Cyber Security

NIS 2 Compliance: Which Companies Are Affected and What Measures Are Now Required

Content

Table

Authors

Chi Hieu Ta

Cyber Security Expert

What is NIS-2? 

The original NIS Directive was introduced by the European Union to respond to the growing cyber risks facing network and information systems. At the same time, it aimed to create a uniform framework, as cybersecurity requirements in individual member states had previously varied significantly. Another objective was to systematically build national cybersecurity capabilities within the EU. 

With the NIS-2 Directive, the EU is consistently pursuing these goals. It significantly expands the scope, tightens the requirements for affected organizations, and completely replaces the previous NIS Directive.  

In addition to the requirements for companies, NIS-2 now also obliges EU member states to develop and implement a national cybersecurity strategy. This is intended to ensure that cybersecurity is systematically strengthened not only at the corporate level, but also at the state level. 

Particularly relevant for companies, however, are the specific organizational, technical, and operational requirements of the Directive. These include, among other things, risk management measures, securing supply chains, handling security incidents, and reporting obligations to the competent authorities.  


Which companies are affected by NIS-2? 

With the NIS-2 Directive, the EU is expanding the scope of affected companies. While the original NIS Directive covered only a few critical industries, NIS-2 now includes a total of 18 sectors. As a result, significantly more companies fall under the new cybersecurity requirements. 

The affected sectors include, among others: 

Sectors of high criticality 

  • Energy 

  • Transport 

  • Banking and financial market infrastructures 

  • Health 

  • Drinking water and wastewater 

  • Digital infrastructure 

  • IT and Managed Service Providers 

  • Public administration 

  • Space 

Other critical sectors 

  • Postal and courier services

  • Waste management

  • Chemical industry

  • Food production and processing

  • Manufacturing

  • Digital services

  • Research organizations

Within these sectors, NIS-2 also distinguishes between different subsectors and types of entities. This allows for a more precise determination of which organizations actually fall under the scope of the Directive.  

Important or essential entity? 

In Germany, the Federal Office for Information Security (BSI) is the competent authority for the implementation and supervision of NIS-2. For companies based in Germany, the NIS-2 requirements are therefore specified by the BSI Act (BSIG). This involves a division into two categories: essential entities and important entities.

Which category applies depends primarily on three factors: 

  1. The industry or sector of the company 

  2. The type of services provided 

  3. The size of the company (number of employees and turnover) 

Operators of critical infrastructures, certain DNS and trust service providers, as well as operators of public telecommunications networks, for example, are considered essential entities. 

For many companies, however, the size consideration is most relevant. Simply put: 

Essential entities 

  • at least 250 employees or 

  • an annual turnover exceeding €50 million and an annual balance sheet total exceeding €43 million 

Important entities

  • at least 50 employees or 

  • an annual turnover exceeding €10 million and an annual balance sheet total exceeding €10 million 

Companies that do not reach these thresholds do not fall under NIS-2 in many cases. However, there are exceptions, such as for operators of critical infrastructures or certain digital services. Therefore, applicability should always be assessed individually.

How to find out if your company is affected 

For most companies, a simple check using the following questions is sufficient: 

  1. Does my company belong to one of the 18 NIS-2 sectors? 

  2. Do we meet the relevant size criteria? 

  3. Do we provide specific digital or critical services? 

If all questions can be answered with "Yes", NIS-2 applicability is likely and should be assessed in detail. 

What role does the BSI play? 

In Germany, the Federal Office for Information Security (BSI) is the competent authority for the implementation and supervision of NIS-2. 

Affected companies must register their status with the BSI and be able to prove that they are implementing the required cybersecurity measures. These include risk management, incident response, security measures in the supply chain, as well as reporting processes for security incidents. 

Tip: Companies should therefore not wait for an inquiry from the authorities.  Identifying early on whether you are affected by NIS-2 allows you to plan and implement the necessary organizational and technical measures in a timely manner. 

Violations of the requirements can be punished with significant fines and regulatory enforcement measures. Therefore, assessing applicability should be the first step on the path to NIS-2 compliance for many companies. 

Which measures must affected companies implement now? 

NIS-2 does not mandate specific technologies or products. Instead, it defines security objectives that affected companies must achieve through appropriate organizational and technical measures. At its core, the Directive requires a systematic management of cyber risks across the entire lifecycle of IT and OT systems. The key requirements include: 

  • Risk management and security policies: Companies must regularly identify and assess their cyber risks and establish appropriate protective measures. This includes, for example, security policies, risk assessments, and documented processes. 

  • Incident detection and response: Security incidents must be detected, assessed, and handled at an early stage. To achieve this, companies need defined incident response processes, responsibilities, and reporting channels. 

  • Business continuity and crisis management: Even in the event of a cyberattack, critical business processes must continue or be quickly restored. NIS-2 therefore requires, among other things: 

    • Backup and recovery concepts

    • Emergency and crisis management

    • Disaster recovery plans for critical systems

    • Regular testing of emergency processes 

  • Supply chain security: Cyber risks often do not originate within your own company, but rather at service providers, suppliers, or software vendors. Therefore, companies must address the security of their supply chain and assess risks not only internally but also for external partners.

  • Secure development and maintenance of systems: Security requirements should be considered as early as during the procurement, development, and maintenance of IT and OT systems. This includes, for example: 

    • Vulnerability management 

    • Patch management 

    • Secure development 

    • Regular security assessments 

  • Effectiveness control: Security measures must not only exist, but must also demonstrably function. Companies should therefore regularly conduct audits, assessments, or technical reviews. 

  • Cyber hygiene and awareness: Employees play a central role in cybersecurity. NIS-2 therefore requires basic security measures such as:  

    • Security awareness training 

    • Password policies 

    • Phishing awareness 

    • Secure handling of data and systems 

  • Cryptography and encryption: Where necessary, data should be protected by modern cryptographic procedures – both during storage and transmission. 

  • Access and authorization management: Companies must ensure that employees can only access the systems and information they need for their work. 

  • Strong authentication: NIS-2 requires the use of modern authentication methods. In practice, this often means implementing multi-factor authentication (MFA) for critical systems and user accounts. 

What does this mean specifically for companies? 

Most companies do not need to invent completely new security measures to implement NIS-2. Many of the requirements correspond to established information security best practices. 

Typical projects within the scope of NIS-2 implementation are (Art. 21 para. 2 lit. a-j NIS-2): 

  • Establishment or expansion of an Information Security Management System (ISMS); 

  • Introduction of a risk management process; 

  • Implementation of an incident response process; 

  • Conducting supplier assessments; 

  • Use of multi-factor authentication or continuous authentication solutions, secured voice, video, and text communications, and, where appropriate, secured emergency communication systems within the entity;  

  • Improvement of backup and recovery concepts; 

  • Human resources security, access control policies, and asset management; 

  • Security awareness programs for employees and management training; 

  • Technical vulnerability analyses and penetration tests 

The challenge therefore rarely lies in individual technical measures, but in implementing them in a structured, documented, and permanently verifiable manner. 

NIS-2, CRA, KRITIS, ISO 27001, and BSI IT-Grundschutz – how are they related? 

When implementing cybersecurity requirements, companies quickly encounter a variety of abbreviations and regulations. However, they actually fulfill different tasks. 

Put simply, they can be divided into three categories: 

1. Laws and regulatory requirements 

These regulations define what requirements companies must meet. 

Regulation 

Purpose 

NIS-2 

Cybersecurity requirements for essential and important entities 

BSI Act (BSIG) 

National transposition of NIS-2 in Germany 

BSI Kritis Regulation 

Definition of critical infrastructures and thresholds 

Cyber Resilience Act (CRA) 

Security requirements for products with digital elements 

Radio Equipment Directive (RED) 

Security requirements for wireless products 

These specifications describe the "What" – meaning which requirements must be met. 

2. Norms and standards 

Standards describe how companies can structure their security organization. 

Standard 

Focus 

ISO/IEC 27001 

Information Security Management (ISMS) 

ISA/IEC 62443 

Cybersecurity for industrial automation and control systems (IACS) and OT systems 

ISO/IEC 15408 (Common Criteria) 

Evaluation and certification of IT products 

These standards provide structured approaches for implementing regulatory requirements. 

3. Frameworks and catalogs of measures 

Frameworks and best practices support companies in the concrete implementation. 

Framework 

Focus 

BSI IT-Grundschutz 

Comprehensive catalog of measures for information security 

BSI ICS Security Compendium 

Recommendations for industrial control and automation systems 

NIST Cybersecurity Framework 

Internationally established cybersecurity framework 

NIST Cryptographic Standards 

Recommendations for cryptography and key management 

These frameworks describe concrete technical and organizational measures. 

From law to technical implementation 

For many companies, the connection can be illustrated simply: 

NIS-2 → BSIG → ISO 27001 / ISA/IEC 62443 → BSI-Grundschutz & technical measures 

NIS-2 defines the regulatory requirements. The BSI Act translates these into German law. Standards like ISO 27001 or ISA/IEC 62443 provide a structured implementation approach. Frameworks like the BSI IT-Grundschutz then assist with the concrete selection and implementation of technical and organizational measures. 

Figure 1: Relationship between EU law and national law 

 CarByte actively supports companies from the initial assessment through to the implementation of the required security measures. If you need assistance with classifying, evaluating, or implementing your regulatory requirements, please feel free to contact our cybersecurity team. 

Takeaways

  • NIS-2 affects companies from 18 sectors and significantly expands the regulatory requirements for cybersecurity, risk management, and reporting obligations.

  • NIS-2 applicability can be assessed based on industry, company size, and critical services.

  • ISO 27001, BSI-Grundschutz, and other established standards support companies in the structured implementation of NIS-2 requirements.

Is your company affected by NIS-2?

NIS-2 now obligates 18 sectors to meet new cybersecurity requirements. Fill out the form to receive a free initial consultation on how you are affected, your obligations, and the next steps.

Is your company affected by NIS-2?

NIS-2 now obligates 18 sectors to meet new cybersecurity requirements. Fill out the form to receive a free initial consultation on how you are affected, your obligations, and the next steps.