Skip to content
← Back to blog

NIS2 Is Here: What the New Cybersecurity Law Means for Mid-Market Companies

#NIS2#Cybersecurity#Compliance#SMEs#BSI

If your company operates in one of 18 regulated sectors and has at least 50 employees or more than EUR 10 million in annual revenue, the NIS2 obligations have applied to you since December 6, 2025 — immediately and with no transition period. Germany’s NIS2 implementation act, the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), is finally in force after years of delay, and the long-running debate about “whether this will even happen” is over. If you’re still waiting, you’re not early anymore — you’re already late.

TL;DR

  • In force since December 6, 2025: The German Bundestag (Nov 13, 2025) and Bundesrat (Nov 21, 2025) passed the NIS2UmsuCG. The obligations apply with no transition period.
  • Who is affected: medium-sized and large companies in 18 regulated sectors — as a rule of thumb, from 50 employees or more than EUR 10 million in revenue. Critical infrastructure (KRITIS) operators and certain digital services are covered regardless of size.
  • The registration deadline has passed: The 3-month registration window with the BSI (Germany’s Federal Office for Information Security) ended on March 6, 2026. By mid-2026, only around 11,500 of an estimated ~29,500 affected companies had registered.
  • What you have to do: register with the BSI, implement risk management per Section 30 of the BSIG (Germany’s IT security act, 10 mandatory areas), and follow a three-stage incident reporting regime (24 h / 72 h / 1 month).
  • A board-level issue with liability: Management must approve and oversee the measures (Section 38) — with personal liability. Fines are possible.
  • This is guidance for orientation, not legal advice.

What is NIS2 in the first place?

NIS2 is short for the NIS 2 Directive (EU) 2022/2555 — an EU-wide framework designed to ensure a common, high level of cybersecurity across the Union. An EU directive doesn’t apply directly, though; each member state has to transpose it into national law. In Germany, that happened with the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG).

For a long time, it was unclear when — or whether — the German law would arrive at all; the draft was stuck for years. Since December 6, 2025, that uncertainty is gone. The law is in force, and there is no gentle ramp-up: the obligations apply with no transition period. That sets NIS2 apart from many other regulations, where companies could take a year or two after entry into force to comply.

If you want to keep track of the EU and German federal regulations that matter right now, our regulatory radar offers a continuously updated overview.

Is my company affected?

That’s the first question to settle — and it has two dimensions: sector and size.

The 18 regulated sectors include, among others:

  • energy
  • transport
  • banking / financial markets
  • healthcare
  • drinking water and wastewater
  • digital infrastructure and ICT services
  • public administration
  • postal and courier services
  • waste management
  • chemicals
  • food
  • manufacturing
  • digital providers

It’s the last items on that list — manufacturing and digital providers — that catch far more mid-market companies than most management teams expect. NIS2 is no longer just a “critical infrastructure” topic for power and water utilities.

The size threshold as a rule of thumb: if you operate in one of these sectors and have 50 or more employees or over EUR 10 million in annual revenue, you should assume you’re in scope. Beyond that, the law distinguishes between important and particularly important entities — that classification determines how intensively you’ll be supervised.

Important: critical infrastructure (KRITIS) operators and certain digital services are covered regardless of size — for them, headcount doesn’t matter.

The precise classification — including whether you count as “important” or “particularly important” — belongs in a proper legal assessment. But the rough self-check against sector and the 50-employee / EUR 10 million threshold is something you can and should do right away.

The registration deadline has already passed — now what?

Let’s be honest: if you haven’t registered with the BSI yet, you’re not alone — but you are past due. The obligation is to register with the BSI within 3 months of falling in scope. Since the law entered into force on December 6, 2025, that deadline expired for most companies on March 6, 2026.

The numbers show how big the gap is: by mid-2026, only around 11,500 of an estimated ~29,500 affected companies had registered. Put differently: more than half of the companies in scope have not yet met their registration obligation.

Don’t take that as a sign that enforcement will be lax. Quite the opposite: if you’re not registered yet, don’t put it off any longer — complete the registration promptly and tackle the substantive obligations in parallel. A missed deadline doesn’t get better by ignoring the risk management requirements on top of it.

What exactly do I have to do?

NIS2 is more than an entry in a register. The key blocks of obligations are:

1. Registration with the BSI

Within 3 months of falling in scope. See above — for many companies, this deadline has already passed.

2. Risk management measures under Section 30 BSIG

The law lists 10 mandatory areas you have to cover with technical and organizational measures. They include, among others:

  • risk analysis
  • incident handling
  • business continuity / crisis management
  • supply chain security
  • secure procurement and development
  • cryptography
  • access control
  • training

This is not a “let’s buy a firewall” exercise — it’s an end-to-end management system. Supply chain security in particular is underestimated: you’re not only responsible for your own IT, you also have to keep your service providers and suppliers in view.

3. Three-stage incident reporting to the BSI

When a significant security incident occurs, a staggered reporting scheme applies:

StageDeadline
Early warningwithin 24 hours
Follow-up reportwithin 72 hours
Final reportwithin 1 month

Twenty-four hours is very tight in a real emergency. That means you need predefined processes, clear responsibilities, and a plan for who reports during an incident — before the systems are already on fire, not after.

4. Management responsibility (Section 38)

This is the point many management teams haven’t fully grasped yet: management must approve the risk management measures and oversee their implementation — with personal liability. NIS2 cannot simply be delegated away to the IT department. Ultimate responsibility stays at the top.

On top of that, fines are possible in case of violations.

Why NIS2 is a board-level issue — not just an IT topic

The biggest misconception we at Rocket-Monkeys see in conversations with mid-market companies: NIS2 gets treated as a purely technical project to “hand off to IT”. Section 38 makes that impossible. When management is personally liable, cybersecurity becomes a question of corporate governance — comparable to occupational safety or data protection.

In practice, that means the measures have to be documented, approved by management, and demonstrably overseen. When it counts — during an audit or after an incident — what matters is not what you “intended to do”, but what you can prove.

Where NIS2 has its limits — and where it doesn’t

Honesty is part of the deal: NIS2 doesn’t automatically make you secure. A checked-off compliance list is no guarantee against attacks — it’s a minimum standard and an accountability framework. Conversely, a high actual level of security won’t protect you from fines if the formal obligations (registration, reporting channels, documented management approval) aren’t met.

And: the precise scoping is complex in its details. Whether you’re “important” or “particularly important”, whether a subsidiary counts separately, whether a company spanning multiple businesses falls into several sectors — those are questions for legal and technical experts. This article is guidance for orientation, not legal advice.

Your next steps

If you want to know where you stand, a pragmatic order of operations is:

  1. Clarify whether you’re in scope — check sector and size threshold.
  2. Catch up on registration if you haven’t done it yet (the deadline has already passed for many).
  3. Assess your current state against Section 30 — which of the 10 mandatory areas are already covered, and where are the gaps?
  4. Set up reporting processes — who reports within 24 h, to whom, with what information?
  5. Bring management on board — document approval and oversight (Section 38).

At Rocket-Monkeys, we help mid-market companies from Munich and beyond with exactly this translation work: from legal text to concrete, technically implemented, and provable measures — from risk analysis through access control and cryptography to secure development. If you’re unsure whether and how much NIS2 affects you, let’s talk — no strings attached.

Just drop us a line at info@rocket-monkeys.com for a free initial consultation. We’ll work out where you stand together — no scaremongering, just a clear view of what needs to happen now.

This article is for general information purposes and is not legal advice. Whether and how the law applies depends on your individual situation.