NIS2
In shortNIS2 may not cover you, but it covers your biggest customer — who passes the duties on.
At a glance
- Instrument
- Directive (EU) 2022/2555; implemented in Germany by the NIS-2 implementation act, in force since 6 December 2025
- Entities covered in Germany
- Around 29,500, by the legislator's estimate
- Transition period
- No general transition period provided
- Core duties
- Risk management, reporting of significant incidents, registration, management-level accountability
- Supply chain
- Regulated entities must account for supplier risk and pass the requirements on contractually
- Self-assessment
- The BSI publishes an applicability check; it is guidance, not legally binding
NIS2 is the second European directive on network and information security. It widens the circle of regulated entities considerably, tightens the duties and makes management personally accountable. In Germany the implementation act has applied since 6 December 2025; no general transition period is provided.
For most small and mid-sized companies the first question is thereby answered: they are not covered. The second question matters more.
The pass-through along the supply chain
Regulated entities must account for risk in their supply chain. They cannot delegate that duty to a service provider, so they pass it on — not as law, but through the contract.
That is why NIS2 currently reaches a great many businesses that do not appear in the statute: the trades business working for an energy utility, the agency whose largest client is a hospital, the software firm maintaining a water authority's line-of-business application.
The duties of regulated entities
Risk management measures reflecting the state of the art, including incident handling, business continuity, supply chain security, access control and encryption.
Reporting of significant incidents in stages, beginning with an early warning within a short deadline. Those deadlines are why a provider with no contact in your time zone becomes a risk at exactly this point.
Registration with the competent authority.
And approval and oversight of the measures by the management bodies — with personal accountability.
What small businesses should actually do
Write down the answers to the five usual questions before anyone asks. Two pages suffice, with a date and named responsibilities.
From then on those two pages are your answer to every questionnaire. They also help in tenders and insurance applications — and they force an inventory of access rights that was overdue anyway. That the sub-processor list becomes visible in the process is a side effect belonging to the Data processing agreement.
Where NIS2 touches the sovereignty question
In three places. The questionnaires require knowledge of your own supply chain. Short reporting deadlines presuppose reachable contacts. And the burden of proof shifts: what used to be an argument in procurement becomes a requirement that gets ticked off.
Common questions
- We are a small business. Does NIS2 concern us?
- Directly, usually not. Through the supply chain, very much so: if one of your customers is regulated, a questionnaire arrives with a short deadline. Whoever cannot answer it comes off worse at the next award.
- What do those questionnaires ask?
- Five points recur almost every time: named responsibility for information security, reporting path and deadline for incidents, service-provider access, backup including the last restore, and what happens when an employee leaves.
- Do we need a certification?
- As a rule no. For small companies it is disproportionate and answers the five questions no better than two well-written pages. If a customer explicitly demands certification, that is a separate calculation.
- What is management accountability?
- NIS2 expressly requires the management bodies of regulated entities to approve and oversee risk management measures, and attaches personal accountability to that. Information security is therefore no longer purely an IT matter.