NIS 2 - EU DIRECTIVE - BSI

Registered does not mean ready

Hexagonal badge with checkmark and text saying Compliant NIS 2 Proks Certification.

You registered with BSI before the deadline. Good. Your CISO has been writing risk assessments. Better. Your board still thinks “we’re compliant” because the registration went through - and they’re wrong. Registration is paperwork. The duties themselves took effect in December 2025 with no transition period, and the fines for the most serious breaches reach €10 million or 2% of global turnover.

Hexagonal badge with checkmark and text saying Compliant NIS 2 Proks Certification.
29,500

Organizations now pulled into scope in Germany

18

Regulated sectors across the directive

€10M / 2%

Maximum fine of €10million  - or 2% of global turnover

2027

First audits and enforcement actions arrive

1

THE DIRECTIVE

What NIS 2 actually is

A directive.
Not a certificate.
The first audit is in 2027.

Registration is paperwork - it tells the regulator you exist. It does not show your controls work. That is what the audit is for, and the BSI says who owes one, and when.

NIS 2 is an EU directive, transposed into German law on 6 December 2025, that expanded cybersecurity obligations to roughly 29,500 organizations across 18 sectors - energy, transport, healthcare, banking, drinking water, digital infrastructure, public administration, postal, chemicals, food, the manufacture of medical devices and electronics, digital providers and research. It splits regulated organizations into two tiers - particularly important and important entities - with fines up to €10M or €7M respectively. It introduces personal liability for executives, a strict incident-reporting cadence of 24 hours, 72 hours and a final report one month after that, and a requirement to document compliance. There is no NIS 2 certificate to “get” - only evidence to produce, and ISO/IEC 27001:2022 is the most defensible way to produce it.

2

THE FIT

Who actually needs to act

NIS 2 stops being someone else’s problem the moment one of these describes you.

01
You are in one of the 18 sectors with 50+ employees or €10M+ revenue.

The threshold catches scale-ups, not just enterprises. If your headcount or turnover crosses the line and your sector is listed, you are in scope - directly.

02
You are a public-sector entity, digital-infrastructure provider or healthcare cloud.

Regulators are watching these categories first. Expect to be early in the queue when enforcement begins.

03
You already have ISO/IEC 27001:2022 and want to know if it is enough.

Short answer: it covers 70–80% of NIS 2’s substantive expectations. Long answer: it depends on your sector and scope - which is exactly what a gap assessment settles.

04
You are a critical supplier to a regulated entity.

Even if you’re not directly in scope, your customers are - and they will push their obligations down the supply chain. That’s how regulation works.

If none of these describe you - wait. If even one does - yesterday was the best time to start.

3

THE PAYOFF

What you actually get from getting ready

We could write four paragraphs of marketing copy - instead:

I.

Avoid the €10M downside. Not hypothetical. The first enforcement actions arrive in 2027 - and the fines reach €10 million or 2% of global turnover.

II.

Replace BSI registration with audit-ready evidence. Most companies that registered have nothing real to show yet. The ones that do will be tomorrow’s preferred suppliers.

III.

Cover NIS 2, ISO/IEC 27001:2022, DORA and VAIT from one evidence base. These regimes overlap substantially in what they ask of your documentation. Assemble it once instead of three times.

IV.

Protect executives personally. NIS 2 introduces director-level liability and puts implementation and monitoring on the management body itself.

V.

Win contracts competitors lose. Procurement teams in regulated sectors are starting to require NIS 2 evidence from suppliers. Be ready first.

4

SCOPE - THE 18 SECtorS

Eighteen sectors, two levels of criticality

NIS 2 reaches across eighteen sectors, grouped by how critical they are to society and the economy. If your sector is listed and you cross the size threshold, the directive applies - directly to you, and indirectly to the suppliers you depend on.

SECTORS OF HIGH CRITICALITY
01
Energy
02
Transport
03
Banking
04
Healthcare
05
Financial markets
06
Drinking water
07
Waste water
08
Digital infrastructure
09
Public administration
OTHER CRITICAL SECTORS
10
Postal
11
Courier
12
Chemicals
13
Food
14
Waste Management
15
Digital providers
16
Research
17
Manufacturing - electronics
18
Manufacturing - medical devices

5

TWO ENTITY TIERS

The tier you fall into sets the size of the fine

Every regulated organization is classed into one of two tiers. The substantive duties are much the same — the penalty ceiling and the intensity of oversight are not.

Particularly important entities

STRICTEST OVERSIGHT

The most critical operators - energy, transport, banking, digital infrastructure and the like at scale. They carry the heaviest exposure under the directive.

MAXIMUM FINE

€10 million

OR % OF GLOBAL TURNOVER

2%

EXECUTIVE LIABILITY

Personal

REPORTING DUTIES

24h / 72h / 30d

Important entities
‍

MODERATE OVERSIGHT

Still in scope, still regulated, still audited - but a tier below the most critical operators in both oversight intensity and penalty ceiling.

MAXIMUM FINE

€7 million

OR % OF GLOBAL TURNOVER

1.4%

EXECUTIVE LIABILITY

Personal

REPORTING DUTIES

24h / 72h / 30d

6

INCIDENT REPORTING

The clock starts the moment you notice

NIS 2 imposes a fixed reporting cadence on significant incidents - three deadlines, each measured from the moment you become aware. Missing them is itself a breach.

24 hours
Early warning

An initial incident notification to the authorities within 24 hours of becoming aware of a significant incident.

72 hours
Detailed report

A fuller incident report within 72 hours - assessment, severity, indicators of compromise and any cross-border impact.

30 days
Final report

A final report within one month: root cause, the full course of the incident and the mitigation measures applied.

Personal liability for executives

NIS 2 makes cybersecurity a board-level duty: directors are personally accountable for governance, and audit-ready evidence is required by 2027. Documented governance is the only defense.

7

THE DUTIES, IN ORDER

What the law asks, in four steps - and where we come in

There's no certificate to chase - the law sets out duties, not a certification scheme. Three of them are yours to discharge. The fourth is where an accredited audit can come in.

01

STEP 1

Scope. Yours to determine.

The law defines two categories of entity - by sector, headcount and turnover - and leaves the classification to you. There is no procedure for the BSI, or anyone else, to confirm that you're in scope. Where the reading is genuinely unclear, that's a question for your lawyers, not for us.

02

STEP 2

02 - Measures. Ten areas, proportionately.

Ten areas your measures have to cover, at minimum. The standard is proportionality, not perfection: size, exposure, cost and likely impact all count. And compliance has to be documented, not just achieved. Much of what an ISO/IEC 27001 ISMS already documents answers the same questions.

03

STEP 3

03 - Reporting and registration. On the clock.

Registration within three months of falling in scope. Incident reports at 24 hours, at 72 hours, and a final report a month after the 72-hour one. Fixed deadlines, no proportionality.

04

STEP 4

04 - Evidence. Where we come in.

Operators of critical installations have to evidence what they've implemented - through a security audit, an examination or a certification, on a date the BSI sets. Everyone else owes no periodic evidence at all. An accredited ISO/IEC 27001:2022 certification is one of those three routes, and it's the one we perform: one audit, one coordinator, a certificate recognised in over 100 countries through the IAF MLA.

8

ONE PROGRAM - MANY REGIMES

Build the evidence once. Use it four times.

NIS 2, ISO/IEC 27001:2022, DORA and VAIT overlap substantially in their substantive requirements. There is no reason to assemble the same evidence three times. A single evidence pool feeds them all, and ISO/IEC 27001:2022 is the part of it that can be independently certified - evidence a regulator doesn't have to take on trust when they ask, “show me your controls are effective.” One coordinator owns the engagement from application through certification.

REGIMES ONE EVIDENCE POOL CAN FEED

ISO/IEC 27001:2022

DORA

VAIT

ISO 22301

IEC 62443

ISO/IEC 27019

KRITIS

GET IN TOUCH

Start your application process
now

Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.

9

FAQs

Clear answers, the same way we run an audit

Is there a "NIS 2 certificate" we can get?

We already hold ISO/IEC 27001:2022 - is that enough for NIS 2?

We are not directly in scope - does NIS 2 still affect us?

We registered with BSI before the deadline - aren't we compliant?

Which tier are we in, and what are the fines?

What can Proks offer?