
By Marlitt Julika Stolz, Head of Management Systems & Audit at secunet
Cyber attacks are no longer an exceptional occurrence for companies today; they are part of day-to-day operations. Since 6 December 2025, Germany has therefore had the ‘Act Implementing the NIS-2 Directive and Regulating Key Aspects of Information Security Management in the Federal Administration’ – or NIS-2 Implementation Act for short. The amendment sets a new benchmark for cyber security: can companies identify risks, report incidents and demonstrate their ability to act?
For many organisations, this is a turning point: the regulated circle is becoming significantly larger, expectations of risk management are rising and, above all, implementation must be verifiable and auditable. From an information security perspective, this is fundamentally good news. After all, the cyber security situation is tense, and vulnerabilities arise quickly and often where processes appear to be ‘actually running’ at first glance. This is precisely why NIS-2 does not view security as a toolbox, but as an interlocking system: responsibility, risk management, reporting channels, supply chains, evidence. Resilience arises where all these elements work together. Companies are required to clarify how they are affected, fulfil upcoming obligations and thus measurably strengthen their security.
The clock is ticking
Reality shows that many companies are still in the early stages. According to a study conducted by secunet in 2024 on the implementation status of the NIS-2 Directive in Germany, only two per cent of companies had completed their NIS-2 project at the time of the survey. More than a quarter of companies (28 per cent) reported that their NIS-2 implementation project had been delayed, while a good third (34 per cent) had not even addressed the issue yet. At the same time, the clock is ticking. There are no transition periods – with fines of up to ten million euros or two per cent of global annual turnover.
In discussions with IT managers, the secunet team is currently encountering two main reactions:
- ‘We're already doing a lot – how are we supposed to implement all this?’
- ‘We are affected – but where do we start without getting bogged down?’
Both questions are justified. And both can be answered with a structured approach that has already proven itself in many projects.
What NIS-2 specifically changes in Germany
The NIS-2 Implementation Act repeals the previous NIS Directive and further develops the content of the BSI Act (BSIG) by significantly expanding its scope. In addition to traditional KRITIS operators and other companies of public interest, many other organisations are now subject to the provisions of the amendment. In total, around 30,000 organisations will be supervised by the BSI in future – significantly more than before.

MARLITT JULIKA STOLZ, HEAD OF MANAGEMENT SYSTEMS & AUDIT AT SECUNET. PHOTO (C) SECUNET
The first challenge here is that companies must now check for themselves whether they are affected, and they are legally obliged to register as NIS-2 companies. This also entails, among other things, the obligation to report significant and substantial security incidents to the BSI, implement risk management measures and document them. The impact analysis alone can quickly become complex, especially for corporations, shareholdings and international structures.
When waiting becomes a risk
NIS-2 no longer applies only to particularly large companies or critical infrastructures. New sector classifications and thresholds for the number of employees, turnover or balance sheet total are now decisive. The sectors most affected are generally energy, transport, finance, healthcare, water/wastewater, digital infrastructure, ICT management, logistics, research, manufacturing (e.g. mechanical engineering), food, postal and courier services – along with a few special regulations. If it cannot be clearly ruled out that your own company is affected, it is worth conducting a structured review and documenting your decision.
Experience shows that the full implementation of these extensive measures requires time and forward planning. It is therefore crucial to be able to present a concrete implementation plan at an early stage. The BSI can demand proof of compliance with the requirements after three years at the latest. However, companies should not use this period as a delay, but as a time for preparation: fines can be imposed even before then.

Four steps to bring order to the NIS-2 chaos
NIS-2 cannot simply be ticked off. But it can be mastered step by step. In practice, a consistent and well-structured approach has proven successful – with clear areas of action spread across four phases:
- Phase 1: Impact analysis
Companies with complex structures in particular face challenges in clarifying the way in which they are affected. Corporations with subsidiaries abroad must comply with the respective national implementation standards. They should therefore first carry out sector and threshold checks that take into account the respective ownership structures. Verifiable documentation of the results (even if you are ‘not affected’) is recommended.
- Phase 2: Gap analysis of NIS-2 requirements
In accordance with proven clustering, secunet reviews the individual requirements for affected companies in the context of evidence, process inspections or interviews using a proven questionnaire based on over 20 years of cybersecurity experience. Based on the current situation, the areas for action are prioritised according to risk and feasibility, and proposals for further action are formulated. Optionally, a link to ISO/IEC 27001 or IT baseline protection (IT-Grundschutz) can also be established.
- Phase 3: Creation of an action plan including tracking
Depending on the initial situation, the gaps identified vary significantly from company to company. Based on the GAP analysis, secunet therefore draws up a concrete action plan that includes responsibilities and milestones and organises them thematically. Quick wins are identified in the process. This process is accompanied by structured action tracking that is audit- and report-ready.
- Phase 4: Implementation and proof of effectiveness
Finally, the implementation phase involves continuously monitoring progress and measuring its effectiveness. This allows any necessary action to be identified at an early stage and targeted corrective measures to be initiated.
secunet supports affected companies in analysing and implementing the respective steps as part of a NIS-2 check-up: This provides structured clarity about the extent of the impact, the degree of maturity and the most sensible implementation sequence – and can be converted into consulting and implementation support if required.
Twelve areas of action as a clear compass
In many cases, the implementation of the NIS-2 amendment does not fail due to a lack of will, but rather due to a lack of overview. That is why secunet structures the requirements into twelve areas of action – as a clear roadmap from risk management to reporting obligations to supplier management.
The latter in particular can often be a pain point, as processes, systems and controls can be checked transparently internally. This is much more difficult with partners – but it is essential for holistic resilience.
- Information security risk management
- Management responsibilities
- Registration and reporting obligations
- Information security in human resources
- Training and awareness
- Information security in supplier management
- Continuous improvement process
- Emergency and crisis management
- Access and access control
- Communication encryption and cryptography
- (Security) incident handling
- Information security in the life cycle of systems, components and processes
Security does not end with IT
Implementing NIS-2 means, among other things, establishing clear responsibilities, carrying out effective controls and providing reliable evidence.
Cybersecurity solutions are indispensable in this context. However, solutions such as the secure edge gateway platform secunet edge, public key infrastructures (PKI) as well as SINA and SINA Cloud only realise their full added value when they are embedded in a functioning information security management system (ISMS). In addition, penetration tests (pentests) should help to identify risks at an early stage and continuously improve the security strategy.
NIS-2 can also be an opportunity
NIS-2 is often perceived as regulatory pressure. However, implementation shows that those who approach the issue correctly gain more than ‘just’ compliance – namely, genuine, controllable resilience. Ultimately, the crucial question is not whether every requirement is formally met. Rather, it is: Can companies detect attacks early, respond in a controlled manner, maintain operations – and provide verifiable evidence of all this?
If the answer is ‘yes’, then NIS-2 is not only fulfilled, but also put to good use.
Contact:
Marlitt Julika Stolz
Head of Management Systems & Audit
secunet Security Networks AG
Do you have any questions or comments about this article? Then contact us using the contact form on the right.
secuview is the online magazine of secunet, Germany's leading cybersecurity company. Whether cloud, IIoT, home office, eGovernment or autonomous driving - there can be no digitisation without security.