Implications for businesses and institutions

European NIS2 Directive

Flags of the EU member states

Your expert for questions

André Glenzer
Partner, Cyber Security, Data & Tech Risk at PwC Germany
Tel: +49 160 94470376
Email

What you need to know about NIS2

The NIS2 Directive (‘Network and Information Systems Directive’, Directive (EU) 2022/2555) is the updated European legal framework for cyber and information security. It was published in the Official Journal of the EU on 27 December 2022 and entered into force on 16 January 2023. The aim of the Directive is to harmonise the level of cybersecurity across EU Member States, strengthen the resilience of businesses and institutions, and introduce more binding rules for managing cyber risks.

What specific cybersecurity measures does NIS2 require: The NIS2 Directive extends cyber security requirements and sanctions to harmonise and improve the level of security in Member States and contains stricter requirements for various sectors. Among other things, companies and organisations must address the issues of cyber risk management, control and monitoring, incident handling and business continuity. In addition, the directive expands the number of organisations that fall within its scope. Stricter liability rules will apply to the management of the organisations concerned.

NIS2 Implementation Act: In Germany, the NIS2 Implementation Act (“Act on the Implementation of the NIS2 Directive and on the Regulation of Key Principles of Information Security Management in the Federal Administration” – BSIG) was passed by the Bundestag on 13 November 2025. The Act has been in force since 6 December 2025.

Particularly relevant for management: The Act provides for mandatory training for company management (Section 38 (3) BSIG). The aim is to strengthen understanding of cyber risks and risk management at board level. The scope and content depend on the individual risk exposure of the company.

“In Germany, the legislation pertaining to critical infrastructure, or KRITIS, has so far mainly affected institutions acting as operators of critical infrastructure. But now NIS2 is making cybersecurity and resilience a major issue for an even wider range of businesses in Europe and Germany.”

André Glenzer,Partner at PwC Germany

Our services in the area of NIS2

Together, we assess whether you are affected by the NIS2 Directive and lay the foundation for your NIS2 readiness.

NIS2 Gap Assessment – from classification to a robust management report.

We help you clarify the NIS2 requirements for all your EU entities and prepare measures efficiently and in a harmonized manner.

We support you in implementing strategic, organisational, procedural and technical measures – in line with current ISO standards, the NIST CSF 2.0 framework or the 'BSI IT-Grundschutz'.

We support you with a Risk Exposure Assessment (REA) and develop a targeted training concept.

Compliance as a service – always compliant, audit-ready, and sustainably secured.

We support you with technical measures such as hardening, detection and response, vulnerability management and testing.

Provide robust evidence of NIS2 compliance.

< Back

< Back
[+] Read More

How we support you

Does NIS2 affect you?

The NIS2 Directive is EU-wide legislation on network and information security that came into force on 16 January 2023. Member States should transpose the Directive into national law by 17 October 2024. In Germany, a cabinet draft of the German implementation law has been submitted to the Bundestag (“Draft law on the implementation of the NIS2 Directive and on the regulation of essential principles of information security management in the federal administration”); implementation is scheduled for Q4 2025/Q1 2026. The new directive will lead to a massive increase in the number of companies affected. In addition, higher requirements will be placed on the companies concerned and enforcement pressure will also increase – for example, through the threat of higher sanctions and liability at management level.

Use our fast impact analysis tool to find out whether the NIS2 Directive affects your business.

Impact analysis tool

NIS2 Incident Severity Indicator

With the introduction of the NIS2 Directive, companies are faced with the challenge of reporting significant security incidents within 24 hours. This requirement has far-reaching implications for business operations and demands quick, accurate decisions.

The NIS2 Incident Severity Indicator is an AI tool designed specifically for this purpose. In an environment where non-compliance can result in heavy fines and tight deadlines leave no room for delays, AI provides the necessary security and speed. It helps teams to assess incidents quickly and reproducibly, clarify reporting requirements and document decisions in a reliable manner.

The integrated, AI-based decision support with detailed, verifiable documentation creates transparency and traceability. At the same time, structured workflows ensure that the effort required for reporting is significantly reduced and that reports are created quickly, consistently and in a resource-efficient manner.

Rely on the NIS2 Incident Severity Indicator to accelerate your incident management, effectively support compliance with the 24-hour reporting obligation, and strengthen your cybersecurity posture in the long term.

Contact us

Structural framework for supply chain security in accordance with BSIG/NIS2

Ensuring your supply chain complies with the law

The cyber security requirements of the BSI Act do not stop at the factory gates. If your company falls under NIS2, you are legally obliged to secure your supply chain. Anyone who breaches this obligation risks substantial fines – and personal liability for senior management. The real difficulty, however, lies in the contractual implementation. And this affects both sides of the supply chain.

Are you subject to NIS2? If so, general IT security clauses or sporadic references to ISO 27001 are not sufficient. You need a set of contracts that systematically extends risk management, incident response, vulnerability management and business continuity throughout your supply chain – in accordance with Section 30 of the BSI Act and the BSI’s recommendations.

Are you a supplier to critical customers? Then you are familiar with the reverse challenge. You are faced with a growing number of individual security annexes, the content of which is inconsistent, often disproportionately strict and, given their sheer number, virtually impossible to implement in a consistent manner. Without a structured position of your own, negotiations become a defensive struggle in which every customer relationship has to be renegotiated from scratch.

This is precisely where our template for a contractual security annex in accordance with the BSIG / NIS2 comes into play. It systematically implements the requirements of Section 30 of the BSIG, whilst also integrating the relevant BSI recommendations on cyber supply chain risk management, IT-Grundschutz and UP KRITIS, and is consistently designed to strike a fair balance between the interests of both parties.

This provides you with a set of contracts that reflects the regulatory framework, remains tenable in negotiations and offers both parties a robust foundation – whether as a basis for your own supplier relationships under NIS2 or as a standardised reference framework for your customers.

Download (German, PDF, 0,2 MB)

NIS2 standards

In the German implementation, a distinction is made between “essential” and “important” entities. The main difference is that important entities face lower fines and are subject to reactive supervision by the authorities, whereas essential entities will be subject to proactive supervision. The German drafts differ in the terminology by naming the entities “very important” and “important”.

Instead of a minimum threshold, as in the past, the EU will use “uniform criteria” to determine what kind of entities are affected. The regulations are expected to apply to medium and large enterprises:

  • Medium: 50-249 employees or turnover of 10-50 million euros, total assets of less than 43 million euros
  • Large: at least 250 employees or at least 50 million euros in turnover

As a result, the number of affected businesses in Germany is expected to increase substantially.

Extended and enhanced liability

Essential entities may face fines of up to 10 million euros or 2 percent of their annual turnover, whichever is higher. Important may face fines of up to 7 million euros or 1.4 percent of their annual turnover, whichever is higher.

The businesses and organizations affected must take appropriate measures in areas such as cyber risk management, supply chain security, business continuity management, encryption, access restrictions, reporting to authorities, and mitigation.

Please note: Under the draft put forward by the Federal Ministry of the Interior and Community, company executives may be held personally liable for compliance with risk management measures. The upper limit for these fines corresponds to 2% of the company's global annual turnover.

  • Various categories of fines up to a maximum of 20 million euros 
  • Negligent and willful misconduct
  • Critical entities may face fines of up to 7 million euros or a maximum of at least 1.4 percent of their global turnover in the most recent fiscal year 
  • Highly critical entities may face fines of up to 10 million euros or a maximum of at least 2 percent of their global turnover in the most recent fiscal year 
  • No differentiation between highly critical entities and critical facilities
  • Example: a cyberattack that impedes operations due to an insufficiently monitored risk management process at a highly critical entity
  • Consequences: 
  • Expenses such as 
    • Ransom payments
    • Costs for external service providers
    • Fines for GDPR or BSIG violations
  • General managers and CEOs are liable for damage incurred due to breaches of monitoring obligations (except for the central government sector)
  • An entity cannot waive the general manager’s liability or agree to a settlement on the matter
  • However, managerial staff can settle with an entity’s creditors in the event of bankruptcy or insolvency – or if the obligation to pay compensation is regulated in an insolvency plan

NIS2: The directive affects more than just critical infrastructure

It’s clear: The scope of application goes well beyond the already familiar types of critical infrastructure. In the energy sector, for instance, the scope of the NIS has so far always been limited to companies that generate, provide, or regulate energy in the electricity and gas sector. We expect NIS2 to extend the requirements to include the supply chain as well, such as the manufacturers of wind turbines and the operators of charging stations for electric vehicles.

Essential entities

Energy

Provision, distribution, transmission, and sale of electricity, gas, oil, heating/cooling, hydrogen; operators of charging stations for electric vehicles

Find out more

Health

Healthcare providers, research laboratories, pharmaceuticals, manufacturing of medical devices

Find out more

Public administration

How will NIS2 affect public administration? What aspects of the federal government are subject to NIS2? We take a closer look at the requirements NIS2 places on information security management, as well as the duties and risk of penalties.

Find out more

Air, rail, road, and water transport

Including shipping companies and port facilities

Water

Drinking water suppliers and wastewater disposal providers

Space

Operators of ground-based infrastructure

Banking/finance

Loans, trading, market and infrastructure; Update: draft version of the NIS-2UmsuCG also covers the insurance sector

Digital infrastructure and IT services

DNS service providers and TLD registries

Find out more

Important entities

Food

Production, processing, and distribution

Research organizations

Production and distribution

Find out more

Waste management

Waste collection, transport, treatment, and disposal

Cyber incidents in waste disposal and recycling can have a significant impact on public life. That is why the sector has been considered critical infrastructure since January 2024 and requires a particular degree of protection. NIS2 will apply to such businesses from October 2024 onward, even if they do not exceed the KRITIS thresholds.

Find out more

Manufacturers

Medical/diagnostic devices, computers, electronics, optical products, machinery, motor vehicles, trailers, semitrailers, other transport equipment

Find out more

Chemical products

Production, manufacturing, and trade

Digital providers

Online marketplaces, search engines, social networking platforms

Providers of postal and courier services

EMEA NIS2 Competence Network

PwC has established a combined NIS2 capability, developed through our communities of Cybersecurity, risk management, incident response, governance, compliance and legal specialists.

These communities have been brought together to form a team of over 150 specialists across EMEA, focussed on supporting our clients with the NIS2 Directive. We are supporting our clients in understanding the relevance of the NIS2 Directive to their organisation; their own ability to meet the requirements or identify where gaps exist, along with supporting them in achieving compliance with the regulatory requirements both local and at EU-level in a proportionate and cost effective manner.

Contact our team

“NIS2 is set to be a real game changer and alter cyber regulation in Europe for good.”

André Glenzer, Partner at PwC Germany

Frequently asked questions

The registration process in Germany is a two-stage procedure. First, you must sign up via the digital service ‘Mein Unternehmenskonto (MUK)’. The second stage involves the actual registration via the newly established BSI portal, which has been accessible since 6 January 2026. The mandatory registration period is three months from the date on which it is determined that an organisation is affected. KRITIS operators must also re-register.

The KRITIS regulation and the associated impact assessment will continue to apply in parallel with the NIS2 Directive. However, KRITIS operators will be integrated into the scope of NIS2 and will be classified as ‘particularly important entities’. All organisations already registered as KRITIS operators were also required to register as particularly important entities (bwE) on the BSI portal by 6 March 2026.

Organisations may ‘disregard’ NIS2-relevant activities when assessing their sector classification, provided that the business activity is ‘negligible in relation to the organisation’s overall business activity’ (Section 28(3) of the BSIG). Possible indicators of negligibility include the number of employees or the turnover/balance sheet total for this area. A share of up to 5 per cent is considered legally very justifiable, and up to 10 per cent is still regarded as justifiable.

The impact must always be assessed at the level of the individual companies (“entities”) within the group; NIS2 does not specify an overall impact at group level. Intra-group IT/shared services companies may be regarded as NIS2 entities in their own right, even without their own direct market presence, if they provide NIS2-relevant IT services (e.g. data centre and cloud services, MSP) and exceed the size threshold of at least a medium-sized enterprise. In the case of group companies in other EU countries, the affected companies must generally register themselves in the respective countries and fulfil the relevant obligations. The governance obligations of senior management cannot be delegated; ultimate responsibility and liability remain with the senior management of the affected organisation.

The new BSI ‘Grundschutz++’ can serve as a potential framework to assist with NIS2 implementation, as it largely covers areas such as incident response, BCM/backup/crisis management, cyber hygiene and training, as well as personnel and access control and assets, and sets out specific requirements. However, there are gaps: in the risk analysis, policy profiles are missing; for procurement, development and maintenance, operational profiles are only available as free text; and the implementation of cryptography requires the independent application of BSI TR-02102. In particular, continuous authentication for MFA is not covered by ‘Grundschutz++’. The BSI explicitly points out that implementing the ‘Grundschutz++’ requirements does not automatically mean that the NIS2 requirements are fully met.

Integrated governance is crucial for overcoming governance silos and consolidating risk assessments, which is important for the transition from maturity level 3 to maturity level 4 in NIS2 implementation. It promotes a shared view of risk and facilitates cross-departmental management. Organisations can utilise existing (risk) management systems to implement the NIS2 requirements for risk management. This requires an assessment of existing approaches, an analysis of the current level of integration, the identification of integration opportunities (quick wins) and the efficient incorporation of the NIS2 requirements into the harmonised framework. Relevant standards for risk analyses under NIS2 include ISO 27005, BSI Standard 200-3 and ISO 31000.

Does NIS2 affect you?

Use our fast impact analysis tool to find out whether the NIS2 Directive affects your business.

How does NIS2 affect your organization?

Check out our white paper to learn more about the directive and who will be affected. You will also get exclusive access to our checklist to help you prepare for NIS2.

(PDF of 262.91KB)
Follow us

Required fields are marked with an asterisk(*)

You can find our privacy policy here.

Contact us

André Glenzer

André Glenzer

Partner, Cyber Security, Data & Tech Risk, PwC Germany

Tel: +49 160 94470376

Hide