The Bundestag has passed the NIS 2 Act and is still pending approval by the Federal Council. Once promulgated, the Act comes into force without a transitional period. With our 7-step plan, you can keep track of things and get your company on course for compliance in good time.

The Bundestag has passed the German NIS-2 Act. The approval of the Federal Council is still pending, but after the announcement, the duties will come into force without longer transition periods. Affected companies should prepare now.
This is a decisive step towards the overdue implementation of the EU Directive. The approval of the Federal Council is currently pending.
As soon as the Act is published in the Federal Law Gazette, it comes into force immediately - without longer transition periods. Companies must therefore prepare all necessary safety measures now and incorporate them into their organization.
Germany has already exceeded the EU implementation deadline. The political and regulatory pressure is correspondingly high, so that a quick announcement must be expected.
The NIS 2 Directive is an EU-wide legislative project and must be implemented into national law in all Member States. The aim is to create a consistently high level of cybersecurity across Europe.
Belgium, Croatia, Hungary, Italy, Latvia, Lithuania, Romania, Slovakia, Slovenia, Malta and Liechtenstein (as an EEA state).
Germany, France, Denmark, Finland, Netherlands, Austria, Poland, Ireland, Sweden, Norway (EEA) and more.
There are delays in other Member States, such as Portugal or Spain, where the situation is currently still unclear.
If you operate in several European countries, you need to keep an eye on NIS-2 not only in Germany, but also in the countries where you have branches or business activities. Each country implements the Directive with its own laws and deadlines.
NIS-2 is a European issue. Anyone with an international presence should closely monitor the implementation status in the individual countries and integrate the requirements into their own processes at an early stage.
As an “important institution”, a medium-sized company with 400 employees and a turnover of €50 million risks fines of up to €7 million for NIS 2 violations.
In addition, management faces personal liability if it fails to fulfill its legal obligations.
The introduction of an ISMS, on the other hand, costs only a fraction — and protects against penalties, loss of reputation and management liability.

The Bundestag passed the German NIS-2 Act on November 13, 2025. The approval of the Federal Council is still pending, but as soon as the Act is promulgated in the Federal Law Gazette, it comes into force immediately. No longer transition periods are foreseen.
Germany has already exceeded the EU implementation deadline, which has significantly increased political and regulatory pressure. Companies must therefore expect that the requirements will take effect very quickly.
Our clear recommendation:
Prepare yourself for NIS-2 now, even if the law has not yet been finally promulgated. Anyone who takes action at an early stage avoids risks, bottlenecks and potentially high fines.
.avif)
At first glance, the fines for NIS-2 seem intimidating:
But these fines are just the tip of the iceberg.
The fine itself is already expensive, but the hidden follow-up costs are usually much higher.
If you implement NIS-2 on time, you not only save money, but also ensure the future viability and reputation of your company.
With increasing digitization and connectivity, the risks of cyber attacks have also increased significantly. Since the start of the Russian attack on Ukraine, the threat situation has increased significantly once again. Ransomware attacks, DDoS attacks, and supply chain attacks are constantly increasing.
The NIS2 Directive (EU 2022/2555) aims to ensure a uniformly high level of cybersecurity throughout the EU. In Germany, it is currently being implemented with the ”NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG)“. The government draft was adopted by the Federal Cabinet on 30-07-2025 (Federal government).
This new law builds on the previous IT Security Act 2.0, but changes over 26 existing laws (including the BSI Act, the Energy Industry Act, the Telecommunications Act, the Social Code). The previous BSI Act is being fundamentally reformed — well-known paragraphs such as “Section 8a BSI Act” are being replaced by new structures, such as “Section 30 (1) et seq. of the BSI Act”.
1) In Germany, significantly more companies will be subject to NIS2 obligations in the future than before.
2) Affected companies are divided into three groups:
The law passed on November 13, 2025 further expands the group of institutions affected. In addition to companies from the energy, health, transport, digital infrastructure, and production sectors, public authorities and administrations are also explicitly included in the scope of application for the first time.
3) These groups must conduct mandatory risk management, report security incidents, register with the BSI (within 3 months of entry into force) and meet further requirements (BSI).
4) Particularly relevant for management: There are clear obligations and liability regulations.
5) There is no deadline for implementation — the law comes into force immediately after its promulgation (Federal government, KPMG).

While only a few hundred KRITIS operators have been subject to the regulations so far, around 29,000—30,000 companies in Germany will be affected in the future (Security Insider). As a result of the law passed on 13-11-2025, official institutions and public administration are now explicitly affected — not just operators of critical infrastructure.

The requirements are set out in the new Section 30 BSIG-E. Ten key areas of action are mandatory, but the deadlines are provisional and depend on the final legislative texts:
In addition, the following applies:
Reporting requirements for security incidents (24-hour early warning, 72 h detailed report, 30-day final report) (bundestag).
Duties for management: It must approve measures, monitor them, participate in training courses — and is liable for breaches of duty (BSI).
“State of the art” means that established methods such as ISO/IEC 27001, NIST or BSI Grundschutz are used. Which specific measures are required depends on the risk situation.
Example: In one company, an authorization concept may be sufficient; in another, database encryption is state of the art.
Which parts of the organization does NIS2 apply to?
For the entire company, not just for individual areas.
Does implementation have to be proven?

Have you already made all the preparations for the NIS2 Directive?
No? We'll show you how you can prepare yourself perfectly with the Aeneis BPM & GRC software, saving you a lot of time and nerves.
The NIS2 Policy is an updated version of the first NIS Policy based on aims to achieve higher levels of cybersecurity and resilience across the EU. In order to prepare for and implement the NIS2 Directive, companies and relevant organizations should consider a few important points. In this guide, you will learn which steps you can take and how you and your employees securely implement the NIS2 guideline in the ISMS app of the BPM & GRC software Aeneis.
Understand the specific requirements introduced by the NIS2 Directive, including the expanded scope of application and the new security and reporting obligations.
Determine whether your organization falls under the expanded definition of critical and important facilities.
In the ISMS app in the Aeneis BPM & GRC software, you have the option to integrate entire manuals and make them available company-wide. In addition, you can graphically map your information security organization there and clearly assign responsibilities.
Your employees know exactly what responsibilities and tasks they have and can find out about important standards, guidelines and requirements. Everything in one place, on one platform.
Assess network and information systems risks and identify where vulnerabilities could exist.
Create plans to minimize these risks, including implementing appropriate security measures.
Aeneis provides you with a risk management process to identify and correctly manage risks that may arise in the context of your cyber and information security. You can implement this process in three simple steps, from risk identification to risk analysis and risk treatment.
There, you can identify which risks may arise directly in your business processes, assess their criticality and develop a plan for treatment with appropriate measures.
Implement both technical and organizational measures to increase the security of your systems. This can include encryption, access controls, regular security audits, and more.
Security measures should be continuously assessed and adapted to new threats.
To maintain information security in your company, you can access a generic pool of measures in the GRC software Aeneis. This helps you to quickly start implementing security measures. When creating your own measures, you can access the pool of measures and directly assign the measure to employees for implementation. You can overview all measures in reports and thus adapt them continuously and quickly to changes.
Develop processes for reporting security incidents, as required by the policy.
Make sure security incident management plans are in place, including recovery plans
Use the ISMS software Aeneis to document and manage your security incidents. There, you can record incidents that have occurred in a separate area in detail, as required by the Directive. The recorded incidents then provide you with information about relevant training topics and help you to specify your risks and measures.
Collaborate with national authorities, such as the national CSIRT and other relevant institutions.
Share information and best practices with other parties within the EU.
Send your documented incidents, risks, and measures to organizations and authorities. In the Aeneis BPM & GRC software, you can not only store content centrally, but also generate print reports from it with just a few clicks. Output tables to an Excel file and save documents as a PDF. This makes it easier for you both to exchange ideas with relevant institutions and to prove regulations in audits.
Conduct regular reviews of your compliance with the NIS 2 policy
Use external audits to verify compliance and build trust with stakeholders.
With reports and evaluations, which present your security risks and measures in graphical and tabular form, you can check your information security status at any time. In the ISMS software, you can demonstrably document NIS2 requirements and thus easily prove them in audits. In this way, you ensure greater security within your company and at the same time contribute to greater trust among customers and partners.
Regularly train your employees on cybersecurity practices and the specific requirements of the NIS2 Directive.
Conduct internal campaigns to increase awareness and importance of cybersecurity.
In the Aeneis BPM & GRC software, you can document security incidents that have occurred and directly deduce where internal training is required. You can also directly raise awareness of cybersecurity among your employees by making information available centrally in Aeneis and involving it in the implementation of measures.