
NIS2 compliance implemented pragmatically
The NIS2 Implementation Act has applied in Germany since 6 December 2025 without a transition period. NMS guides companies from the applicability assessment to audit-proof continuous operation.
ISO 27001 · Microsoft Solution Partner
Since December 2025, NIS2 has been applicable law in Germany, without a transition period. From an honest applicability assessment to audit-proof continuous operation: a structured path to compliance. Even for those who are late.
What lies behind NIS2
NIS2 is the EU's response to a simple observation: cyberattacks no longer target just power plants and major banks. The directive significantly expands the circle of obligated companies and raises the standard of what is considered an appropriate protective measure.
In Germany, the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) transposes the EU requirements into national law. It came into force on 6 December 2025, without a transition period. The three-month registration deadline with the BSI expired on 6 March 2026; the obligation to register itself remains in place.
Entry into force EU: 16 January 2023. From this date, the directive was binding for all member states.
In force in Germany: 6 December 2025, immediately applicable.
Registration obligation: Deadline 6 March 2026 expired; late registration with the BSI remains mandatory.
Wider scope: Around 29,500 companies in Germany fall under the regulation: a multiple compared to NIS1.
Affected? Probably yes
The NIS2UmsuCG distinguishes between essential and important entities. The decisive factors are sector and company size.
Essential entities
Threshold: from 250 employees or more than €50m annual turnover and more than €43m balance sheet total. Sectors include: energy, transport, banking and financial market infrastructures, healthcare, drinking water and waste water, digital infrastructure (DNS, TLD, data centres, cloud), ICT service providers in B2B, public administration, space.
Important entities
Threshold: from 50 employees or more than €10m annual turnover or balance sheet total. Sectors include: postal and courier services, waste management, chemicals, food production and distribution, manufacturing (medical devices, electronics, mechanical engineering, motor vehicles), digital providers, research.
Even below the thresholds: the supply chain
Anyone supplying essential or important entities will have to follow suit contractually. NIS2 explicitly demands security requirements along the entire supply chain: critical providers, subcontractors and ICT service providers are thus effectively also obliged.
Ten minimum measures, no pick-and-choose
Article 21 of the directive prescribes the catalogue of measures. Each item must be demonstrated independently:
Risk analysis and security concepts: systematic assessment of risks to network and information systems.
Incident management: incident response, defined, practised, documented, including reporting chains.
Business continuity and crisis management: backup, recovery, BCM and crisis management team, tested rather than merely documented.
Supply chain security: assessment and management of risks regarding suppliers and ICT third parties.
Procurement, development, maintenance: security in procurement, in in-house development, in vulnerability management.
Effectiveness measurement: KPIs, internal audits and reviews that prove measures are effective.
Cyber hygiene and training: basic practices plus regular awareness and mandatory training.
Cryptography and encryption: concepts for data at rest and in transit.
Human resources, access, asset management: HR security, least-privilege access, complete asset inventory.
MFA and secured communication: multi-factor authentication, secured voice, video and text communication.
The catalogue applies regardless of classification. Differences exist in the supervisory regime, fine framework and audit depth, not in the substantive obligation.
Reporting obligations and consequences
A staged chain applies to reportable incidents: early warning within 24 hours, initial assessment after 72 hours, final report after one month.
The fine framework for essential entities is up to €10m or 2% of total worldwide annual turnover, and for important entities up to €7m or 1.4%, whichever is higher. Added to this are orders and audits by supervisory authorities, the potential prohibition from exercising management functions, and personal liability of executive management for risk management obligations.
Three packages, building on each other
- Package 1 covers assessment and gap analysis: Applicability analysis (sector, threshold, supply chain), maturity check along the ten mandatory measures, gap list with effort and priority, management presentation. Typical duration: 3 to 5 weeks.
- Package 2 covers implementation and hardening: Identity hardening with MFA, Conditional Access and PIM, EDR/XDR and logging, backup and recovery tests, policies and training, incident playbooks. With Microsoft 365 and Azure as the preferred platform. Typical duration: 3 to 9 months.
- Package 3 covers continuous operation and monitoring: Security operations, patch and vulnerability management, quarterly maturity reviews, awareness programme, support during external audits, as a Managed Service with a monthly fixed fee.
Five phases, each with an artefact
Baseline assessment: workshops with IT, executive management and business departments. Artefact: current state analysis and applicability report.
Gap analysis and roadmap: alignment with mandatory measures and supplementary standards such as ISO 27001 and BSI IT-Grundschutz. Artefact: action plan with estimated effort.
Implementation: technical and organisational measures, hardening, policy development, contract adjustments, training. Artefact: evidence and a trained workforce.
Verification: internal audit, tabletop exercises, recovery tests. Artefact: audit report and compliance file.
Continuous operation: monitoring, incident handling, regular reviews. Artefact: ongoing reports and audit readiness.
- Step 1 of 5Baseline assessmentArtefact: current state analysis and applicability report
- Step 2 of 5Gap analysis and roadmapArtefact: action plan with estimated effort
- Step 3 of 5ImplementationArtefact: evidence and a trained workforce
- Step 4 of 5VerificationArtefact: audit report and compliance file
- Step 5 of 5Continuous operationArtefact: ongoing reports and audit readiness
No project without evidence: each phase ends with an outcome that can be presented.
Why NMS
New Media Service is an IT system house in Singen that operates, hardens and documents Microsoft infrastructures. NMS is itself ISO 27001-certified and a Microsoft Solution Partner: Microsoft 365 and Azure are home platforms, not newsletter knowledge. The approach is based on established information security standards, service management on ITIL, and project management on transparent stage gates.
Legal notice: NMS provides technical and organisational IT consultancy, not legal advice within the meaning of the Legal Services Act (Rechtsdienstleistungsgesetz). The deadlines, thresholds and fine frameworks mentioned here reflect the state of information as of the date specified and do not replace individual legal evaluation. Binding information is provided by the competent authorities (in particular the BSI) and specialised legal counsel. As of: July 2026
My company is below the thresholds. Am I out of scope?
Directly, presumably yes; indirectly, often no. Anyone acting as a supplier to essential or important entities will be held contractually obligated. Furthermore, there are sectors where size criteria do not apply (such as trust services, DNS, TLD registries). An individual assessment is the only reliable answer.
We already have an ISO 27001 certificate. Is that enough for NIS2?
A very good foundation, but not a free pass. ISO 27001 covers a large portion; NIS2 adds specific reporting obligations, supply chain requirements, training obligations and the personal liability of executive management. We perform an alignment and close the gaps in a targeted manner without having to reinvent the ISMS.
How long does a NIS2 implementation realistically take?
The assessment typically takes 3 to 5 weeks. Depending on maturity, implementation takes between three and nine months. Those who are already well positioned finish faster; those starting from scratch need longer. A reliable timeline is established following the gap analysis.
The registration deadline on 6 March 2026 has passed. What now?
No reason to panic, but also no reason to wait. Registration with the BSI remains mandatory: late registration is better than none and noticeably reduces risk. Concurrently, what counts is proof that risk management measures are taking effect: set up late registration cleanly, close gaps, build documentation.
Do we need our own CISO for NIS2?
Not necessarily, but the role must be filled, by in-house personnel or as CISO-as-a-Service. NMS takes on this function upon request with clear escalation and reporting structures.
How much does a NIS2 implementation cost?
The assessment can be calculated as a fixed price, depending on locations, number of employees and complexity. Implementation is offered based on the roadmap, while continuous operation runs on a monthly fixed fee. A first reliable offer follows after an initial 30-minute consultation.

Solutions in a new dimension.
One conversation is enough to find out where IT, Microsoft Cloud and AI can take real weight off day-to-day business.
Your contact: Jan Emmerich, Managing Director