NIS2 Directive 2026: Requirements, Deadlines & Compliance
Description:
Learn what companies need to know about the NIS2 Directive in 2026: requirements, deadlines, risk management, management liability, and fines.
Scope
This article is intended for managing directors, board members, IT managers, information security managers, and companies that need to determine whether they are affected by the NIS2 Directive.
The article explains:
- what the NIS2 Directive is,
- which companies and sectors are affected,
- what has changed compared with NIS1,
- what responsibilities management has,
- which ten risk-management measures are required,
- which reporting deadlines apply,
- what fines may be imposed,
- how BSI registration works,
- which requirements apply in Germany and Austria,
- and which first steps affected companies should take.
NIS2 Directive: Current Status in 2026
The NIS2 Implementation Act (NIS2UmsuCG) has been in force since December 2025. Around 29,500 companies across 18 sectors are affected and must implement the ten risk-management measures.
Management has personal responsibility for NIS2 compliance. This responsibility cannot be delegated and can lead to fines of up to €10 million.
At its core, NIS2 requires an information security and risk-management system. Companies that already implement ISO 27001 can, based on experience, cover a large part of the requirements.
The BSI registration portal has been online since January 2026. Affected companies must register and begin their risk analysis in parallel.
Current Status in July 2026
The NIS2UmsuCG has been in force since December 6, 2025, without a transition period. The three-month BSI registration deadline expired on March 6, 2026. The BSI set an extension deadline until July 31, 2026.
Companies that have not yet registered should complete their registration. Failure to register may result in fines of up to €500,000 (§65 BSIG).
What Is the NIS2 Directive?
The NIS2 Directive (EU 2022/2555) is the next-generation European cybersecurity directive. Since December 2025, it has been implemented in Germany through the NIS2 Implementation Act (NIS2UmsuCG).
It requires companies and public authorities to establish structured risk management across ten defined areas. It also introduces rapid reporting requirements for security incidents and personal responsibility for management.
One special feature is that this responsibility cannot be delegated. Board members and managing directors can be held personally liable.
Around 29,500 companies in Germany are affected. These include large companies in areas such as energy, banking, and healthcare, as well as medium-sized and smaller companies in digital sectors and industries such as chemicals, food, and logistics.
At its core, NIS2 is a standard for information security and risk management. The directive applies to companies and public organizations that operate critical infrastructures or provide digital services.
According to the article, the previous NIS1 Directive from 2016 did not sufficiently address the increased threat landscape created by ransomware, state-sponsored hackers, supply-chain attacks, and other organized cyberattacks.
NIS2 addresses these gaps through:
- higher standards for risk prevention,
- faster reporting procedures,
- specific and higher fines,
- mandatory governance requirements for management.
Personal Responsibility of Management
With NIS2, responsibility for cybersecurity no longer ends with the IT department or IT manager.
The board and management must deal with risk-management decisions, consciously approve them, and monitor their implementation.
Complete delegation to operational IT is no longer possible.
In the event of violations, managing directors and board members can be held personally liable. In serious cases, authorities can also investigate individuals and impose fines on them.
Timeline: From the EU Directive to German Law
The development of the NIS2 Directive has taken place over several years.
On January 10, 2023, the European Parliament adopted the NIS2 Directive after lengthy negotiations.
EU Member States were required to transpose the directive into national law by December 17, 2024 at the latest.
Germany missed this deadline and adopted the NIS2 Implementation Act (NIS2UmsuCG) in December 2025. The law entered into force immediately.
At the same time, the Federal Office for Information Security (BSI) developed its online registration portal. The portal has been live since January 2026.
Companies can determine their classification there, enter their data, and update it. The portal helps companies clarify whether they are classified as an “essential” or “important” entity under the criteria of the NIS2 Directive.
The three-month registration deadline expired on March 6, 2026. The BSI set an extension deadline until July 31, 2026.
Affected companies should complete registration to avoid fines of up to €500,000 (§65 BSIG). Risk analysis should already begin in parallel with registration.
There is no single deadline for the complete implementation of the ten risk-management measures for all companies. Depending on whether a company is classified as an essential or important entity and depending on the sector, different implementation phases and deadlines may apply.
Particularly critical sectors such as energy must achieve full compliance earlier, while other sectors may have more time.
The BSI is gradually publishing specific implementation roadmaps, requirements, and interpretation guidance for different sectors.
NIS2 at a Glance: The 5 Most Important Changes
NIS2 differs from NIS1 in five key areas.
1. Expanded Scope: From 7 to 18 Sectors
NIS1 covered seven critical infrastructure sectors. NIS2 significantly expands the scope to 18 sectors and distinguishes between:
- essential entities,
- important entities.
Affected areas include energy, transport, banking, healthcare, chemicals, food, manufacturing, research, and digital services.
Companies in areas such as logistics, postal and courier services, waste management, and manufacturing can now also fall under NIS2.
The size thresholds have also been significantly expanded.
For large companies, the stated thresholds are 250 employees or €50 million in annual revenue. Smaller companies with 50 employees or €10 million in revenue are also subject to requirements, although with a lower scope.
2. Personal Liability of Company Management
Management must consciously approve risk-management measures, actively monitor their implementation, and review them regularly.
This responsibility cannot be delegated.
Board members and managing directors can be held personally liable if their monitoring obligations are not fulfilled.
Violations can result in fines for the company and directly for the responsible individuals. In particularly serious cases, managing directors can also face criminal prosecution.
Management must be able to demonstrate that it has fulfilled its supervisory duties.
3. Stricter Reporting Requirements
NIS2 introduces a three-stage reporting procedure for security incidents.
Within 24 hours:
Major security incidents must be reported to the BSI and the responsible authorities.
After 72 hours:
A confirmation of the incident with the first available information follows.
Within one month at the latest:
A complete and detailed report must be submitted.
These deadlines require an established and trained incident-response process.
4. Ten Risk-Management Measures Under §30 BSIG
NIS2 defines ten key risk-management measures:
- Risk analysis and risk treatment
- Incident management and business continuity
- Supply-chain security management
- Procurement security
- Cryptography and quantum readiness
- Personnel and personnel security
- Access control and authentication
- Multi-factor authentication (MFA)
- Communications security
- Network monitoring
These ten measures form the organizational and technical foundation of risk management.
Companies with an existing ISO 27001 ISMS already cover a large part of the NIS2 requirements.
“At its core, NIS2 requires what ISO 27001 has specified for years. Companies that establish an ISMS do not fulfill NIS2 as a separate obligation, but as a side effect of a systematic approach. The ten areas of measures under §30 read like the table of contents of an ISO 27001 implementation.”
Bettina Stearn, ISO/IEC 27001 Auditor & Quality Management Expert at SECJUR
5. Higher Fines and Stronger Enforcement
For essential entities, fines of up to €10 million or 2 percent of worldwide annual revenue may be imposed, depending on which amount is higher.
For important entities, the limit is €7 million or 1.4 percent of worldwide revenue.
This means the possible penalties are significantly higher than under NIS1.
Who Does NIS2 Apply To? Quick Check
The quick check consists of three steps.
Step 1: Check the Sector
Check whether your company operates in one of the 18 affected sectors listed in Annex I or Annex II of the NIS2 Directive.
Step 2: Check the Size Threshold
For essential entities, the stated threshold is:
- 250 employees or more,
- or more than €50 million in annual revenue.
For important entities, the threshold is:
- 50 employees or more,
- or more than €10 million in revenue.
Step 3: Consider Special Rules
Digital services such as hosting providers, cloud services, and online marketplaces may be subject to different thresholds in some cases.
Micro-enterprises and small companies with fewer than 50 employees and less than €10 million in annual revenue are generally exempt from NIS2.
However, suppliers of micro and small companies may still be affected if they operate as critical ICT service providers and provide certain services.
The BSI registration portal helps companies determine their exact classification.
NIS2 in Austria: The NISG 2026
Groups with locations in Austria must also assess whether they are affected under Austrian law.
Austria is implementing NIS2 through the Network and Information System Security Act 2026 (NISG 2026). The law was published on December 23, 2025, as BGBl. I No. 94/2025.
It will apply from October 1, 2026. There is no transition period for the substantive obligations.
The responsible authority is the Federal Office for Cybersecurity, which reports to the Federal Ministry of the Interior.
Affected entities must register within three months after the law enters into force. Self-declaration follows within twelve months.
The penalty range is up to €10 million or 2 percent for essential entities and up to €7 million or 1.4 percent for important entities.
There is no official figure for the number of affected companies. The Austrian Economic Chamber estimates that around 4,000 companies may be affected.
Practical Example
A group headquartered in Munich with a production company in Linz conducts two separate assessments:
- the German company under the BSIG,
- the Austrian company under NISG 2026.
The assessment of whether the companies are affected is carried out separately for each company and each jurisdiction. Thresholds, deadlines, and contact with authorities are assessed separately.
What Must Affected Companies Do?
Affected companies must address four key areas in parallel.
1. Register with the BSI Portal
Companies must register with the BSI portal and clarify their official classification as an essential or important entity.
2. Establish or Audit a Risk-Management System
The risk-management system must fully and transparently document the ten measures under §30 BSIG.
3. Establish an Incident-Response Process
An established, tested, and trained incident-response process must account for the reporting deadlines of 24 hours, 72 hours, and one month.
4. Involve Management
Management must be formally involved in risk governance.
This includes:
- regular reporting,
- regular coordination meetings,
- documented governance activities.
Companies with an existing ISO 27001 ISMS are often already more than halfway finished because many basic requirements have already been fulfilled and only need to be translated and documented for NIS2.
Companies without an established security infrastructure must start from the beginning.
A typical implementation takes 6–18 months, depending on company size and sector.
The NIS2 Directive (EU 2022/2555) in Detail
Legal Basis and Scope
The NIS2 Directive (EU 2022/2555) was adopted by the European Parliament on January 10, 2023.
It is based on Directive 2016/1148 (NIS1) and fully replaces it within its areas of application.
In Germany, implementation is carried out through the NIS2 Implementation Act (NIS2UmsuCG), which entered into force in December 2025.
The law is integrated into the Federal Information Security Act (BSIG) and contains the new provisions in §§28–39 BSIG.
The scope includes companies and public authorities that provide public services or operate or support critical infrastructure.
This includes physical infrastructure such as:
- electricity networks,
- water pipelines,
- transport infrastructure,
- railway networks.
It also includes digital infrastructure, such as:
- cloud services,
- DNS providers,
- Internet Exchange Points,
- CDN networks.
Critical suppliers of systems or services may also be affected.
NIS2 vs. NIS1: What Has Changed?
NIS1 was limited to seven narrowly defined sectors and, in most sectors, covered only very large companies with 10,000 or more employees.
NIS2 expands the scope to 18 sectors, lowers the size thresholds, and introduces ten mandatory risk-management measures as a minimum standard.
In addition, management is explicitly and personally responsible for fulfilling the requirements.
Another difference is supply-chain security. Companies must include their suppliers and digital partners in their security responsibilities in a traceable manner.
The 18 Sectors of the NIS2 Directive
Essential Entities
- Energy (electricity, gas, heat)
- Transport and logistics
- Banking and financial services
- Financial market infrastructure
- Healthcare and pharmaceuticals
- Drinking water and wastewater management
- Digital infrastructure (IXP, DNS, providers)
- ICT service management (B2B, critical)
- Public administration at federal and state level
- Space and satellite infrastructure
Important Entities
- Postal and courier services
- Waste management and recycling
- Chemical industry
- Food and agricultural industry
- Manufacturing
- Digital services (AICL, cloud computing, hosting)
- Research and development
Companies classified as essential entities are subject to stricter requirements, higher fines, and, in some cases, extended compliance deadlines.
Important entities have somewhat more flexibility in implementation but must also establish robust and demonstrable risk management.
Companies operating in multiple sectors are classified in the higher category depending on the focus of their business activities.
Implementation Status in EU Member States
The implementation deadline for NIS2 was December 17, 2024.
Several major Member States missed this deadline. Germany adopted its NIS2 Implementation Act in December 2025.
Austria and Switzerland have experienced similar delays. Other countries, including France, Poland, the Netherlands, Sweden, Belgium, and Italy, implemented their laws earlier or closer to the deadline in some cases.
The European Commission is examining infringement proceedings against countries that have not implemented the directive or did not implement it on time and are not actively working toward a solution.
Despite different implementation speeds, the European Commission is working on harmonized guidance, guidelines, and interpretation materials.
The BSI registration portal in Germany has been online since January 2026. The BSI extension period for registration runs until July 31, 2026.
Other EU countries are gradually activating their registration portals and authority structures.
Companies should not wait to be contacted by authorities. They should take the initiative themselves, register, and begin implementation in a structured manner.
How SECJUR Supports NIS2 Compliance
SECJUR offers a structured approach to NIS2 compliance through its ISMS platform.
The risk-management module helps companies document the ten measures under §30 BSIG, work through them systematically, identify gaps, and prepare the results for management.
The module guides users through each step of a standardized process and provides recommendations for action.
According to the original article, companies report up to 50 percent faster implementation compared with traditional consulting.
Costs start at €10,000, depending on company size, sector, and existing security structure.
The platform also supports the NIS2 reporting process and the deadlines of 24 hours, 72 hours, and one month.
Further information is available on the SECJUR NIS2 compliance page.
Conclusion
NIS2 is a long-term regulatory framework for cybersecurity and risk management.
Affected companies must pay particular attention to registration, the ten risk-management measures, the incident-response process, and management involvement.
Companies with an existing ISO 27001 ISMS already have many of the necessary foundations. Companies without established security infrastructure need to build the required measures accordingly.
A structured and early implementation helps companies address the requirements transparently and establish the necessary security structures.
FAQ
What is the NIS2 Directive?
The NIS2 Directive (EU 2022/2555) is a European cybersecurity directive implemented in Germany through the NIS2 Implementation Act.
When did NIS2 enter into force in Germany?
The NIS2UmsuCG has been in force since December 6, 2025.
How many companies in Germany are affected?
According to the original article, around 29,500 companies in Germany are affected.
What risk-management measures does NIS2 require?
NIS2 defines ten key measures, including risk analysis, incident management, supply-chain security, cryptography, access control, MFA, communications security, and network monitoring.
What reporting deadlines apply to security incidents?
The three-stage procedure includes an initial report within 24 hours, further information after 72 hours, and a complete report within one month.
What fines can be imposed for violations?
For essential entities, fines can reach up to €10 million or 2 percent of worldwide annual revenue. For important entities, the limit is €7 million or 1.4 percent.