Skip to content
SECURITYSQUAD
Back to the blog

NIS2 for Mid-Sized Companies: Directive, Duties & Compliance

2026-06-20 · by SECURITYSQUAD

NIS2 for Mid-Sized Companies: Directive, Duties & Compliance

The NIS2 directive raises the level of cybersecurity across Europe significantly – and affects far more organisations than its predecessor. Many mid-sized companies now fall within its scope for the first time, often without realising it. Those who understand the obligations and act early gain a durable advantage, both in regulatory and security terms.

What is the NIS2 directive?

NIS2 (Directive (EU) 2022/2555) is the European legal framework for a uniformly high level of network and information security. It replaces the first NIS directive from 2016, considerably widens the range of affected sectors, and tightens requirements, reporting obligations and sanctions. As a directive, NIS2 does not apply directly but must be transposed into national law by each EU member state. In Germany this is done through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), which essentially recasts the BSI Act (BSIG).

Who is affected by NIS2?

NIS2 distinguishes two categories of regulated organisation. The German transposition refers to particularly important entities (equivalent to the directive's "essential" entities) and important entities. Both categories are subject to the same security obligations; they differ mainly in the intensity of supervision and the level of potential fines.

Sectors

The scope covers 18 sectors, split into sectors of high criticality and other critical sectors – including:

  • Energy, transport, banking and financial market infrastructures
  • Health, drinking water, wastewater
  • Digital infrastructure, ICT service management, public administration, space
  • Postal and courier services, waste management, chemicals, food
  • Manufacturing/production, digital services (e.g. online marketplaces, search engines, social networks) and research

Size thresholds

Whether an organisation is regulated depends on sector and size:

  • Particularly important entities: generally from 250 employees, or more than EUR 50 million annual turnover and EUR 43 million balance sheet total.
  • Important entities: generally from 50 employees, or more than EUR 10 million annual turnover and balance sheet total.

Regardless of size, certain entities always fall within scope – for example qualified trust service providers, DNS service providers, TLD registries, providers of public telecommunications networks, and critical infrastructure (KRITIS) operators. A self-assessment is therefore essential: there is no individual notification from the authorities; every organisation must determine its own applicability.

Impact on the supply chain

NIS2 reaches well beyond the circle of directly regulated companies. Affected entities must incorporate supply-chain security into their risk management and impose requirements on service providers and suppliers. In practice this means that even smaller businesses that are not themselves regulated are drawn in contractually when they act as a supplier to an affected company – for example through security clauses, audit rights or evidence required in tenders. Demonstrable information security thus becomes a competitive and procurement criterion, and is fast turning from a "nice-to-have" into a basic prerequisite for business relationships.

Which obligations does NIS2 bring?

Risk management and technical and organisational measures

At the core of the obligations is a risk-based management system with a minimum catalogue of technical and organisational measures. These include, among others:

  • Risk analysis and concepts for the security of information systems
  • Handling of security incidents (incident response)
  • Business continuity, backup management and crisis management
  • Supply-chain security
  • Security in acquisition, development and maintenance
  • Access control, asset management and cryptography concepts
  • Cyber hygiene, training and the use of multi-factor authentication

Reporting obligations and deadlines

NIS2 introduces a staged reporting procedure for significant security incidents to the BSI:

  1. Early warning within 24 hours of becoming aware
  2. Incident notification within 72 hours with an initial assessment
  3. Final report within one month

The 24-hour deadline challenges many organisations – it requires well-rehearsed processes and clear responsibilities.

Management responsibility and liability

NIS2 explicitly holds senior management accountable. Management bodies must approve the risk-management measures, oversee their implementation and attend training regularly. Violations carry significant fines – for particularly important entities up to EUR 10 million or 2% of worldwide annual turnover, for important entities up to EUR 7 million or 1.4%. This responsibility cannot be fully delegated.

Status of the German transposition: the NIS2UmsuCG

Germany missed the EU transposition deadline (October 2024) by a wide margin but has since completed the process. The Bundestag passed the NIS2UmsuCG on 13 November 2025, and the Bundesrat approved it on 20 November 2025. Following promulgation in the Federal Law Gazette (BGBl. 2025 I No. 301 of 5 December 2025), the law entered into force on 6 December 2025 – with no general transition period. The registration obligation for affected entities with the BSI ran until 6 March 2026; late registration remains possible and is strongly recommended. Estimates suggest that around 29,500 companies in Germany newly fall under the rules. Risk management, reporting and registration obligations therefore apply immediately – action is needed now. The BSI gains extended supervisory and enforcement powers and may request evidence, audits and security assessments. Postponing implementation risks not only fines but also personal liability for management and reputational damage in the event of an incident.

NIS2, ISO 27001 and IT-Grundschutz

NIS2 does not prescribe a specific standard but requires appropriate measures commensurate with the risk. An established information security management system (ISMS) is the most pragmatic route: organisations working to ISO/IEC 27001 or BSI IT-Grundschutz already cover most NIS2 requirements in a structured way – from risk analysis through technical and organisational measures to the continual improvement process. An ISMS also provides the evidence that supervisory authorities expect. In this way a compliance obligation becomes a robust security foundation.

Concrete steps towards NIS2 compliance

  1. Determine applicability – check sector, size and special provisions.
  2. Assess your status – e.g. with a Cyber Risk Check per DIN SPEC 27076 as a fast entry point.
  3. Gap analysis – compare the current state against NIS2 duties and an ISMS standard.
  4. Prioritise measures – implement in a risk-based, pragmatic and audit-proof way.
  5. Establish reporting and governance processes – embed 24/72-hour capability and management responsibility.
  6. Maintain evidence – ensure documentation and continual improvement.

How SECURITYSQUAD supports you

SECURITYSQUAD supports you from applicability analysis to demonstrable implementation. As a company certified to ISO 27001 based on IT-Grundschutz and a member of the Alliance for Cyber Security, we combine regulatory knowledge with hands-on practice: ISMS and ISO 27001 consulting, IT-Grundschutz, NIS2 and KRITIS implementation, external ISO / CISO as a Service, penetration testing, security awareness, and managed security services up to our Managed SIEM & SOC. This way you achieve NIS2 compliance not as a paper exercise but as measurably greater resilience.

Read more: Expertise & Services · Cyber Risk Check · ISO 27001 & IT-Grundschutz