\/li>\n<\/ul>\n<h3>Reporting and Information Obligations<\/h3>\n<ul>\n<li>Immediate reporting of significant security incidents to the BSI<\/li>\n<li>Ongoing reporting on incident management<\/li>\n<li>Notification of customers or partners upon order of the authorities<\/li>\n<\/ul>\n<h3>Consequences of violations<\/h3>\n<ul>\n<li>Ensuring and monitoring the measures<\/li>\n<li>Mandatory training<\/li>\n<li>Personal liability for breaches of duty<\/li>\n<\/ul>\n<p>KRITIS operators are also subject to additional requirements, such as restrictions on the use of certain critical components.<\/p>\n<h3>Consequences of violations<\/h3>\n<p>The NIS2 regulation provides for graduated sanctions, some of which are substantial. Fines can amount to up to \u20ac10 million or 2% of global annual turnover\u2014whichever is higher.<\/p>\n<p>Furthermore, liability can be extended to management. Violations can result not only in regulatory consequences but also in personal liability risks for board members and executives.<\/p>\n<\/div><div class=\"fusion-text fusion-text-6\"><h2>Implementation: Holistic and Practical<\/h2>\n<p>The requirements of NIS2 apply not only to IT systems but to the entire organization\u2014from technical safeguards and processes to physical security.<\/p>\n<p>ASTRUM IT helps companies implement these requirements in a structured and sustainable manner\u2014as part of a holistic, future-proof IT strategy.<\/p>\n<p>This includes, among other things:<\/p>\n<ul>\n<li><a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4669\" target=\"_blank\" rel=\"noopener\"><strong>Custom software development<\/strong><\/a> that integrates security from the very beginning<\/li>\n<li><strong><a href=\"https:\/\/www.astrum-it.de\/en\/products\/it-hosting\/\">Fully managed hosting<\/a><\/strong> and <strong>operations on GDPR-compliant<\/strong>, <strong><a href=\"https:\/\/www.astrum-it.de\/en\/products\/it-hosting\/\">ISO 27001-certified infrastructures in Germany<\/a><\/strong><\/li>\n<li>Solutions such as <strong>VISIT<\/strong>, which make a significant contribution to physical access control\u2014for example, in <strong><a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4670\">visitor management<\/a><\/strong> and <a href=\"https:\/\/visit.astrum-it.de\/en\/?post_type=news&amp;p=4669\"><strong>yard management<\/strong><\/a>.<\/li>\n<\/ul>\n<p>This creates a comprehensive approach that combines digital and physical security and lays the foundation for digital vitality.<\/p>\n<\/div><\/div><\/div><\/div><\/div><\/p>\n","protected":false},"featured_media":3402,"template":"","meta":{"_acf_changed":false,"rs_blank_template":"","rs_page_bg_color":"","slide_template_v7":"","_links_to":"","_links_to_target":""},"mediathek-kategorie":[50],"class_list":["post-4667","news","type-news","status-publish","has-post-thumbnail","hentry","mediathek-kategorie-technology-insights-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/news\/4667","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/news"}],"about":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/types\/news"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/media\/3402"}],"wp:attachment":[{"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/media?parent=4667"}],"wp:term":[{"taxonomy":"mediathek-kategorie","embeddable":true,"href":"https:\/\/visit.astrum-it.de\/en\/wp-json\/wp\/v2\/mediathek-kategorie?post=4667"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}