NMS - New Media Service GmbH
Hands on a laptop keyboard, a keyring and a smartphone beside them
AI-generated

NIS2 – EU Cybersecurity Directive

NIS2 briefly explained: Who is affected, which obligations apply, and which deadlines are decisive in Germany.

IT Glossary

In brief

NIS2 is the EU directive aimed at increasing cybersecurity. In Germany, the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) implements the requirements; it has applied since 6 December 2025 without a transition period.

Around 29,500 companies across 18 sectors are affected, divided into essential and important entities. Sector and size are decisive. Smaller companies are also indirectly bound by obligations if they supply affected entities. NIS2 requires security measures along the supply chain.

At the core of the obligations are ten minimum measures (including risk management, incident response, business continuity, supply chain security, cryptography, multi-factor authentication), staged reporting obligations from 24 hours to one month, as well as the personal responsibility of senior management. Details on the page NIS2 Compliance.