NIS2 and telecom infrastructure: obligations, deadlines and implementation

Why NIS2 now affects every telecom infrastructure

NIS2 has been in force since 6 December 2025 with no transition period

The NIS2 Implementation Act has applied since 6 December 2025 and requires around 29,500 companies to take demonstrable cybersecurity measures. Anyone operating networks, sites or cloud services must now be able to prove their own IT and network security. There is no grace period.

In a nutshell:

  • In Germany, NIS2 has applied directly since 6 December 2025, with no transition period for technical and organisational measures.
  • It affects medium and large companies from 18 sectors with at least 50 employees and 10 million euros in annual turnover.
  • Management is personally liable, and fines can reach up to 10 million euros or 2 percent of global annual turnover.
  • The telecom infrastructure is at the core: networks, connections and carrier supply chains are among the audited risk areas.

The solution:

Assess your scope properly, analyse the gaps and implement the telecom-side measures in a structured way. Step by step instead of as a firefighting exercise.

What this article covers:
Who is affected by NIS2, which ten minimum requirements the BSIG sets out, which reporting deadlines apply and which measures your telecom infrastructure concretely needs.

What is NIS2 implementation for the telecom infrastructure?

NIS2 implementation for the telecom infrastructure refers to all technical and organisational measures with which a company adapts its networks, connections and telecommunications services to the NIS2 Implementation Act (NIS2UmsuCG). It covers risk management, supply chain security, reporting processes and access controls for the entire network environment. The law has applied since 6 December 2025 and provides for no transition period. The goal is demonstrable, documented cybersecurity across all critical communication paths.

Delighted customers

The NIS2 Implementation and Cybersecurity Strengthening Act reforms the BSI Act and transposes EU Directive 2022/2555 into German law. It came into force on 6 December 2025, after Germany had missed the EU deadline of October 2024.

Since its promulgation, the security measures under Section 30 BSIG and the tightened reporting obligations have applied directly. The law provides for no grace period for implementation. Affected companies must be able to demonstrate compliance from day one.

The BSI is the competent supervisory authority with investigative, enforcement and sanctioning powers. The BSI reporting and information portal (MIP) has been online since 6 January 2026. The registration deadline ended on 6 March 2026. Anyone who missed it must act immediately and risks a fine.

NIS2 legal situation 2026 and BSI supervision for the telecom infrastructure at SAVECALL

Am I affected? Thresholds and 18 sectors

Checking NIS2 scope by thresholds and sectors for the telecom infrastructure at SAVECALL

Size threshold: from 50 employees and 10 million euros turnover

NIS2 covers medium and large companies. An entity qualifies as an important entity if it has at least 50 employees and reaches at least 10 million euros in annual turnover or balance sheet total.

Large companies with 250 or more employees or 50 million euros in turnover count as essential entities subject to stricter supervision.

18 sectors, including digital infrastructure and ICT services

18 sectors from Annexes 1 and 2 of the BSIG are affected. These include energy, transport, health, finance, drinking water and digital infrastructure such as cloud, DNS, CDN and managed services.

ICT service providers, manufacturing and research also fall under it. Classification is done through self-assessment based on sector, size and activity.

Critical infrastructure operators regardless of size

Operators of critical facilities qualify as essential entities by law, regardless of headcount or turnover.

Anyone previously below the threshold of cybersecurity regulation becomes supervision-relevant for the first time under NIS2. The circle of monitored entities multiplies compared with the old BSIG.

The ten minimum requirements under Section 30 BSIG

Section 30 BSIG requires at least ten technical and organisational measures. They follow an all-hazards approach and must be documented and implemented according to the state of the art. For the telecom infrastructure, they are the core of any implementation.

  • Risk analysis and concepts for the security of information systems 
  • Handling of security incidents, including reporting processes 
  • Business continuity, backup management and recovery 
  • Supply chain security, meaning also the carriers and service providers used 
  • Security in the procurement, development and maintenance of network and IT systems 
  • Procedures for assessing the effectiveness of the security measures 
  • Training on cyber hygiene and staff awareness 
  • Cryptography and encryption wherever appropriate 
  • Access control, personnel security and asset management concepts 
  • Multi-factor authentication and secured voice, video and text communication 

Reporting obligations: 24-hour early warning, 72-hour report, monthly final report

Significant security incidents must be reported to the BSI once the company is registered in the portal. Reporting follows a three-stage procedure with fixed deadlines.

24 hours: early warning

Within 24 hours of becoming aware of a significant incident, an initial early warning must be sent to the BSI.

It describes the incident in broad terms and states whether an unlawful or cross-border background is suspected.

72 hours: incident report

Within 72 hours, the detailed report follows, with assessment, severity, impact and indicators of compromise.

If personal data is involved, the data protection authority must also be informed.

One month: final report

A final report is due no later than one month after the incident report.

It fully describes the cause, course, measures taken and impact of the incident.

Telecom-specific measures for NIS2 implementation

For NIS2, the telecom infrastructure is not a side topic but a central risk area. Networks, connections and communication services link all sites and systems. Securing them covers a large part of the legal requirements.

How SAVECALL orchestrates NIS2 implementation for your telecom infrastructure

SAVECALL is not a carrier, but your independent sourcing and consulting partner for secure network and communication solutions. 

With more than 80 carrier partners, SAVECALL connects the NIS2 requirements with concrete telecom measures. The key building blocks: 

Conclusion: NIS2 implementation as a roadmap, not a firefighting exercise

NIS2 is mandatory and has applied since 6 December 2025 with no transition period. The decisive question is no longer whether measures are needed, but whether they are documented, effective and auditable.

Those who approach implementation as an ordered roadmap replace haste with structure. Scoping, gap analysis and a step-by-step build-up of the telecom-side measures create demonstrability and reduce management’s liability risk. 

The first step is always the same: clarify your own scope and make the gaps in your telecom infrastructure visible.

How SAVECALL supports you

SAVECALL assesses your NIS2 scope with you, identifies the gaps in your telecom infrastructure and plans the right measures, vendor-neutral, prioritised and with clear responsibility.

Frank Frommknecht, Key Account Consultant at SAVECALL

Written by

Frank Frommknecht

Key Account Consultant, SAVECALL

Has guided companies for over 20 years in selecting and optimising their connectivity solutions. His focus: making complex telecommunications understandable from the customer’s perspective and strategically finding the right solution.

Articles that may also interest you

Why

Selection & operation of worldwide connectivity & cloud infrastructure. Without vendor risk & unnecessary costs.

What drives you forward – & what drives

Book a free expert consultation

Frequently asked questions about NIS2 implementation

Is my company affected by NIS2?

Your company is affected by NIS2 if it operates in one of the 18 covered sectors and has at least 50 employees and at least 10 million euros in annual turnover or balance sheet total. The sectors include, among others, digital infrastructure, ICT services, energy, transport, health and finance. Operators of critical facilities are considered affected regardless of their size. Classification is done through a self-assessment. If the assignment remains unclear, you should have your sector, size class and activity assessed in a structured way.

By when did I have to register with the BSI?

The registration deadline with the BSI expired on 6 March 2026. It began when the law came into force on 6 December 2025 and ran for three months. Registration is done through the BSI reporting and information portal, which has been online since 6 January 2026. A prerequisite is an ELSTER organisation certificate. Anyone who missed the deadline must register immediately, since even late registration can be penalised with a fine.

What happens if I do not implement NIS2?

Anyone who does not implement NIS2 risks substantial fines and personal liability of management. For essential entities, penalties are up to 10 million euros or 2 percent of global annual turnover, whichever is higher. On top of this come the BSI’s enforcement and supervisory powers, up to the temporary prohibition of activities. Late registration or missing incident reports are also sanctionable. Reputational damage and loss of customer trust often follow as well.

What role does management play in NIS2?

Under NIS2, management bears direct responsibility and is personally liable. It must approve the risk management measures, oversee their implementation and undergo regular cybersecurity training. This duty cannot be fully delegated. Breaches can lead to personal liability of the governing bodies. NIS2 thus makes cybersecurity a matter for top management and anchors it at board and management level. Documented involvement of management in decisions is therefore a central proof of compliance.

Does NIS2 also apply to me as a supplier to an affected company?

As a supplier, you can be indirectly affected by NIS2, even if you do not reach the thresholds yourself. NIS2 explicitly obliges affected companies to secure their supply chain. Your customers will therefore pass security requirements on to you contractually and demand evidence. Anyone who fails to meet these requirements risks losing contracts. It is therefore worth aligning your own security organisation with NIS2, even if the law does not formally apply to you directly.

How are NIS2 and my telecom infrastructure connected?

NIS2 and your telecom infrastructure are closely connected, because networks and communication services are among the central audited risk areas. The minimum requirements under Section 30 BSIG include supply chain security, network segmentation, multi-factor authentication and secured communication, among others. These very points directly concern your connections, carriers and internal networks. A secure, documented telecom infrastructure covers a large part of the obligations. It is therefore not a sideshow but a foundation of the entire NIS2 implementation.