NIS2 and telecom infrastructure: obligations, deadlines and implementation
Trusted Advisor for sourcing of IT & telecommunications
Why NIS2 now affects every telecom infrastructure
NIS2 has been in force since 6 December 2025 with no transition period
The NIS2 Implementation Act has applied since 6 December 2025 and requires around 29,500 companies to take demonstrable cybersecurity measures. Anyone operating networks, sites or cloud services must now be able to prove their own IT and network security. There is no grace period.
In a nutshell:
- In Germany, NIS2 has applied directly since 6 December 2025, with no transition period for technical and organisational measures.
- It affects medium and large companies from 18 sectors with at least 50 employees and 10 million euros in annual turnover.
- Management is personally liable, and fines can reach up to 10 million euros or 2 percent of global annual turnover.
- The telecom infrastructure is at the core: networks, connections and carrier supply chains are among the audited risk areas.
The solution:
Assess your scope properly, analyse the gaps and implement the telecom-side measures in a structured way. Step by step instead of as a firefighting exercise.
What this article covers:
Who is affected by NIS2, which ten minimum requirements the BSIG sets out, which reporting deadlines apply and which measures your telecom infrastructure concretely needs.
>20%
Ersparnis
99,99%
Verfügbarkeit
24/7
Support
What is NIS2 implementation for the telecom infrastructure?
NIS2 implementation for the telecom infrastructure refers to all technical and organisational measures with which a company adapts its networks, connections and telecommunications services to the NIS2 Implementation Act (NIS2UmsuCG). It covers risk management, supply chain security, reporting processes and access controls for the entire network environment. The law has applied since 6 December 2025 and provides for no transition period. The goal is demonstrable, documented cybersecurity across all critical communication paths.
Delighted customers
NIS2 in Germany: status and legal situation 2026
The NIS2 Implementation and Cybersecurity Strengthening Act reforms the BSI Act and transposes EU Directive 2022/2555 into German law. It came into force on 6 December 2025, after Germany had missed the EU deadline of October 2024.
Since its promulgation, the security measures under Section 30 BSIG and the tightened reporting obligations have applied directly. The law provides for no grace period for implementation. Affected companies must be able to demonstrate compliance from day one.
The BSI is the competent supervisory authority with investigative, enforcement and sanctioning powers. The BSI reporting and information portal (MIP) has been online since 6 January 2026. The registration deadline ended on 6 March 2026. Anyone who missed it must act immediately and risks a fine.

Am I affected? Thresholds and 18 sectors

1
Size threshold: from 50 employees and 10 million euros turnover
NIS2 covers medium and large companies. An entity qualifies as an important entity if it has at least 50 employees and reaches at least 10 million euros in annual turnover or balance sheet total.
Large companies with 250 or more employees or 50 million euros in turnover count as essential entities subject to stricter supervision.
2
18 sectors, including digital infrastructure and ICT services
18 sectors from Annexes 1 and 2 of the BSIG are affected. These include energy, transport, health, finance, drinking water and digital infrastructure such as cloud, DNS, CDN and managed services.
ICT service providers, manufacturing and research also fall under it. Classification is done through self-assessment based on sector, size and activity.
3
Critical infrastructure operators regardless of size
Operators of critical facilities qualify as essential entities by law, regardless of headcount or turnover.
Anyone previously below the threshold of cybersecurity regulation becomes supervision-relevant for the first time under NIS2. The circle of monitored entities multiplies compared with the old BSIG.
The ten minimum requirements under Section 30 BSIG
Section 30 BSIG requires at least ten technical and organisational measures. They follow an all-hazards approach and must be documented and implemented according to the state of the art. For the telecom infrastructure, they are the core of any implementation.
- Risk analysis and concepts for the security of information systems
- Handling of security incidents, including reporting processes
- Business continuity, backup management and recovery
- Supply chain security, meaning also the carriers and service providers used
- Security in the procurement, development and maintenance of network and IT systems
- Procedures for assessing the effectiveness of the security measures
- Training on cyber hygiene and staff awareness
- Cryptography and encryption wherever appropriate
- Access control, personnel security and asset management concepts
- Multi-factor authentication and secured voice, video and text communication
Reporting obligations: 24-hour early warning, 72-hour report, monthly final report
Significant security incidents must be reported to the BSI once the company is registered in the portal. Reporting follows a three-stage procedure with fixed deadlines.
1
24 hours: early warning
Within 24 hours of becoming aware of a significant incident, an initial early warning must be sent to the BSI.
It describes the incident in broad terms and states whether an unlawful or cross-border background is suspected.
2
72 hours: incident report
Within 72 hours, the detailed report follows, with assessment, severity, impact and indicators of compromise.
If personal data is involved, the data protection authority must also be informed.
3
One month: final report
A final report is due no later than one month after the incident report.
It fully describes the cause, course, measures taken and impact of the incident.
Telecom-specific measures for NIS2 implementation
For NIS2, the telecom infrastructure is not a side topic but a central risk area. Networks, connections and communication services link all sites and systems. Securing them covers a large part of the legal requirements.
How SAVECALL orchestrates NIS2 implementation for your telecom infrastructure
SAVECALL is not a carrier, but your independent sourcing and consulting partner for secure network and communication solutions.
With more than 80 carrier partners, SAVECALL connects the NIS2 requirements with concrete telecom measures. The key building blocks:
- Cyber Security & risk management as the basis for Section 30 BSIG and documented security concepts
- Zero Trust & multi-factor authentication for access control and secured communication
- SASE & network segmentation to separate critical areas and secure distributed sites
- Penetration testing to assess the effectiveness of the security measures in place
- Consulting & supply chain audit for evaluating carriers and service providers along the supply chain
Conclusion: NIS2 implementation as a roadmap, not a firefighting exercise
NIS2 is mandatory and has applied since 6 December 2025 with no transition period. The decisive question is no longer whether measures are needed, but whether they are documented, effective and auditable.
Those who approach implementation as an ordered roadmap replace haste with structure. Scoping, gap analysis and a step-by-step build-up of the telecom-side measures create demonstrability and reduce management’s liability risk.
The first step is always the same: clarify your own scope and make the gaps in your telecom infrastructure visible.
How SAVECALL supports you
SAVECALL assesses your NIS2 scope with you, identifies the gaps in your telecom infrastructure and plans the right measures, vendor-neutral, prioritised and with clear responsibility.

Written by
Frank Frommknecht
Key Account Consultant, SAVECALL
Has guided companies for over 20 years in selecting and optimising their connectivity solutions. His focus: making complex telecommunications understandable from the customer’s perspective and strategically finding the right solution.
Articles that may also interest you
Why
Telecom & IT sourcing. Worldwide. Carrier-independent.
Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.
- 80+ carriers worldwide
- One point of contact
- One SLA
- One portal: mySAVECALL
- Min. 20% savings
25+
years of experience
40+
Employees
80+
Partner
1400+ Clients
What drives you forward – & what drives
Book a free expert consultation
Frequently asked questions about NIS2 implementation
Your company is affected by NIS2 if it operates in one of the 18 covered sectors and has at least 50 employees and at least 10 million euros in annual turnover or balance sheet total. The sectors include, among others, digital infrastructure, ICT services, energy, transport, health and finance. Operators of critical facilities are considered affected regardless of their size. Classification is done through a self-assessment. If the assignment remains unclear, you should have your sector, size class and activity assessed in a structured way.
The registration deadline with the BSI expired on 6 March 2026. It began when the law came into force on 6 December 2025 and ran for three months. Registration is done through the BSI reporting and information portal, which has been online since 6 January 2026. A prerequisite is an ELSTER organisation certificate. Anyone who missed the deadline must register immediately, since even late registration can be penalised with a fine.
Anyone who does not implement NIS2 risks substantial fines and personal liability of management. For essential entities, penalties are up to 10 million euros or 2 percent of global annual turnover, whichever is higher. On top of this come the BSI’s enforcement and supervisory powers, up to the temporary prohibition of activities. Late registration or missing incident reports are also sanctionable. Reputational damage and loss of customer trust often follow as well.
Under NIS2, management bears direct responsibility and is personally liable. It must approve the risk management measures, oversee their implementation and undergo regular cybersecurity training. This duty cannot be fully delegated. Breaches can lead to personal liability of the governing bodies. NIS2 thus makes cybersecurity a matter for top management and anchors it at board and management level. Documented involvement of management in decisions is therefore a central proof of compliance.
As a supplier, you can be indirectly affected by NIS2, even if you do not reach the thresholds yourself. NIS2 explicitly obliges affected companies to secure their supply chain. Your customers will therefore pass security requirements on to you contractually and demand evidence. Anyone who fails to meet these requirements risks losing contracts. It is therefore worth aligning your own security organisation with NIS2, even if the law does not formally apply to you directly.
NIS2 and your telecom infrastructure are closely connected, because networks and communication services are among the central audited risk areas. The minimum requirements under Section 30 BSIG include supply chain security, network segmentation, multi-factor authentication and secured communication, among others. These very points directly concern your connections, carriers and internal networks. A secure, documented telecom infrastructure covers a large part of the obligations. It is therefore not a sideshow but a foundation of the entire NIS2 implementation.











