Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Law · 2 min read · Updated 16 August 2026

NIS2

In shortNIS2 may not cover you, but it covers your biggest customer — who passes the duties on.

At a glance

Instrument
Directive (EU) 2022/2555; implemented in Germany by the NIS-2 implementation act, in force since 6 December 2025
Entities covered in Germany
Around 29,500, by the legislator's estimate
Transition period
No general transition period provided
Core duties
Risk management, reporting of significant incidents, registration, management-level accountability
Supply chain
Regulated entities must account for supplier risk and pass the requirements on contractually
Self-assessment
The BSI publishes an applicability check; it is guidance, not legally binding

NIS2 is the second European directive on network and information security. It widens the circle of regulated entities considerably, tightens the duties and makes management personally accountable. In Germany the implementation act has applied since 6 December 2025; no general transition period is provided.

For most small and mid-sized companies the first question is thereby answered: they are not covered. The second question matters more.

Tier 1 Regulated entity falls under the law, must account for supply-chain risk Tier 2 Questionnaire passes the duty on — not as law, but as a contract condition Tier 3 Supplier falls outside the law and still has to answer
The pass-through happens by contract. That is why NIS2 concerns far more companies than fall within its scope.

The pass-through along the supply chain

Regulated entities must account for risk in their supply chain. They cannot delegate that duty to a service provider, so they pass it on — not as law, but through the contract.

That is why NIS2 currently reaches a great many businesses that do not appear in the statute: the trades business working for an energy utility, the agency whose largest client is a hospital, the software firm maintaining a water authority's line-of-business application.

The duties of regulated entities

Risk management measures reflecting the state of the art, including incident handling, business continuity, supply chain security, access control and encryption.

Reporting of significant incidents in stages, beginning with an early warning within a short deadline. Those deadlines are why a provider with no contact in your time zone becomes a risk at exactly this point.

Registration with the competent authority.

And approval and oversight of the measures by the management bodies — with personal accountability.

What small businesses should actually do

Write down the answers to the five usual questions before anyone asks. Two pages suffice, with a date and named responsibilities.

From then on those two pages are your answer to every questionnaire. They also help in tenders and insurance applications — and they force an inventory of access rights that was overdue anyway. That the sub-processor list becomes visible in the process is a side effect belonging to the Data processing agreement.

Where NIS2 touches the sovereignty question

In three places. The questionnaires require knowledge of your own supply chain. Short reporting deadlines presuppose reachable contacts. And the burden of proof shifts: what used to be an argument in procurement becomes a requirement that gets ticked off.

Common questions

We are a small business. Does NIS2 concern us?
Directly, usually not. Through the supply chain, very much so: if one of your customers is regulated, a questionnaire arrives with a short deadline. Whoever cannot answer it comes off worse at the next award.
What do those questionnaires ask?
Five points recur almost every time: named responsibility for information security, reporting path and deadline for incidents, service-provider access, backup including the last restore, and what happens when an employee leaves.
Do we need a certification?
As a rule no. For small companies it is disproportionate and answers the five questions no better than two well-written pages. If a customer explicitly demands certification, that is a separate calculation.
What is management accountability?
NIS2 expressly requires the management bodies of regulated entities to approve and oversee risk management measures, and attaches personal accountability to that. Information security is therefore no longer purely an IT matter.

Sources

See also

Related terms