What is NIS2?
NIS2 is the EU's network and information security directive (EU 2022/2555). It obliges companies in 18 sectors to manage their IT risks, secure their supply chains and report significant incidents, and it makes management personally liable for getting this done. In Germany it covers an estimated 30,000 companies, most of them mid-sized businesses that never had to think about a security regulation before.
Who is affected
As a rule of thumb: companies with 50 or more employees or more than €10 million annual turnover, active in one of 18 sectors such as manufacturing, logistics, food production, waste management, chemicals or digital services. Smaller companies can be pulled in indirectly, because affected customers pass security requirements down their supply chain.
What it requires
Risk analysis and security policies, incident handling, backup and crisis management, supply-chain security, access control with multi-factor authentication, encryption and security training. Significant incidents must be reported: an early warning within 24 hours and an assessment within 72 hours. Affected companies also register with the national authority (in Germany the BSI).
What happens if you ignore it
Fines reach up to €10 million or 2% of global turnover, and management can be held personally liable for missing security measures. The quieter consequence arrives earlier: larger customers increasingly demand NIS2-grade proof from their suppliers before signing, so the directive shows up in sales long before an auditor does.
FAQ
Common questions.
Does NIS2 apply to small companies too?
Usually not directly below 50 employees, with exceptions for critical services. But affected customers push the requirements into their contracts, so many small suppliers end up having to meet the same standards anyway.
Where do I start?
With an inventory: what runs where, what is backed up, who has access. That is exactly what an IT audit delivers. Most of the required measures, patching, tested backups, monitoring, MFA, are standard managed IT practice, not exotic security projects.
Book a free infrastructure assessment.
A no-commitment look at your setup. What's healthy, what's at risk, and what to fix first. Real answers, no pressure.