NIS 2 for Mid-Sized Companies: Who Is Affected and What to Do Now (as of July 2026)
The NIS 2 directive has been transposed into German law since December 2025, and around 29,500 companies are affected, many of them mid-sized. Based on the legal situation as of July 2026, this article explains who falls under the law, which duties and deadlines apply, and which steps let you approach implementation in a structured way.
This article provides general information and is no substitute for legal advice. For binding answers on your situation, consult a law firm.
Legal status as of July 2026: NIS 2 is applicable law
NIS 2 stands for the second EU directive on network and information security, a European set of rules that obliges companies in critical sectors to implement cybersecurity measures. Germany has transposed the directive into national law with the NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG, the German NIS 2 implementation and cybersecurity strengthening act). Its centerpiece is a revised BSI-Gesetz (BSIG), the law governing the BSI (Germany’s Federal Office for Information Security), which acts as the central supervisory authority. The law was promulgated in the Bundesgesetzblatt (the Federal Law Gazette) on December 5, 2025 and entered into force on December 6, 2025. This article reflects the legal situation as of July 2026.
There are no transition periods for the substantive obligations. Risk management, reporting duties, and management duties have applied since the law entered into force. This sets NIS 2 apart from some other regulation and explains why the topic is currently landing on management’s desk in many companies.
Registration is lagging nationwide. Under Paragraf 33 BSIG (Section 33 of the act), entities that were already covered when the law entered into force had to register within three months, that is, by March 6, 2026. According to reports from specialist law firms, only around 11,500 of an estimated 29,500 affected companies had registered by that date, and around 18,500 by the end of May 2026. The BSI tolerates late registrations until July 31, 2026. This is an administrative forbearance, not an extension of the statutory deadline. If you are affected and not yet registered, you should therefore not postpone registration any further.
Who is affected: sectors and size thresholds
The law covers 18 sectors, spread across two annexes. Anlage 1 (Annex 1 of the act) lists sectors of high criticality: energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, management of ICT services for other companies, public administration, and space. Anlage 2 (Annex 2) adds other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing, including mechanical engineering, vehicle construction, electronics, and medical devices, as well as providers of digital services and research.
Whether a company in one of these sectors is actually regulated is decided by size thresholds. Put simply, a company counts as an important entity (wichtige Einrichtung) if it operates in one of the 18 sectors and employs at least 50 people, or reaches both more than 10 million euros in annual revenue and more than 10 million euros in balance sheet total. A company counts as a particularly important entity (besonders wichtige Einrichtung) if it operates in an Anlage 1 sector and employs at least 250 people, or reaches more than 50 million euros in revenue and at the same time more than 43 million euros in balance sheet total. For mid-sized companies, the most important message is: as few as 50 employees in one of the sectors can be enough.
Some companies are covered regardless of their size, including operators of critical facilities (KRITIS, the German term for critical infrastructure, such as large energy or water supply facilities), providers of DNS services, that is, name resolution on the internet, operators of top-level domain registries, and trust service providers, for example for qualified electronic signatures. Partly lower thresholds apply to telecommunications providers.
The BSI provides an official online self-assessment at betroffenheitspruefung-nis-2.bsi.de. Carry out this check and document the result in writing, even if it is negative. That way you can later demonstrate that you examined the question.
The catalog of duties: risk management under Paragraf 30 BSIG
Paragraf 30 BSIG requires affected entities to take suitable, proportionate, and effective technical and organizational measures. The law lists ten areas: concepts for risk analysis and IT security, handling of security incidents, business continuity with backup management, recovery, and crisis management, supply chain security, security in the procurement, development, and maintenance of IT systems, procedures for assessing the effectiveness of the entity’s own measures, cyber hygiene and training, use of cryptography and encryption, personnel security with access control and management of the entity’s own IT systems, as well as multi-factor authentication, that is, signing in with a second factor in addition to the password, and secured communication systems.
The law explicitly requires proportionality: the decisive factors are the extent of risk exposure, the size of the entity, the cost of implementation, and the probability and severity of possible incidents. A business with 60 employees therefore does not have to reach the security level of a large corporation. But it must be able to justify and document why the measures taken are appropriate for its risk.
For the broad majority of affected companies, Paragraf 30 does not contain a certification requirement. Aligning with established standards such as ISO 27001, the international standard for information security management systems, or with the BSI’s IT-Grundschutz (the BSI’s baseline protection methodology) is still worthwhile, because it brings structure to the implementation and makes documentation easier.
Reporting duties and registration: deadlines that require preparation
Under Paragraf 32 BSIG, significant security incidents must be reported to a joint reporting office run by the BSI and the BBK (Germany’s Federal Office of Civil Protection and Disaster Assistance), in three stages: an early warning without undue delay, at the latest 24 hours after becoming aware of the incident, a more detailed report with an initial assessment at the latest after 72 hours, and a final report at the latest one month after the incident was reported. On request by the BSI, interim reports must be submitted in addition.
24 hours is short when operations are down at the same time. If you only clarify in an actual emergency who reports, who decides, and where the credentials for the reporting portal are stored, you will hardly meet the deadline. Define the reporting path in advance: responsible person, deputy, availability outside office hours. Run through the procedure once as a test.
Registration under Paragraf 33 BSIG takes place via the BSI portal and requires, among other things, name, legal form, contact details, IP address ranges, and the assignment to a sector. Changes must be reported within two weeks at the latest. Access requires an ELSTER organization certificate, the electronic proof of identity for companies issued via ELSTER, Germany’s tax portal. Applying for it takes some lead time, so plan for that.
Management: personal duties, supervision, and fines
Paragraf 38 BSIG explicitly places duties on the management: it must implement the risk management measures under Paragraf 30, monitor their implementation, and regularly attend training in order to be able to assess risks itself. The operational work may be delegated to the IT lead or a service provider, the responsibility may not.
If the management culpably violates these duties, it is liable to its own company for damages under the corporate law rules of the respective legal form. Added to this are fines under Paragraf 65 BSIG: up to 10 million euros for particularly important entities and up to 7 million euros for important entities. For companies with very high worldwide revenue, revenue-based caps of 2 and 1.4 percent respectively apply. Violations of the registration duty are also subject to fines, with specialist articles citing up to 500,000 euros here.
When it comes to supervision, the law distinguishes: particularly important entities are subject to comprehensive supervision by the BSI, while important entities are supervised on a case-by-case basis, meaning the BSI mainly acts there after incidents or concrete indications. You should not rely on that: the duties apply equally in both categories.
Suppliers: not regulated, but held to account through the supply chain
One of the ten areas of measures in Paragraf 30 BSIG is supply chain security. Regulated companies must assess the risks arising from their service providers and suppliers. In practice, they pass these requirements on contractually.
For smaller suppliers that are themselves below the thresholds, this means: security questionnaires from customers, contractual minimum requirements for IT security, clauses on reporting incidents, and in some cases requests for evidence. Anyone who leaves such inquiries unanswered risks losing orders over time, entirely without any statutory duty of their own.
It makes sense to answer these requirements in a bundled way rather than customer by customer. A baseline of security that is properly documented once, with patch management, that is, the orderly installation of security updates, with tested backups, multi-factor authentication, and a simple emergency plan, covers a large share of the usual questionnaires and strengthens the business independently of NIS 2.
First steps: a realistic sequence
First: check whether you are affected, ideally with the official BSI self-assessment, and document the result. Second: if you are affected, register in the BSI portal without delay, as the forbearance period for late registrations ran until July 31, 2026 according to the published guidance. Third: involve the management, appoint responsible persons, and plan the legally required training for the management level.
Fourth: carry out a gap analysis, that is, a structured comparison between the current state of your IT security and the ten areas of measures from Paragraf 30 BSIG. Fifth: prioritize. The ability to report, tested backups, and multi-factor authentication deliver substance quickly, the rest follows in an action plan with deadlines. Sixth: review your service provider and supplier contracts with regard to security requirements and reporting paths.
An honest assessment: the self-assessment, the registration, and a first stocktake are quite feasible with internal IT. For the structured gap analysis, for building an information security management system, that is, the orderly organization of all security processes, and for preparing the reporting processes, experienced external support often saves a lot of time. Individual legal questions, such as classification in borderline cases or the drafting of contract clauses, belong in the hands of a specialized law firm. This article does not replace legal advice.
The short version
NIS 2 has been applicable law in Germany since December 6, 2025, with no transition periods for the substantive obligations. If you check properly whether you are affected, complete the registration, and work through the ten areas of measures in a clear sequence, you turn a statutory duty into a plannable project. Ruknova, based in Schwerin, supports companies Germany-wide with the self-assessment, the gap analysis, and the technical implementation.