NIS 2 Directive: A Guide for Companies

NIS2: New standards for cyber security in Europe

NIS2 Directive: What Companies Need to Know

With NIS2, the EU is tightening the security requirements for IT and network systems. Companies from almost all sectors are affected. Those who fail to prepare in good time risk fines and operational risks. Now is the time to adapt structures and processes at an early stage.

The question: How well prepared is your company for the implementation of the NIS2 requirements?

Auf den Punkt gebracht:

  • Extended scope for more sectors and company sizes
  • Reporting obligations and stricter supervision by national authorities
  • Clear accountability obligations for management and supply chains
  • Significantly higher sanctions for non-compliance

Die Lösung: SAVECALL assesses your NIS2 readiness, defines your implementation roadmap, and connects the regulatory requirements with concrete measures for your network and communications infrastructure.

Worum es in diesem Beitrag geht: What is changing under NIS2, who is affected, which deadlines and penalties apply, and how to prepare your organization step by step.










What is new about the NIS2 directive?

In July 2016, the Directive on the security of Network and Information Systems (NIS) was issued. The aim of this directive was to increase cyber resilience throughout the European Union through regulatory measures. It focused on strengthening cybersecurity capabilities at national level, improving cooperation between member states and embedding cybersecurity in the DNA of organizations.

In 2023, the European Union adopted a new version of the Network and Information Security Directive. This “NIS-2” aims to bring the EU up to date and create a higher level of cybersecurity and resilience in European Union organizations. EU member states were required to transpose NIS2 into national law by October 18, 2024, a deadline Germany missed.

The new directive extends the scope to other sectors and focuses on providing guidance to ensure consistent implementation across EU member states. NIS2 defines two categories of facilities: important and essential facilities.

Important facilities:

  • Digital provider
  • Manufacturer
  • Postal and courier services
  • Waste management
  • Chemical products
  • Food
  • Research facilities

Essential companies:

  • Energy
  • Road, rail, air and water transportation
  • Water
  • Health
  • Public administration
  • IT services
  • Banking and finance

Companies in both categories must meet the same requirements, but follow different monitoring and sanctioning rules. Essential companies must comply with supervisory requirements from the introduction of the NIS2 Directive, while important companies are subject to ex-post supervision, meaning that if the authorities receive evidence of non-compliance, action will be taken.

Which companies are affected by NIS2?

Large companies: over 250 employees or a turnover of more than 50 million euros.

Medium-sized companies: over 50 employees or a turnover of more than 10 million euros.

EU member states can extend these requirements if a company meets certain criteria that indicate a key role for society, the economy or for certain sectors or types of services.

Registration of essential and important entities

By April 2025, Member States had to identify the essential and important facilities that fall within the scope of the NIS2 Directive. Member States may allow entities to register themselves. To register, contracting entities had to provide at least the following information:

  • their name, address and registration number
  • the sector or sub-sector under which they fall within the scope of NIS2
  • their updated contact details
  • Member States in which they operate
  • the list of IP addresses assigned to them

Current status in Germany: the German implementation act (NIS2UmsuCG) entered into force on December 6, 2025, after Germany missed the original EU deadline of October 18, 2024, there is no transition period. Affected entities have been registering via the BSI reporting portal since January 6, 2026. The statutory three-month deadline expired on March 6, 2026. Since only part of the roughly 29,500 affected companies had registered by then, the BSI communicated a grace period until July 31, 2026, which does not retroactively remove the original obligation.

Improved collaboration (CSIRT platform)

Another important element of the new directive is the intention to improve cooperation between EU member states on cyber incidents and threats. The European Union Agency for Cybersecurity (ENISA) is tasked with setting up a European vulnerability disclosure database to facilitate knowledge sharing between Member States.

Obligation to report incidents

As already established for the NIS-1 Directive, each EU Member State has a central contact point for compliance with the Directive and a coordinating CSIRT (Computer Security Incident Response Team) for incident reporting or a competent authority. The Federal Office for Information Security (BSI) is responsible for checking the affected companies in Germany. Incidents with a significant impact must be reported by the essential and important bodies without unnecessary delay:

  • A preliminary report must be submitted within 24 hours of becoming aware of an incident.
  • A full incident report must be submitted within 72 hours, including an assessment of the incident and its impact.
  • A detailed final report describing the incident in detail, including cross-border effects, must be submitted within one month.

In this respect, the Directive encourages Member States to simplify the incident reporting process by establishing a single point of contact for incidents in order to reduce the administrative burden, including for incidents affecting several Member States.

The CSIRT or, where applicable, the competent authority must report to ENISA every three months on the incidents, using anonymized information. With all this information, ENISA then in turn reports on EU incidents every six months. This reporting helps organizations and Member States learn from other incidents and is a key change in the NIS2 Directive.

Focus on important supply chains

Recent incidents around the world have highlighted the importance of continuity within critical supply chains, which is why the NIS2 Directive introduces this as one of the key areas of focus. Individual companies are responsible for considering cyber security risks in their own supply chains as well as in their relationships with their suppliers.

This requirement can have an indirect impact on many suppliers who do not fall within the scope of the NIS2 Directive, but who may supply services or products to an entity falling within scope. Their customer could therefore impose a minimum cybersecurity maturity on the supplier. The supplier is not supervised by the national authorities in relation to NIS2, but by their customer. So even if your company does not fall within the scope, it may have an impact depending on the service and industry.

Management accountability

Another important addition to NIS-1 is the accountability that the new directive assigns to the management of the organizations affected by the scope of application. Management is required to take responsibility for the maturity of cybersecurity. This includes, among other things, conducting risk assessments and approving risk treatment plans to be implemented. In order to implement these measures, management must participate in cybersecurity training. The directive even suggests that not only management but also employees should be trained to deepen their knowledge of cybersecurity.

Complexity of case law

Under the NIS2 Directive, essential and significant institutions are considered to be under the jurisdiction of the Member State in which they provide their services.

Where the entity provides services in more than one Member State, it should be subject to the jurisdiction of each of those Member States. Entities providing services outside the EU or dependent on the EU should ensure the continuity of their EU services in case of interruption of their activities outside the EU.

Sanctions for non-compliance

The NIS-1 Directive provided for sanctions for non-compliance by OESs and DSPs, while the NIS 2 Directive provides for more severe sanctions for non-compliance, including fines of up to 10% of a company’s annual turnover.

For essential entities: administrative pecuniary penalties of up to €10,000,000 or at least 2% of the total worldwide annual turnover of the company to which the essential entity belongs in the previous financial year, whichever is higher.

For important companies: fines of up to €7,000,000 or at least 1.4% of the total worldwide annual turnover of the company to which the important company belongs in the previous financial year, whichever is higher. In Germany, failure to register with the BSI can additionally result in fines of up to €500,000.

How do you prepare your organization for NIS2?

Based on our experience with NIS, you will learn the key aspects your organization should consider to be on the right path to NIS2 compliance.

1. Anticipate and start preparing

Timely preparation is a key element in an organization’s journey to compliance. The support of top management, the approval of stakeholders and the provision of the necessary budget and resources will take time.

Be prepared for delays and commit to strict planning with fixed deadlines. In addition, the implementation of some of the new requirements can be seen as quick wins and defined in advance, e.g. escalation of incidents and reporting to the relevant authorities.

2. Identify critical processes in your company

The starting point on the road to compliance is to identify the organization’s critical services, processes and assets that provide the essential service defined in NIS2.

One method to achieve this is to conduct an organization-wide business impact assessment to identify the organization’s critical processes and their dependency on network and information systems. A critical element for scoping is defining the business impact criteria that cause a process, site or facility to fall within the scope.

3. Implement a risk and information security management system

Companies that fall within the scope of the NIS2 directive must manage their information security risks. In order to meet this requirement, a risk and information security management system must be introduced.

Such an information security management system aims to identify, address and monitor the company’s information security risks and ensure that responsibilities are defined and key processes are functional, such as:

  • Risk management and security guidelines for information systems
  • Treatment and management of incidents
  • Business continuity and crisis management (backups, disaster recovery)
  • Security of the supply chain
  • Security in the procurement, development and maintenance of networks and information systems, including the handling and disclosure of vulnerabilities
  • Strategies and procedures for assessing the effectiveness of cybersecurity risk management measures
  • Cryptography and encryption, multi-level authentication
  • People, awareness and training

4. Initiate your IT supply chain security management process

Take a close look at your IT suppliers (partners), especially those that are critical to the continuity of your operations. Knowing the weaknesses in your IT supply chain and the security gaps at your suppliers will help you tackle the lengthy process of fixing your contractual, operational or technical vulnerabilities.

5. Establish a cyber-oriented culture

One of the most frequently mentioned elements, but one that is difficult to implement in many companies, is a cyber-oriented culture and a mature awareness of information security among employees. Employees should be aware of their roles and responsibilities in relation to the information security ecosystem.

IT staff should have the necessary knowledge to carry out the required checks. And last but not least, management should see cyber security as a key element for the company’s survival in this digital age.





How SAVECALL supports your NIS2 implementation

Our team of experts have mastered NIS1 and are here to help you with NIS2 too. SAVECALL can help you assess your readiness, define your compliance roadmap, determine your scope, set up and implement your risk and security management frameworks, secure your IT supply chain and optimize your cybersecurity awareness program.

Conclusion: implement NIS2 now, do not wait

NIS2 has been binding law in Germany since December 2025, there is no transition period left. If your organization has already missed the BSI registration deadline, catch up now, the fines and personal liability for management are real. More important than registration itself, however, is the risk management behind it: organizations that bring their network and communications infrastructure into NIS2 compliance early reduce regulatory exposure and gain more resilient, better documented IT security.

Frank Frommknecht, Key Account Consultant bei SAVECALL

Written by

Frank Frommknecht

Key Account Consultant, SAVECALL

Has supported companies for over 20 years in selecting and optimizing their connectivity solutions. His focus: making complex telecommunications understandable from the customer’s perspective and finding the right strategic solution.

Why

Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.

Sources

  • Regulation (EU) 2022/2555 (NIS2 Directive), Official Journal of the European Union, December 27, 2022
  • Act implementing the NIS2 Directive and regulating key aspects of information security management in federal administration (NIS2UmsuCG), in force since December 6, 2025
  • Federal Office for Information Security (BSI), NIS2 reporting portal and registration obligation under Section 33 BSIG, as of July 2026
  • ENISA, NIS2 Technical Guidance on Cybersecurity Risk Management Measures, 2025

Frequently asked questions about NIS2

Is the NIS2 Directive already in force in Germany?

Yes, the German implementation act (NIS2UmsuCG) entered into force on December 6, 2025, after Germany missed the EU transposition deadline of October 2024. There is no transition period, obligations apply immediately. Affected companies had to register with the BSI within three months, and the statutory deadline expired on March 6, 2026. Since only part of the roughly 29,500 affected companies had registered by then, the BSI granted a grace period until July 31, 2026.

Which companies are affected by NIS2?

Companies with more than 50 employees or over 10 million euros in annual turnover in one of the 18 sectors covered by the BSI Act are generally affected, including IT services, energy, healthcare, transport, postal services, waste management, and banking and finance. The directive distinguishes between important and essential entities, which must meet the same requirements but are subject to different supervisory rules. Suppliers to affected companies may also indirectly need to meet requirements imposed by their customers, even if not in scope themselves.

By when must companies register for NIS2?

The statutory registration deadline expired on March 6, 2026, three months after the NIS2UmsuCG entered into force. Since only part of the affected companies had registered by then, the BSI communicated a grace period to industry associations until July 31, 2026. This does not retroactively remove the original obligation, companies that missed the deadline are still considered in default. Registration takes place through the BSI reporting portal, available since January 6, 2026.

What penalties apply for non-compliance with NIS2?

Failure to register can result in fines of up to 500,000 euros. Violations of risk management or reporting obligations carry significantly higher sanctions: essential entities risk fines of up to 10 million euros or 2 percent of global annual turnover, important entities up to 7 million euros or 1.4 percent, whichever is higher. Management is also personally liable for implementing the risk management measures.

What do companies need to implement to become NIS2 compliant?

At its core, NIS2 requires documented risk and information security management with incident detection, reporting processes within 24 hours, 72 hours and one month, business continuity planning, supply chain security, cryptography and multi-factor authentication, and regular training for management and staff. Management must actively approve and oversee these measures, not merely sign off on them formally.

How does SAVECALL support companies with NIS2 implementation?

As an independent sourcing and advisory partner, SAVECALL assesses the NIS2 readiness of network and communication infrastructure, defines the implementation roadmap, and connects regulatory requirements with concrete technical measures such as zero trust, SASE, cyber security, and penetration testing. This turns legal obligations into a practical, prioritized set of measures instead of pure theory.

Articles that may also interest you

What drives you forward – & what drives

Book a free expert consultation