The directive widens the circle of affected organizations considerably, demands ten concrete minimum measures and puts senior management personally on the hook.
Roughly 29,500 organizations in Germany fall under NIS2, many of them without knowing it. Those never covered by critical-infrastructure rules are the most surprised.
Early warning within 24 hours, notification within 72 hours, final report within one month. Without defined ownership the first deadline passes before anyone has decided anything.
Management must approve the measures, oversee their implementation and undergo training. Where they fail to, they are personally liable, and fines reach 10 million euro or 2 percent of global annual turnover.
Germany's implementing act, the NIS2UmsuCG, has been in force since December 2025 and brings new duties to roughly 29,500 organizations. We establish whether it applies to you, measure your controls against Article 21 and build the reporting chain the law requires.
Sector and size decide: from 50 employees or 10 million euro turnover you are an important entity, from 250 employees or 50 million euro an essential one. We assess each of your legal entities separately and clarify the registration duty with the BSI.
The directive lists ten minimum measures, from risk analysis through supply chain security to cryptography. We assess each one for what is already in place and what is missing.
Early warning within 24 hours, notification within 72 hours, final report within one month. We define who reports, who decides and what is submitted at each stage.
Article 20 requires management to approve the measures, oversee their implementation and undergo training. That duty cannot be delegated, so we make its fulfilment traceable and evidenced.