Manufacturing
Utilities
Policies & Standards
NIS-2 and its implementation
Resilience is now a top priority
(c) Getty Images

By Marlitt Julika Stolz, Head of Management Systems & Audit at secunet

Since the German NIS-2 Implementation Act came into force, cybersecurity is no longer just best practice for many organisations, but a verifiable obligation: the circle of regulated institutions is growing significantly, requirements for risk management, reporting channels and supply chains are becoming more specific – and violations can have serious consequences. So where should you start? A tried-and-tested four-step approach offers guidance – from impact and gap analysis to action planning and proof of effectiveness. With the NIS-2 check-up and subsequent implementation support, secunet helps affected companies translate compliance into robust resilience.

Cyber attacks are no longer an exceptional occurrence for companies today; they are part of day-to-day operations. Since 6 December 2025, Germany has therefore had the ‘Act Implementing the NIS-2 Directive and Regulating Key Aspects of Information Security Management in the Federal Administration’ – or NIS-2 Implementation Act for short. The amendment sets a new benchmark for cyber security: can companies identify risks, report incidents and demonstrate their ability to act?

For many organisations, this is a turning point: the regulated circle is becoming significantly larger, expectations of risk management are rising and, above all, implementation must be verifiable and auditable. From an information security perspective, this is fundamentally good news. After all, the cyber security situation is tense, and vulnerabilities arise quickly and often where processes appear to be ‘actually running’ at first glance. This is precisely why NIS-2 does not view security as a toolbox, but as an interlocking system: responsibility, risk management, reporting channels, supply chains, evidence. Resilience arises where all these elements work together. Companies are required to clarify how they are affected, fulfil upcoming obligations and thus measurably strengthen their security.

The clock is ticking

Reality shows that many companies are still in the early stages. According to a study conducted by secunet in 2024 on the implementation status of the NIS-2 Directive in Germany, only two per cent of companies had completed their NIS-2 project at the time of the survey. More than a quarter of companies (28 per cent) reported that their NIS-2 implementation project had been delayed, while a good third (34 per cent) had not even addressed the issue yet. At the same time, the clock is ticking. There are no transition periods – with fines of up to ten million euros or two per cent of global annual turnover.

In discussions with IT managers, the secunet team is currently encountering two main reactions:

  • ‘We're already doing a lot – how are we supposed to implement all this?’
  • ‘We are affected – but where do we start without getting bogged down?’

Both questions are justified. And both can be answered with a structured approach that has already proven itself in many projects.

What NIS-2 specifically changes in Germany

The NIS-2 Implementation Act repeals the previous NIS Directive and further develops the content of the BSI Act (BSIG) by significantly expanding its scope. In addition to traditional KRITIS operators and other companies of public interest, many other organisations are now subject to the provisions of the amendment. In total, around 30,000 organisations will be supervised by the BSI in future – significantly more than before.

MARLITT JULIKA STOLZ, HEAD OF MANAGEMENT SYSTEMS & AUDIT AT SECUNET. PHOTO (C) SECUNET

The first challenge here is that companies must now check for themselves whether they are affected, and they are legally obliged to register as NIS-2 companies. This also entails, among other things, the obligation to report significant and substantial security incidents to the BSI, implement risk management measures and document them. The impact analysis alone can quickly become complex, especially for corporations, shareholdings and international structures.

When waiting becomes a risk

NIS-2 no longer applies only to particularly large companies or critical infrastructures. New sector classifications and thresholds for the number of employees, turnover or balance sheet total are now decisive. The sectors most affected are generally energy, transport, finance, healthcare, water/wastewater, digital infrastructure, ICT management, logistics, research, manufacturing (e.g. mechanical engineering), food, postal and courier services – along with a few special regulations. If it cannot be clearly ruled out that your own company is affected, it is worth conducting a structured review and documenting your decision.

Experience shows that the full implementation of these extensive measures requires time and forward planning. It is therefore crucial to be able to present a concrete implementation plan at an early stage. The BSI can demand proof of compliance with the requirements after three years at the latest. However, companies should not use this period as a delay, but as a time for preparation: fines can be imposed even before then.

Photo (c) Getty Images

Four steps to bring order to the NIS-2 chaos

NIS-2 cannot simply be ticked off. But it can be mastered step by step. In practice, a consistent and well-structured approach has proven successful – with clear areas of action spread across four phases:

  • Phase 1: Impact analysis

Companies with complex structures in particular face challenges in clarifying the way in which they are affected. Corporations with subsidiaries abroad must comply with the respective national implementation standards. They should therefore first carry out sector and threshold checks that take into account the respective ownership structures. Verifiable documentation of the results (even if you are ‘not affected’) is recommended.

  • Phase 2: Gap analysis of NIS-2 requirements

In accordance with proven clustering, secunet reviews the individual requirements for affected companies in the context of evidence, process inspections or interviews using a proven questionnaire based on over 20 years of cybersecurity experience. Based on the current situation, the areas for action are prioritised according to risk and feasibility, and proposals for further action are formulated. Optionally, a link to ISO/IEC 27001 or IT baseline protection (IT-Grundschutz) can also be established.

  • Phase 3: Creation of an action plan including tracking

Depending on the initial situation, the gaps identified vary significantly from company to company. Based on the GAP analysis, secunet therefore draws up a concrete action plan that includes responsibilities and milestones and organises them thematically. Quick wins are identified in the process. This process is accompanied by structured action tracking that is audit- and report-ready.

  • Phase 4: Implementation and proof of effectiveness

Finally, the implementation phase involves continuously monitoring progress and measuring its effectiveness. This allows any necessary action to be identified at an early stage and targeted corrective measures to be initiated.

secunet supports affected companies in analysing and implementing the respective steps as part of a NIS-2 check-up: This provides structured clarity about the extent of the impact, the degree of maturity and the most sensible implementation sequence – and can be converted into consulting and implementation support if required.

Twelve areas of action as a clear compass

In many cases, the implementation of the NIS-2 amendment does not fail due to a lack of will, but rather due to a lack of overview. That is why secunet structures the requirements into twelve areas of action – as a clear roadmap from risk management to reporting obligations to supplier management.

The latter in particular can often be a pain point, as processes, systems and controls can be checked transparently internally. This is much more difficult with partners – but it is essential for holistic resilience.

  1. Information security risk management
  2. Management responsibilities
  3. Registration and reporting obligations
  4. Information security in human resources
  5. Training and awareness
  6. Information security in supplier management
  7. Continuous improvement process
  8. Emergency and crisis management
  9. Access and access control
  10. Communication encryption and cryptography
  11. (Security) incident handling
  12. Information security in the life cycle of systems, components and processes

 

Security does not end with IT

Implementing NIS-2 means, among other things, establishing clear responsibilities, carrying out effective controls and providing reliable evidence.

Cybersecurity solutions are indispensable in this context. However, solutions such as the secure edge gateway platform secunet edge, public key infrastructures (PKI) as well as SINA and SINA Cloud only realise their full added value when they are embedded in a functioning information security management system (ISMS). In addition, penetration tests (pentests) should help to identify risks at an early stage and continuously improve the security strategy.

NIS-2 can also be an opportunity

NIS-2 is often perceived as regulatory pressure. However, implementation shows that those who approach the issue correctly gain more than ‘just’ compliance – namely, genuine, controllable resilience. Ultimately, the crucial question is not whether every requirement is formally met. Rather, it is: Can companies detect attacks early, respond in a controlled manner, maintain operations – and provide verifiable evidence of all this?

If the answer is ‘yes’, then NIS-2 is not only fulfilled, but also put to good use.

Contact request

Contact:

Marlitt Julika Stolz
Head of Management Systems & Audit
secunet Security Networks AG

Do you have any questions or comments about this article? Then contact us using the contact form on the right.

Seite 1
Submit
* Required fields
Logo

secuview is the online magazine of secunet, Germany's leading cybersecurity company. Here you will find news, trends, viewpoints and background information from the world of cybersecurity for public authorities and companies. Whether cloud, IIoT, home office, eGovernment or autonomous driving - there can be no digitisation without security.

 

In addition to the online magazine, secuview is published twice a year as a journal, which you can subscribe to free of charge in printed form or download as a PDF.

secuview is the online magazine of secunet, Germany's leading cybersecurity company. Whether cloud, IIoT, home office, eGovernment or autonomous driving - there can be no digitisation without security.

© 2026 secunet Security Networks AG