
You registered with BSI before the deadline. Good. Your CISO has been writing risk assessments. Better. Your board still thinks “we’re compliant” because the registration went through - and they’re wrong. Registration is paperwork. The duties themselves took effect in December 2025 with no transition period, and the fines for the most serious breaches reach €10 million or 2% of global turnover.
Organizations now pulled into scope in Germany
Regulated sectors across the directive
Maximum fine of €10million - or 2% of global turnover
First audits and enforcement actions arrive
1
NIS 2 is an EU directive, transposed into German law on 6 December 2025, that expanded cybersecurity obligations to roughly 29,500 organizations across 18 sectors - energy, transport, healthcare, banking, drinking water, digital infrastructure, public administration, postal, chemicals, food, the manufacture of medical devices and electronics, digital providers and research. It splits regulated organizations into two tiers - particularly important and important entities - with fines up to €10M or €7M respectively. It introduces personal liability for executives, a strict incident-reporting cadence of 24 hours, 72 hours and a final report one month after that, and a requirement to document compliance. There is no NIS 2 certificate to “get” - only evidence to produce, and ISO/IEC 27001:2022 is the most defensible way to produce it.
2
NIS 2 stops being someone else’s problem the moment one of these describes you.
The threshold catches scale-ups, not just enterprises. If your headcount or turnover crosses the line and your sector is listed, you are in scope - directly.
Regulators are watching these categories first. Expect to be early in the queue when enforcement begins.
Short answer: it covers 70–80% of NIS 2’s substantive expectations. Long answer: it depends on your sector and scope - which is exactly what a gap assessment settles.
Even if you’re not directly in scope, your customers are - and they will push their obligations down the supply chain. That’s how regulation works.
3
We could write four paragraphs of marketing copy - instead:
Avoid the €10M downside. Not hypothetical. The first enforcement actions arrive in 2027 - and the fines reach €10 million or 2% of global turnover.
Replace BSI registration with audit-ready evidence. Most companies that registered have nothing real to show yet. The ones that do will be tomorrow’s preferred suppliers.
Cover NIS 2, ISO/IEC 27001:2022, DORA and VAIT from one evidence base. These regimes overlap substantially in what they ask of your documentation. Assemble it once instead of three times.
Protect executives personally. NIS 2 introduces director-level liability and puts implementation and monitoring on the management body itself.
Win contracts competitors lose. Procurement teams in regulated sectors are starting to require NIS 2 evidence from suppliers. Be ready first.
4
NIS 2 reaches across eighteen sectors, grouped by how critical they are to society and the economy. If your sector is listed and you cross the size threshold, the directive applies - directly to you, and indirectly to the suppliers you depend on.
5
Every regulated organization is classed into one of two tiers. The substantive duties are much the same — the penalty ceiling and the intensity of oversight are not.
STRICTEST OVERSIGHT
The most critical operators - energy, transport, banking, digital infrastructure and the like at scale. They carry the heaviest exposure under the directive.
€10 million
2%
Personal
24h / 72h / 30d
MODERATE OVERSIGHT
Still in scope, still regulated, still audited - but a tier below the most critical operators in both oversight intensity and penalty ceiling.
€7 million
1.4%
Personal
24h / 72h / 30d
6
NIS 2 imposes a fixed reporting cadence on significant incidents - three deadlines, each measured from the moment you become aware. Missing them is itself a breach.
An initial incident notification to the authorities within 24 hours of becoming aware of a significant incident.
A fuller incident report within 72 hours - assessment, severity, indicators of compromise and any cross-border impact.
A final report within one month: root cause, the full course of the incident and the mitigation measures applied.
NIS 2 makes cybersecurity a board-level duty: directors are personally accountable for governance, and audit-ready evidence is required by 2027. Documented governance is the only defense.
7
There's no certificate to chase - the law sets out duties, not a certification scheme. Three of them are yours to discharge. The fourth is where an accredited audit can come in.
STEP 1
The law defines two categories of entity - by sector, headcount and turnover - and leaves the classification to you. There is no procedure for the BSI, or anyone else, to confirm that you're in scope. Where the reading is genuinely unclear, that's a question for your lawyers, not for us.
STEP 2
Ten areas your measures have to cover, at minimum. The standard is proportionality, not perfection: size, exposure, cost and likely impact all count. And compliance has to be documented, not just achieved. Much of what an ISO/IEC 27001 ISMS already documents answers the same questions.
STEP 3
Registration within three months of falling in scope. Incident reports at 24 hours, at 72 hours, and a final report a month after the 72-hour one. Fixed deadlines, no proportionality.
STEP 4
Operators of critical installations have to evidence what they've implemented - through a security audit, an examination or a certification, on a date the BSI sets. Everyone else owes no periodic evidence at all. An accredited ISO/IEC 27001:2022 certification is one of those three routes, and it's the one we perform: one audit, one coordinator, a certificate recognised in over 100 countries through the IAF MLA.
8
NIS 2, ISO/IEC 27001:2022, DORA and VAIT overlap substantially in their substantive requirements. There is no reason to assemble the same evidence three times. A single evidence pool feeds them all, and ISO/IEC 27001:2022 is the part of it that can be independently certified - evidence a regulator doesn't have to take on trust when they ask, “show me your controls are effective.” One coordinator owns the engagement from application through certification.
ISO/IEC 27001:2022
DORA
VAIT
ISO 22301
IEC 62443
ISO/IEC 27019
KRITIS
Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.
9