NIS2: who is affected, what it requires and what happens if you fail to comply
With the NIS2 Directive (EU) 2022/2555, the EU has significantly extended cybersecurity obligations. Germany has transposed it into its BSI Act. It no longer applies only to operators of critical infrastructure, but to many mid-sized companies, some of which do not yet know they are in scope.
Who NIS2 applies to
Two questions decide: which sector is the company active in, and how large is it? The directive lists 18 sectors, including energy, transport, health, digital infrastructure, waste management, chemicals, food, the manufacture of machinery, vehicles and electronic equipment, and digital services. Within these sectors, NIS2 generally applies from medium size, meaning 50 or more employees or more than EUR 10 million in annual turnover and balance sheet total.
Companies are classified as "essential" or "important" entities. Some providers are covered regardless of size, such as certain telecommunications and DNS service providers. For Germany alone, the federal government estimated around 29,500 affected companies.
Suppliers are affected indirectly: NIS2 requires companies in scope to take the security of their supply chain into account, and many pass requirements and evidence obligations on to their service providers. Whether NIS2 applies to your company is best checked with your national authority or your legal counsel.
The 18 sectors at a glance
The directive splits the sectors into two groups. Companies in the first group are more likely to be classified as essential entities, companies in the second as important entities. The exact classification also depends on size.
- Sectors of high criticality (Annex I): energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management for other businesses, public administration and space.
- Other critical sectors (Annex II): postal and courier services, waste management, manufacture and distribution of chemicals, production and distribution of food, manufacturing (including medical devices, electronic and optical products, electrical equipment, machinery and vehicles), digital providers such as online marketplaces, search engines and social networks, and research.
Manufacturers in particular often underestimate whether they are in scope. A machine builder with 80 employees can fall under NIS2, even though it has nothing to do with critical infrastructure in the traditional sense.
What NIS2 requires
- Risk management: Article 21 lists measures such as risk analysis, incident handling, business continuity, supply chain security, vulnerability handling, training, cryptography, access control and multi-factor authentication.
- Reporting: significant incidents must be reported in stages, with an early warning within 24 hours, a notification within 72 hours and a final report after one month.
- Registration: companies in scope must register with the competent authority, in Germany the BSI.
- Management accountability: management must approve the measures, oversee their implementation and take part in training regularly.
What happens if you fail to comply
The directive provides for much higher fines than before: for essential entities up to EUR 10 million or 2 percent of worldwide annual turnover, for important entities up to EUR 7 million or 1.4 percent, whichever is higher. On top of that, authorities can issue orders and carry out audits.
The biggest change is personal accountability: managers who breach their obligations can be held liable for resulting damage. IT security becomes an explicit responsibility of company management and can no longer be delegated to the IT department alone.
First steps in five points
- Check whether you are in scope: review sector and size, for example with the guidance of your national authority, and involve legal counsel if in doubt.
- Register: companies in scope register with the competent authority and name a point of contact.
- Take stock: compare existing measures with the requirements of Article 21 and record what is missing.
- Assign responsibility: management approves the measures and takes part in training. Every requirement gets a named owner.
- Reporting and supply chain: decide who reports an incident within 24 hours, and include your key suppliers and service providers in the assessment.
None of these steps is done in a few days. What matters is to start and to document the status so that it can be demonstrated at any time.
How Sightadel helps with implementation
Sightadel is our compliance and GRC platform. It does not start with an empty spreadsheet, but with a ready-made structure for NIS2, ISO 27001 and other standards. Every requirement gets a named owner, a person rather than a department. Every piece of evidence has an expiry date, and Sightadel sends a reminder before it becomes outdated.
One piece of evidence can count toward several standards, so companies that already have ISO 27001 quickly see what is still missing for NIS2. Supplier risks can be assessed in the same platform. For audits, external auditors get their own read-only access and see only the audit scope. Management can follow the state of implementation at any time.
For the technical part, vulnerability handling under Article 21, veyrisk provides continuous scans and a dedicated NIS2 evidence report. If you would like to know where your company stands on NIS2, get in touch with us.
This article is a general overview and not legal advice. The legal text and the guidance of the competent authority are authoritative.
FAQ
Frequently asked questions
Does NIS2 apply to suppliers that are not in scope themselves?
Not directly. However, companies in scope must take the security of their supply chain into account and therefore often ask their suppliers for evidence, contract clauses or questionnaires. Suppliers who can provide such evidence have a clear advantage.
Is an ISO 27001 certification enough for NIS2?
Not automatically, but it covers a large part. Many requirements of Article 21 are also found in ISO 27001. NIS2 additionally requires registration, the staged reporting obligations and training for management, among other things.
Who checks compliance?
The competent national authority, in Germany the BSI. It can request evidence, order audits and impose measures and fines in case of violations. Its powers go further for essential entities.
What has to happen after a security incident?
Significant incidents are reported in stages: an early warning within 24 hours, a notification with an initial assessment within 72 hours and a final report after one month. It should be clear beforehand who decides and who reports.
How exactly do Sightadel and veyrisk help?
Sightadel maps the NIS2 requirements with owners, evidence and deadlines and shows the progress. veyrisk provides the technical evidence for vulnerability handling and a dedicated NIS2 report.
Blog
More articles
neonotu at CES 2027 in Las Vegas
From January 6 to 9, 2027, we show Sightadel, veyrisk and Valar at booth 50123 in the Venetian Expo, with live demos and short …
Why continuous vulnerability management now belongs in every business
New vulnerabilities are published every week, and attackers look for systems that have not been updated yet. Why one scan a yea…
Cyber Resilience Act: the first reporting obligations apply since September 2026
Since September 11, 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and se…
Contact
Reputation takes years. Destruction takes seconds.
Talk to us before somebody else does. The first conversation is free and we reply the same business day.