
Cyber Security
NIS 2 Compliance: Which Companies Are Affected and What Measures Are Now Required
What is NIS-2?
The original NIS Directive was introduced by the European Union to respond to the growing cyber risks facing network and information systems. At the same time, it aimed to create a uniform framework, as cybersecurity requirements in individual member states had previously varied significantly. Another objective was to systematically build national cybersecurity capabilities within the EU.
With the NIS-2 Directive, the EU is consistently pursuing these goals. It significantly expands the scope, tightens the requirements for affected organizations, and completely replaces the previous NIS Directive.
In addition to the requirements for companies, NIS-2 now also obliges EU member states to develop and implement a national cybersecurity strategy. This is intended to ensure that cybersecurity is systematically strengthened not only at the corporate level, but also at the state level.
Particularly relevant for companies, however, are the specific organizational, technical, and operational requirements of the Directive. These include, among other things, risk management measures, securing supply chains, handling security incidents, and reporting obligations to the competent authorities.
Which companies are affected by NIS-2?
With the NIS-2 Directive, the EU is expanding the scope of affected companies. While the original NIS Directive covered only a few critical industries, NIS-2 now includes a total of 18 sectors. As a result, significantly more companies fall under the new cybersecurity requirements.

The affected sectors include, among others:
Sectors of high criticality
Energy
Transport
Banking and financial market infrastructures
Health
Drinking water and wastewater
Digital infrastructure
IT and Managed Service Providers
Public administration
Space
Other critical sectors
Postal and courier services
Waste management
Chemical industry
Food production and processing
Manufacturing
Digital services
Research organizations
Within these sectors, NIS-2 also distinguishes between different subsectors and types of entities. This allows for a more precise determination of which organizations actually fall under the scope of the Directive.
Important or essential entity?
In Germany, the Federal Office for Information Security (BSI) is the competent authority for the implementation and supervision of NIS-2. For companies based in Germany, the NIS-2 requirements are therefore specified by the BSI Act (BSIG). This involves a division into two categories: essential entities and important entities.
Which category applies depends primarily on three factors:
The industry or sector of the company
The type of services provided
The size of the company (number of employees and turnover)
Operators of critical infrastructures, certain DNS and trust service providers, as well as operators of public telecommunications networks, for example, are considered essential entities.
For many companies, however, the size consideration is most relevant. Simply put:
Essential entities
at least 250 employees or
an annual turnover exceeding €50 million and an annual balance sheet total exceeding €43 million
Important entities
at least 50 employees or
an annual turnover exceeding €10 million and an annual balance sheet total exceeding €10 million
Companies that do not reach these thresholds do not fall under NIS-2 in many cases. However, there are exceptions, such as for operators of critical infrastructures or certain digital services. Therefore, applicability should always be assessed individually.
How to find out if your company is affected
For most companies, a simple check using the following questions is sufficient:
Does my company belong to one of the 18 NIS-2 sectors?
Do we meet the relevant size criteria?
Do we provide specific digital or critical services?
If all questions can be answered with "Yes", NIS-2 applicability is likely and should be assessed in detail.
What role does the BSI play?
In Germany, the Federal Office for Information Security (BSI) is the competent authority for the implementation and supervision of NIS-2.
Affected companies must register their status with the BSI and be able to prove that they are implementing the required cybersecurity measures. These include risk management, incident response, security measures in the supply chain, as well as reporting processes for security incidents.
Tip: Companies should therefore not wait for an inquiry from the authorities. Identifying early on whether you are affected by NIS-2 allows you to plan and implement the necessary organizational and technical measures in a timely manner.
Violations of the requirements can be punished with significant fines and regulatory enforcement measures. Therefore, assessing applicability should be the first step on the path to NIS-2 compliance for many companies.
Which measures must affected companies implement now?
NIS-2 does not mandate specific technologies or products. Instead, it defines security objectives that affected companies must achieve through appropriate organizational and technical measures. At its core, the Directive requires a systematic management of cyber risks across the entire lifecycle of IT and OT systems. The key requirements include:
Risk management and security policies: Companies must regularly identify and assess their cyber risks and establish appropriate protective measures. This includes, for example, security policies, risk assessments, and documented processes.
Incident detection and response: Security incidents must be detected, assessed, and handled at an early stage. To achieve this, companies need defined incident response processes, responsibilities, and reporting channels.
Business continuity and crisis management: Even in the event of a cyberattack, critical business processes must continue or be quickly restored. NIS-2 therefore requires, among other things:
Backup and recovery concepts
Emergency and crisis management
Disaster recovery plans for critical systems
Regular testing of emergency processes
Supply chain security: Cyber risks often do not originate within your own company, but rather at service providers, suppliers, or software vendors. Therefore, companies must address the security of their supply chain and assess risks not only internally but also for external partners.
Secure development and maintenance of systems: Security requirements should be considered as early as during the procurement, development, and maintenance of IT and OT systems. This includes, for example:
Vulnerability management
Patch management
Secure development
Regular security assessments
Effectiveness control: Security measures must not only exist, but must also demonstrably function. Companies should therefore regularly conduct audits, assessments, or technical reviews.
Cyber hygiene and awareness: Employees play a central role in cybersecurity. NIS-2 therefore requires basic security measures such as:
Security awareness training
Password policies
Phishing awareness
Secure handling of data and systems
Cryptography and encryption: Where necessary, data should be protected by modern cryptographic procedures – both during storage and transmission.
Access and authorization management: Companies must ensure that employees can only access the systems and information they need for their work.
Strong authentication: NIS-2 requires the use of modern authentication methods. In practice, this often means implementing multi-factor authentication (MFA) for critical systems and user accounts.
What does this mean specifically for companies?
Most companies do not need to invent completely new security measures to implement NIS-2. Many of the requirements correspond to established information security best practices.
Typical projects within the scope of NIS-2 implementation are (Art. 21 para. 2 lit. a-j NIS-2):
Establishment or expansion of an Information Security Management System (ISMS);
Introduction of a risk management process;
Implementation of an incident response process;
Conducting supplier assessments;
Use of multi-factor authentication or continuous authentication solutions, secured voice, video, and text communications, and, where appropriate, secured emergency communication systems within the entity;
Improvement of backup and recovery concepts;
Human resources security, access control policies, and asset management;
Security awareness programs for employees and management training;
Technical vulnerability analyses and penetration tests
The challenge therefore rarely lies in individual technical measures, but in implementing them in a structured, documented, and permanently verifiable manner.
NIS-2, CRA, KRITIS, ISO 27001, and BSI IT-Grundschutz – how are they related?
When implementing cybersecurity requirements, companies quickly encounter a variety of abbreviations and regulations. However, they actually fulfill different tasks.
Put simply, they can be divided into three categories:
1. Laws and regulatory requirements
These regulations define what requirements companies must meet.
Regulation | Purpose |
NIS-2 | Cybersecurity requirements for essential and important entities |
BSI Act (BSIG) | National transposition of NIS-2 in Germany |
BSI Kritis Regulation | Definition of critical infrastructures and thresholds |
Cyber Resilience Act (CRA) | Security requirements for products with digital elements |
Radio Equipment Directive (RED) | Security requirements for wireless products |
These specifications describe the "What" – meaning which requirements must be met.
2. Norms and standards
Standards describe how companies can structure their security organization.
Standard | Focus |
ISO/IEC 27001 | Information Security Management (ISMS) |
ISA/IEC 62443 | Cybersecurity for industrial automation and control systems (IACS) and OT systems |
ISO/IEC 15408 (Common Criteria) | Evaluation and certification of IT products |
These standards provide structured approaches for implementing regulatory requirements.
3. Frameworks and catalogs of measures
Frameworks and best practices support companies in the concrete implementation.
Framework | Focus |
BSI IT-Grundschutz | Comprehensive catalog of measures for information security |
BSI ICS Security Compendium | Recommendations for industrial control and automation systems |
NIST Cybersecurity Framework | Internationally established cybersecurity framework |
NIST Cryptographic Standards | Recommendations for cryptography and key management |
These frameworks describe concrete technical and organizational measures.
From law to technical implementation
For many companies, the connection can be illustrated simply:
NIS-2 → BSIG → ISO 27001 / ISA/IEC 62443 → BSI-Grundschutz & technical measures
NIS-2 defines the regulatory requirements. The BSI Act translates these into German law. Standards like ISO 27001 or ISA/IEC 62443 provide a structured implementation approach. Frameworks like the BSI IT-Grundschutz then assist with the concrete selection and implementation of technical and organizational measures.

Figure 1: Relationship between EU law and national law
CarByte actively supports companies from the initial assessment through to the implementation of the required security measures. If you need assistance with classifying, evaluating, or implementing your regulatory requirements, please feel free to contact our cybersecurity team.
Takeaways
NIS-2 affects companies from 18 sectors and significantly expands the regulatory requirements for cybersecurity, risk management, and reporting obligations.
NIS-2 applicability can be assessed based on industry, company size, and critical services.
ISO 27001, BSI-Grundschutz, and other established standards support companies in the structured implementation of NIS-2 requirements.
