Skip to main content
Definition

NIS2 Compliance

NIS2 (Network and Information Security Directive 2) is the EU cybersecurity directive mandatory since October 2024; the German implementing act distinguishes "particularly important" and "important" entities. It extends NIS1 with new sectors (energy, health, transport, critical supply chains), mandates risk management, requires incident reporting within 24/72 hours and makes management personally liable.

In detail

NIS2 Compliance in practice

NIS2 obliges affected organisations to implement ten minimum cybersecurity measures: risk analysis policy, incident handling, business continuity, supply chain security, vulnerability management, cybersecurity awareness training, encryption, access control, asset management and multi-factor authentication. Reporting deadlines: initial notification within 24h, detailed report within 72h, final report 30 days after the incident. In Germany the NIS2UmsuCG (NIS2 Implementation and Cybersecurity Strengthening Act) transposes the directive.

Penalties under Section 65 BSIG: up to EUR 10 million — or up to 2 % of total turnover where that exceeds EUR 500 million — for particularly important entities, and up to EUR 7 million or 1.4 % for important entities.