Get a no-obligation quote
Send us a message now
Get a no-obligation quote
Send us a message now

NIS2 Implementation 2026: Obligations, Deadlines, Fines

NIS2-Umsetzung 2026: Pflichten, Fristen, Bußgelder

The NIS2 implementation in 2026 is no longer theory but applicable law with teeth. The German NIS2 Implementation Act (NIS2UmsuCG) has been in force since December 6, 2025 - with no generous transition period. Around 29,500 companies across 18 sectors are affected, and the registration deadline with the BSI expired on March 6, 2026. Anyone who has not yet acted should now treat the topic as a top priority.

Many managing directors in the mid-market underestimate that NIS2 has long ceased to affect only classic operators of critical infrastructure (KRITIS). Manufacturing, logistics, digital infrastructure, healthcare and research also fall under it - as a rule from 50 employees or 10 million euros in revenue. This article explains what the NIS2 implementation in 2026 means in concrete terms, which obligations apply and how you avoid fines.


NIS2 implementation 2026: the current status

The act was promulgated on December 6, 2025 and has applied directly ever since. The three-month registration window started at the same time and ended on March 6, 2026. Important to know: registration takes place via "Mein Unternehmenskonto", the ELSTER-based German company account. Without this account, registering with the BSI is technically impossible - a detail that has put many companies under avoidable time pressure.

The BSI is actively auditing in 2026. The authority has announced that it will fulfill its supervisory role and can order measures as well as impose fines. The time for waiting is over: affected entities have been required since December 2025 to implement appropriate technical and organizational measures and to report significant security incidents within 24 hours.

A widespread misconception is that the work is done once you have registered. Registration is merely the formal entry point. The actual obligation lies in ongoing implementation and in demonstrating the security measures. Anyone who is registered but cannot demonstrate a working risk management process does not meet the requirements. If an incident is then accompanied by a late or missing report, exactly this point becomes the problem - because the reporting obligation under Section 32 is multi-staged: an initial report within 24 hours is followed by a more detailed report within 72 hours and a final report.

Am I affected at all?

Whether you are in scope (governed by Section 28 NIS2UmsuCG) depends on sector and company size. Check the following points:

  • Does your company belong to one of the 18 covered sectors (including energy, transport, health, drinking water, manufacturing, logistics, digital infrastructure)?
  • Do you regularly employ at least 50 people?
  • Do you generate more than 10 million euros in annual revenue and balance sheet total?
  • Are you a supplier to an affected company and thus part of its supply chain?

The last point is decisive for smaller SMBs: even companies below the thresholds are pulled into scope through the supply chain requirements as soon as large customers demand proof of security. NIS2 thus reaches far beyond the circle of directly affected companies.

In practice, this means a domino effect through the entire economy. An affected corporation must ensure the security of its supply chain and passes this requirement on contractually to its suppliers. A Leipzig machine builder with 30 employees that supplies a large car manufacturer is thus effectively obliged to implement NIS2-like measures - even though it does not formally fall under the act. Those who can present proof of security gain a clear competitive advantage and remain attractive as a business partner. Conversely, those who cannot deliver risk losing important contracts.

The five central obligations

The act spells out the requirements in several sections. You should know these five:

  • Section 28: determining whether you are in scope, and self-classification
  • Section 30: risk management with technical and organizational measures
  • Section 32: reporting obligations - initial report of significant incidents within 24 hours
  • Section 38: management duties including personal liability
  • Section 65: fines for violations

The required risk management includes, among other things, access controls, multi-factor authentication, encryption, backup and recovery concepts, training and incident management. In effect, NIS2 thus demands zero-trust principles without using the term.

Specifically, Section 30 lists a minimum catalog of measures that every affected company must cover. These include:

  • Concepts for risk analysis and for the security of information systems
  • Handling of security incidents including reporting processes
  • Business continuity, such as backup and emergency management
  • Security of the supply chain and of relationships with service providers
  • Concepts for access control, encryption and asset management
  • Cybersecurity training and basic cyber hygiene

These points are not recommendations but mandatory components. What matters is that companies not only implement them but also document them. In an audit, what counts is what can be evidenced - a verbal "we already have backups" is not enough.

Fines and personal liability

The sanctions are substantial. Particularly important entities face fines of up to 10 million euros or 2 percent of worldwide annual revenue, whichever amount is higher. For important entities, the limit is up to 7 million euros or 1.4 percent of revenue.

Especially critical: Section 38 makes company management personally responsible. Managing directors must approve the risk management measures, monitor their implementation and undergo training themselves. Failures can lead to personal liability. NIS2 has thus definitively become a matter for top management.

What you should do now

Even though the registration deadline has passed, one thing holds: acting is better than continuing to wait. A missed registration can be made up for; a neglected risk management process cannot be once an audit comes. Proceed in a structured way:

  • Check whether you are in scope: compare sector, headcount and revenue, including your role as a supplier
  • If not yet done, register with the BSI via Mein Unternehmenskonto on ELSTER
  • Compare existing security measures against the requirements of Section 30 (gap analysis)
  • Define reporting processes for security incidents and make them known across the team
  • Train management and formally anchor the responsibility

Especially for smaller companies without their own IT security department, external support pays off. An experienced service provider knows the requirements, avoids expensive detours and ensures audit-proof documentation. This turns a regulatory obligation into a genuine security gain.

Conclusion

The NIS2 implementation in 2026 is reality, the deadlines have passed and the BSI is actively auditing. Companies that are in scope and remain inactive risk high fines and the personal liability of their management. The good news: many NIS2 requirements are solid IT security practice from which every company benefits - regardless of the regulation.

Unsure whether and how NIS2 affects you? Cryon guides mid-sized companies from Leipzig and the region through the scoping assessment, risk management and the establishment of verifiable security measures. Arrange a no-obligation initial consultation and bring your compliance up to a solid standard.

Cryon can help

NIS2 affects you too. Are you ready?

Cryon brings your IT up to the required standard: from risk analysis to emergency plans and monitoring.

Categories

Cryon IT-Dienstleistungen

Our purpose is to build solutions that remove barriers preventing people from doing their best work.

04157 Leipzig
(Mo - Fr)
(09 - 17 Uhr)