Check now: Are you affected by NIS-2?

The law implementing the NIS 2 Directive came into force on December 6, 2025.

The Bundestag has passed the NIS 2 Act and is still pending approval by the Federal Council. Once promulgated, the Act comes into force without a transitional period. With our 7-step plan, you can keep track of things and get your company on course for compliance in good time.

Be part
of intellior

When does NIS-2 come into force and what are the penalties?

NIS-2: Bundestag passes law — act quickly now!

The Bundestag has passed the German NIS-2 Act. The approval of the Federal Council is still pending, but after the announcement, the duties will come into force without longer transition periods. Affected companies should prepare now.

The Bundestag passed the NIS-2 Act on November 13, 2025.

This is a decisive step towards the overdue implementation of the EU Directive. The approval of the Federal Council is currently pending.

As soon as the Act is published in the Federal Law Gazette, it comes into force immediately - without longer transition periods. Companies must therefore prepare all necessary safety measures now and incorporate them into their organization.

Germany has already exceeded the EU implementation deadline. The political and regulatory pressure is correspondingly high, so that a quick announcement must be expected.

Penalties:

  • For important facilities: up to 1.4% of annual global turnover.
  • Only with a turnover exceeding €500 million does a fixed upper limit of €7 million apply (Section 65 (7)).
  • For particularly important institutions: up to €10 million or 2% of annual global turnover — the higher amount in each case (KPMG).

Webinar recording from October 2025 for IS officers & IT managers

Where does NIS-2 currently apply in Europe?

The NIS 2 Directive is an EU-wide legislative project and must be implemented into national law in all Member States. The aim is to create a consistently high level of cybersecurity across Europe.

The current situation in Europe

  • Since October 2024 all EU member states are required to transpose NIS-2 into national law.
  • Many countries are already there, others are still lagging behind.

Countries where NIS-2 already applies:

Belgium, Croatia, Hungary, Italy, Latvia, Lithuania, Romania, Slovakia, Slovenia, Malta and Liechtenstein (as an EEA state).

Countries with ongoing implementation (draft laws or parliamentary procedures):

Germany, France, Denmark, Finland, Netherlands, Austria, Poland, Ireland, Sweden, Norway (EEA) and more.

There are delays in other Member States, such as Portugal or Spain, where the situation is currently still unclear.

What that means for you:

If you operate in several European countries, you need to keep an eye on NIS-2 not only in Germany, but also in the countries where you have branches or business activities. Each country implements the Directive with its own laws and deadlines.

Conclusion:

NIS-2 is a European issue. Anyone with an international presence should closely monitor the implementation status in the individual countries and integrate the requirements into their own processes at an early stage.

Example companies

  • Staff: 400
  • Annual turnover: €50 million
  • Classification: Important Facility

Basics of the amount of fines

  • For important institutions: fines of up to €7 million (Section 64 (5) No. 1 b)).
  • For important institutions with a turnover exceeding €500 million: different fines of up to 1.4% of the total turnover (Section 65 (7)).

Example of penalty calculation

  • Turnover = €50 million → below the 500 million threshold.
  • There is a fixed limit: fines of up to €7 million.

Classification of costs

  • Maximum fine for the company: €7 million
  • Costs for an ISMS in accordance with ISO 27001 (including introduction, training, software): approx. 100,000—150,000 €
  • Ratio: The penalty is round 50 to 70 times more expensive than a timely implementation.

Personal liability of management

  • Management must approve, implement, and monitor NIS 2 measures (SECTION 30 BSIG-E).
  • Breaches of duty may lead to personal liability — even to the extend of recourse claims against private assets.
  • Without adequate D&O insurance, individual managing directors are therefore exposed to financial risk.

Conclusion

As an “important institution”, a medium-sized company with 400 employees and a turnover of €50 million risks fines of up to €7 million for NIS 2 violations.
In addition, management faces personal liability if it fails to fulfill its legal obligations.
The introduction of an ISMS, on the other hand, costs only a fraction — and protects against penalties, loss of reputation and management liability.

The Bundestag passed the German NIS-2 Act on November 13, 2025. The approval of the Federal Council is still pending, but as soon as the Act is promulgated in the Federal Law Gazette, it comes into force immediately. No longer transition periods are foreseen.

Germany has already exceeded the EU implementation deadline, which has significantly increased political and regulatory pressure. Companies must therefore expect that the requirements will take effect very quickly.

Our clear recommendation:
Prepare yourself for NIS-2 now, even if the law has not yet been finally promulgated. Anyone who takes action at an early stage avoids risks, bottlenecks and potentially high fines.

NIS-2 penalties are just the tip of the iceberg

Penalties are just the tip of the iceberg

At first glance, the fines for NIS-2 seem intimidating:

  • Up to €7 million or 1.4% turnover for important institutions
  • Up to €10 million or 2% turnover for particularly important institutions

But these fines are just the tip of the iceberg.

There are much greater risks lurking beneath the water surface:

  • Production downtime due to cyber attacks → can cost millions
  • Loss of customer trust → difficult to measure, but often threatening the company existence
  • Reputational damage → bad press has an effect for years
  • Management liability → personal responsibility of management & board
  • Subsequent requirements & audits by the BSI → additional financial and organizational expenses

Conclusion:

The fine itself is already expensive, but the hidden follow-up costs are usually much higher.
If you implement NIS-2 on time, you not only save money, but also ensure the future viability and reputation of your company.

What is NIS2 anyway and why is it important?

With increasing digitization and connectivity, the risks of cyber attacks have also increased significantly. Since the start of the Russian attack on Ukraine, the threat situation has increased significantly once again. Ransomware attacks, DDoS attacks, and supply chain attacks are constantly increasing.

The NIS2 Directive (EU 2022/2555) aims to ensure a uniformly high level of cybersecurity throughout the EU. In Germany, it is currently being implemented with the ”NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG)“. The government draft was adopted by the Federal Cabinet on 30-07-2025 (Federal government).

This new law builds on the previous IT Security Act 2.0, but changes over 26 existing laws (including the BSI Act, the Energy Industry Act, the Telecommunications Act, the Social Code). The previous BSI Act is being fundamentally reformed — well-known paragraphs such as “Section 8a BSI Act” are being replaced by new structures, such as “Section 30 (1) et seq. of the BSI Act”.

NIS2 in 5 sentences for management

1) In Germany, significantly more companies will be subject to NIS2 obligations in the future than before.

2) Affected companies are divided into three groups:

  1. Operators of critical systems
  2. Particularly important facilities
  3. Key facilities

The law passed on November 13, 2025 further expands the group of institutions affected. In addition to companies from the energy, health, transport, digital infrastructure, and production sectors, public authorities and administrations are also explicitly included in the scope of application for the first time.

3) These groups must conduct mandatory risk management, report security incidents, register with the BSI (within 3 months of entry into force) and meet further requirements (BSI).

4) Particularly relevant for management: There are clear obligations and liability regulations.

5) There is no deadline for implementation — the law comes into force immediately after its promulgation (Federal government, KPMG).

Present the urgency of NIS-2 to management

Who is affected by NIS2?

While only a few hundred KRITIS operators have been subject to the regulations so far, around 29,000—30,000 companies in Germany will be affected in the future (Security Insider). As a result of the law passed on 13-11-2025, official institutions and public administration are now explicitly affected — not just operators of critical infrastructure.

NIS-2 impact assessment

NIS-2 impact assessment
*Appendix 1 | Appendix 2, Source: Decision tree of the BSI NIS-2 impact assessment

Explanations of the concern

  • Operators of critical plants: sectors such as energy, health, transportation, water, nutrition, waste management, IT/telecommunications, space, finance. Thresholds remain the same as in the previous KRITIS system.
  • Appendix 1 and Appendix 2: Include detailed lists of industries and activities. Appendix 1 lists “particularly important” facilities and Appendix 2 lists “important” facilities.
  • New criteria: Number of employees, turnover and balance sheet total play a role.
Check your NIS-2 condition now
The Federal Office for Information Security (BSI) offers a free impact assessment.
- Quick questions, easy to use
- Immediate initial assessment of whether your company is affected by NIS-2
- Anonymous use, no data storage
- The result is for guidance only, not legally binding

Check NIS-2 impact assessment with the BSI now

What specific measures does NIS2 require?

The requirements are set out in the new Section 30 BSIG-E. Ten key areas of action are mandatory, but the deadlines are provisional and depend on the final legislative texts:

  1. Risk analysis & IT security concepts
  2. Incident management
  3. Operational Safety & Disaster Recovery
  4. Supply chain security
  5. Secure procurement, development & maintenance
  6. Evaluation of the effectiveness of safety measures
  7. Cyber hygiene & training
  8. Cryptography & Encryption
  9. Staff security & access control
  10. Multi-factor authentication & secure communication

In addition, the following applies:

Reporting requirements for security incidents (24-hour early warning, 72 h detailed report, 30-day final report) (bundestag).

Duties for management: It must approve measures, monitor them, participate in training courses — and is liable for breaches of duty (BSI).

Implement state of the art

“State of the art” means that established methods such as ISO/IEC 27001, NIST or BSI Grundschutz are used. Which specific measures are required depends on the risk situation.

Example: In one company, an authorization concept may be sufficient; in another, database encryption is state of the art.

Key questions about NIS2

Which parts of the organization does NIS2 apply to?
For the entire company, not just for individual areas.

Does implementation have to be proven?

  • Operators of critical systems: Verification every 3 years (instead of the previous 2 years).
  • Particularly important institutions: no general obligation, but BSI can request evidence.
  • Important institutions: Evidence or audits only in individual cases.
NIS-2 guide

Your 7-step plan for secure NIS-2 implementation, this is how Aeneis supports you.

Your guide to greater cybersecurity

Have you already made all the preparations for the NIS2 Directive?
No? We'll show you how you can prepare yourself perfectly with the Aeneis BPM & GRC software, saving you a lot of time and nerves.


The NIS2 Policy is an updated version of the first NIS Policy based on aims to achieve higher levels of cybersecurity and resilience across the EU. In order to prepare for and implement the NIS2 Directive, companies and relevant organizations should consider a few important points. In this guide, you will learn which steps you can take and how you and your employees securely implement the NIS2 guideline in the ISMS app of the BPM & GRC software Aeneis.

NIS 2 Implementieren - Schritt 1: Anforderungen verstehen

1. Understanding the requirements

Informing about the policy

Understand the specific requirements introduced by the NIS2 Directive, including the expanded scope of application and the new security and reporting obligations.

Identifying relevant actors

Determine whether your organization falls under the expanded definition of critical and important facilities.

Manuals and organization in Aeneis

In the ISMS app in the Aeneis BPM & GRC software, you have the option to integrate entire manuals and make them available company-wide. In addition, you can graphically map your information security organization there and clearly assign responsibilities.

Your employees know exactly what responsibilities and tasks they have and can find out about important standards, guidelines and requirements. Everything in one place, on one platform.

2. Risk management

Carrying out risk assessments

Assess network and information systems risks and identify where vulnerabilities could exist.

Development of a risk management plan

Create plans to minimize these risks, including implementing appropriate security measures.

Managing risks in 3 steps in Aeneis

Aeneis provides you with a risk management process to identify and correctly manage risks that may arise in the context of your cyber and information security. You can implement this process in three simple steps, from risk identification to risk analysis and risk treatment.

There, you can identify which risks may arise directly in your business processes, assess their criticality and develop a plan for treatment with appropriate measures.

NIS 2 Implementieren - Schritt 2: Risiken managen
NIS 2 Implementieren - Schritt 3: Sicherheitsmaßnahmen implementieren

3. Implementing security measures

Implement both technical and organizational measures to increase the security of your systems. This can include encryption, access controls, regular security audits, and more.

Lasting development

Security measures should be continuously assessed and adapted to new threats.

Measure management in Aeneis

To maintain information security in your company, you can access a generic pool of measures in the GRC software Aeneis. This helps you to quickly start implementing security measures. When creating your own measures, you can access the pool of measures and directly assign the measure to employees for implementation. You can overview all measures in reports and thus adapt them continuously and quickly to changes.

4. Reporting and Incident Management

Establishing reporting channels

Develop processes for reporting security incidents, as required by the policy.

Incident response planning

Make sure security incident management plans are in place, including recovery plans

Security incidents

Use the ISMS software Aeneis to document and manage your security incidents. There, you can record incidents that have occurred in a separate area in detail, as required by the Directive. The recorded incidents then provide you with information about relevant training topics and help you to specify your risks and measures.

NIS 2 Implementieren - Schritt 4: Vorfälle managen
NIS 2 Implementieren - Schritt 5: Informationen dokumentieren und kommunizieren

5. Cooperation and exchange of information

Cooperating at national level

Collaborate with national authorities, such as the national CSIRT and other relevant institutions.

Promoting the exchange of information

Share information and best practices with other parties within the EU.

Print reports in Aeneis

Send your documented incidents, risks, and measures to organizations and authorities. In the Aeneis BPM & GRC software, you can not only store content centrally, but also generate print reports from it with just a few clicks. Output tables to an Excel file and save documents as a PDF. This makes it easier for you both to exchange ideas with relevant institutions and to prove regulations in audits.

6. Compliance and monitoring

Periodic reviews

Conduct regular reviews of your compliance with the NIS 2 policy

External audits and certifications

Use external audits to verify compliance and build trust with stakeholders.

Reports and evaluations

With reports and evaluations, which present your security risks and measures in graphical and tabular form, you can check your information security status at any time. In the ISMS software, you can demonstrably document NIS2 requirements and thus easily prove them in audits. In this way, you ensure greater security within your company and at the same time contribute to greater trust among customers and partners.

NIS 2 Implementieren - Schritt 6: Compliance managen
NIS 2 Implementieren - Schritt 7: Bewusstsein bilden

7. Education and awareness-raising

Employee training

Regularly train your employees on cybersecurity practices and the specific requirements of the NIS2 Directive.

Awareness campaigns

Conduct internal campaigns to increase awareness and importance of cybersecurity.

Training needs and provision of information

In the Aeneis BPM & GRC software, you can document security incidents that have occurred and directly deduce where internal training is required. You can also directly raise awareness of cybersecurity among your employees by making information available centrally in Aeneis and involving it in the implementation of measures.

Follow these 7 steps in Aeneis to be NIS-2 compliant:

Download PDF here

“We design our process management from functional documentation to an instrument for overall process control. In doing so, we transform our document management system into a lively, always up-to-date process management system and implement the regulatory requirements in Aeneis in a legally secure and digital manner. A core element of this is, for example, the connection of the policy structure with a customer and value-added oriented process structure. ”

#be part of the process
Portrait von Tobias Hehn von der Deka-Bank

“It is particularly valuable for us that Aeneis optimally supports TRILUX's Simplify philosophy: Our employees have easy access to all relevant processes, which results in significantly improved collaboration.
In addition, we can effectively map all touchpoints with our customers and their dependencies in order to align our processes even better with customer needs. ”

#be part of the process
Portrait von Stefan Köster von TRILUX

“Before implementing Aeneids, there was no uniform process model in our company. Our goal was to create a central port for all business areas and management systems, supported by a uniform process model. By using Aeneis as BPM and GRC software, we can digitize our processes in a validated environment and integrate them into a central platform. This enables us to consolidate our global business processes and management systems and laid the foundation for merging the process-supporting application structure. ”

#be part of the process
Portrait von Robin Schmalz von Ottobock

In the past, data maintenance was cumbersome and paper-based. With Aeneis, we have significantly reduced effort, simplified complexity and can now fully concentrate on our actual profession again. Aeneis combines all the important functions we need: process descriptions, risk management, audits, error reporting systems, and much more. The big advantage is that we can adapt it exactly to our structures and needs, which is often not possible with other solutions.

#be part of the process

“Until 12 years ago, we had not documented any processes, just a few work instructions and a few organizational guidelines. Then we got to know Aeneis through an external consultant. With Aeneis as BPM software, we have now mapped our key business processes and organizational structure and integrated everything into a central quality management system down to employee level. This is fully accessible to all our employees and integrated into our existing intranet. The GoToMarket process, which is very important to us, forms the core of documenting our process organization and the organizational chart, which is very conveniently structured in Aeneis, provides guidance about our organizational structure. ”

#be part of the process
Portrait von René Slavik von MHZ

Leading experts from the industry — including in-house consulting managers, quality management representatives, process managers, organizational development managers and risk management experts — presented their valuable experiences and successes with Aeneis at the BPM|Symposium. They shared exciting insights into integrated management systems, process-oriented organizations in critical infrastructures, and interesting best practices. In this video, you can see brief statements about their experiences with Aeneis in everyday business. Have fun watching!

#be part of the process

“We didn't have any process documentation before, just a few instructions and forms. But then, as part of further training, we got to know another company that had already successfully used the system. With Aeneis as BPM and GRC software, we have now documented our processes and integrated them together with our documents, instructions and forms into a central management system. This led to improved knowledge of processes and cooperation and thus to fewer frictional losses and extra work. ”

#be part of the process
Portrait von Nils Werner von ppg

“In the Infraserv Höchst Group, I worked for over 15 years as a responsible coordinator for process management and as a management representative responsible for the PRISMA integrated management system (software Aeneis) and the associated certifications. Aeneis has given us the flexibility to successfully implement the many requirements with an integrated management system and to be 'compliant'. The modules offered or our own customizing provided us with very good support.”

#be part of the process
Bernd Hientzsch von Infraserv Höchst

“Since 1990, SHD has developed into one of the market-leading companies in the areas of IT infrastructure and process digitization.
Among other things, we recommend ISMS @Aeneis to our customers so that they can master ISO 27001 and NIS2, take their risk management to a new level and to protect them in emergencies (business continuity management). The innovative power is unwavering, so with Aeneis we are looking forward to implementing our clients' great ideas.”

#be part of the process

“As an official service partner of intellior, we offer you a first-class solution for GoBD-compliant process documentation with GoBD@aeneis. This platform not only serves as a basis for tax compliance, but also enables precise monitoring and management of tax risks. By comprehensively documenting IT systems and interfaces, Aeneis maximizes application acceptance and effectively supports you in optimizing your tax processes and preparing for tax audits — everything is fully integrated and automated. With Aeneis, you can rely on efficiency, compliance and future security for your business processes. ”

#be part of the process
Understanding, optimizing, and securing success-critical processes
See how easy NIS-2 can be implemented.

Arrange a personal consultation:
Request a free NIS 2 expert discussion