NIS2 makes cybersecurity a board-level duty in all 27 EU member states. Management has to approve and oversee security measures and can be held liable for breaches. Fines reach up to €10 million or 2% of worldwide turnover.
Yet many companies still haven't caught up. Take Germany, the EU's largest economy: by the end of June 2026, only 17,729 companies had registered with the national authority, against an estimated 29,500 in scope.
The good news: NIS2 is an EU directive, so the core rules are the same everywhere. Each country writes its own law and names its own authority, but scope, obligations, reporting deadlines and fines follow one template.
So in this issue, I'll walk you through NIS2 using Germany as the worked example. Swap in your own national law and authority, and the logic stays the same.
From EU directive to national law
NIS2 (Directive 2022/2555) doesn't apply directly. Every member state had to turn it into national law by October 2024. In July 2026, the European Commission took Ireland, Spain, France and the Netherlands to the EU Court of Justice over it.
Germany was late too. Its NIS2 Implementation Act only came into force on 6 December 2025 and rewrote the BSI Act (BSIG). So in Germany, NIS2 obligations are sections of the BSIG. That's the law you quote. Below, I give both references: the NIS2 article, which applies EU-wide, and the German section as the example.

Step 0: Are you affected?
There are two tests.
Test 1: Your sector. Annex 1 covers sectors like energy, transport, finance, health, water, digital infrastructure and space. Annex 2 covers sectors like postal services, waste management, chemicals, food, manufacturing, digital providers and research.
Test 2: Your size.
Essential entity: Annex 1 sector and 250+ employees, or more than €50m turnover and €43m balance sheet.
Important entity: 50+ employees, or more than €10m turnover and balance sheet. Annex 2 companies are "only" important, even if they're large.
For some types of companies, size doesn't matter: operators of critical facilities, qualified trust service providers, TLD registries and DNS providers are always in. And if you're part of a group, linked companies can count towards your numbers.

The obligations at a glance
You're in scope. Now what? Germany's BSIG sets out eight obligations. The biggest, risk management (Art. 21 NIS2 / § 30 BSIG), gets its own issue. Today we cover the four that catch most companies off guard: registration, management, reporting and notification.

Obligation 1: Registration (Art. 3 NIS2 / § 33 BSIG)
The one many companies have already missed. It's two steps:
Identification: Are you affected? That's the scope check above.
Registration: Register in the BSI portal.
In Germany, you have three months at most from the moment you become an essential or important entity. For everyone in scope when the law came into force, that was 6 March 2026. If you haven't registered, do it now. Missing it can cost up to €500,000.
And it's not a one-time thing. Changes to your master data must be updated within two weeks at most.

Obligation 2: Management (Art. 20 NIS2 / § 38 BSIG)
This is where it gets personal. "Management" means the managing directors or the board. Not the CISO. Not the IT manager.
They have three duties:
Implementation: Approve and implement appropriate risk management measures. Does the managing director configure the firewall? Of course not. They can delegate the work, but not the responsibility.
Oversight: Monitor whether the measures actually work. A policy signed once and put in a drawer is not enough.
Training: Attend regular training, so they can actually judge the risks.
In an ISO 27001 audit, this is exactly where I ask top management: show me the evidence.

If you don't comply, Germany's § 65 BSIG mirrors the EU-wide NIS2 levels (Art. 34): fines of up to €10 million or 2% of worldwide turnover for essential entities (whichever is higher), and up to €7 million or 1.4% for important entities.

But this is what makes managing directors sit up: NIS2 requires every member state to hold management accountable. In Germany, under § 38(2) BSIG, management is liable with their private assets for damage culpably caused by breaching these duties. And the company can't waive those claims.
Obligation 3: Reporting (Art. 23 NIS2 / § 32 BSIG)
First, a distinction people mix up all the time. Reporting (§ 32) means you report to the authority (in Germany, the BSI). Notification (§ 35) means you inform your customers.
A security incident is basically any event that compromises the availability, integrity or confidentiality of data or services. Pretty much every malware infection counts. But you only report it if it's significant: if it causes, or can cause, severe operational disruption or financial loss, or considerable damage to others. Note the words "can cause". You don't wait for the damage.
Let's make it concrete. Monday morning. An employee in accounting clicks a link in an email, and malware lands on his laptop.
Scenario 1: The antivirus spots the unusual behaviour within the first hour and isolates the laptop automatically. You handle it, you document it. Not significant. No report.

Scenario 2: The malware goes undetected. Attackers move through the network and encrypt the customer databases. Production stops. Now it's significant, and from the moment you're aware of it, the clock is ticking.

24 hours: Early warning. Is a malicious act suspected? Could there be cross-border impact?
72 hours: Incident notification. A first assessment of severity, impact and indicators of compromise.
1 month: Final report. Root cause, full impact and remedial measures.

My advice: don't figure out who reports to the BSI on day one of a ransomware attack. Put it in your incident response plan now. And GDPR or DORA may require separate reports for the same incident.
Obligation 4: Notification (Art. 23 NIS2 / § 35 BSIG)
Notification comes in two flavours.
Reactive (§ 35(1)): After a significant incident, the BSI can order you to inform your customers without undue delay. This applies to all essential and important entities.
Proactive (§ 35(2)): Nothing has happened yet, but you've spotted a significant cyber threat. In certain sectors like finance, digital infrastructure and ICT services, you must warn potentially affected customers and tell them what they can do. The goal is to protect the supply chain.

NIS2 in one breath: check your scope, register, get management on board, and know your clock: 24 hours, 72 hours, one month.
The Answer to NIS2: ISO 27001
NIS2 is demanding. The good news: you don't have to invent a system that delivers it. It already exists, and it's called ISO 27001.
Management duties (Art. 20) → Clause 5, Leadership
Risk management (Art. 21) → Clause 6 and the Annex A controls
Reporting (Art. 23) → incident management, A.5.24 to A.5.28
Add the NIS2 specifics on top, such as registration and the 24h/72h/1-month clock, and you have one system that turns legal duties into daily practice.
Ready to learn ISO 27001? My ISO 27001 Lead Implementer course takes you through all 12 steps, templates included. It's now part of GRCLab+.

