Skip to content
Cybersecurity

NIS2 for Mid-Sized Companies: What to Do Now

NIS2 for mid-sized companies: who is in scope, the ten mandatory areas, reporting deadlines, management liability and what to do in the first 90 days.

Published on 4 min read

Meeting table with a dark blue document tray and a tablet in front of a glass wall with a city view.

The German NIS 2 implementation act (NIS2UmsuCG) has been in force since 6 December 2025. Affected entities must register with the Federal Office for Information Security (BSI) by 6 March 2026. The BSI estimates around 29,500 affected entities, many of them mid-sized companies previously subject to no security regulation.

Who is affected

The EU directive (EU) 2022/2555 and the German act cover companies by sector and size. Affected is anyone in one of the 18 sectors with at least 50 employees or 10 million euros in annual turnover or balance sheet total. Essential and important entities face the same requirements but differ in supervision and fines.

The sectors range from energy, transport, banking, health, digital infrastructure and public administration to postal and courier services, waste management, chemicals, food and manufacturing (including medical devices, electronics, mechanical and vehicle engineering).

Even those below the thresholds are rarely unaffected, because NIS 2 obliges affected entities to manage supply chain security. Customers demand evidence on backup, access control and incident reporting or add security clauses to contracts. The check therefore asks two questions: whether your company falls under the act, and which of your customers do.

The ten mandatory areas

Section 30 of the new BSI Act requires appropriate, proportionate and effective technical and organisational measures in ten areas:

  1. Risk management: documented, regularly updated concepts for risk analysis.
  2. Incident handling: detecting, assessing, containing and reporting incidents.
  3. Backup and business continuity: data backup, recovery planning and crisis management, guided by the 3-2-1 rule and BSI Standard 200-4.
  4. Supply chain security: assessment of and contractual requirements for suppliers.
  5. Vulnerability management: security in acquiring, developing and maintaining systems, including a patch process.
  6. Effectiveness testing: audits, tests and recovery exercises.
  7. Training: cyber hygiene and awareness for all employees, explicitly including management.
  8. Cryptography: encryption of storage media, data transfers and email.
  9. Access control and MFA: authorisation concepts, asset management and multi-factor authentication.
  10. Secure communication: secured voice, video and text communication, also in emergencies.

For most mid-sized companies, areas 3, 5 and 9 have the biggest gaps. A backup attackers cannot delete, a patch process with fixed deadlines and MFA on all remote access also stop real attacks most reliably; when they take effect is described in the article How hacker attacks work.

Reporting deadlines and management responsibility

Significant incidents must be reported to the BSI in stages; deadlines run from when the incident becomes known.

StageDeadlineContent
Early warning24 hoursInitial report, suspected unlawful act, possible cross-border impact
Notification72 hoursUpdate, initial assessment of severity and impact
Interim reportOn request by the BSIStatus update
Final reportOne monthDetailed description, cause, measures taken

Meeting them requires a definition of what counts as a significant incident in your company and a named contact who can trigger the report at the weekend.

Management must approve the measures and monitor their implementation; breaching these duties can make it personally liable for the resulting damage. Fines reach 10 million euros or 2 percent of worldwide annual turnover for essential entities and 7 million euros or 1.4 percent for important entities.

A service provider can implement, but responsibility for approval and oversight stays with management. The topic needs a decision, a budget and one person reporting regularly.

The first 90 days

  1. Weeks 1 to 2: determine applicability. Check sector, headcount, turnover and balance sheet total; record the result in writing, even if it is: not affected.
  2. Weeks 2 to 4: register and assign responsibility. Register with the BSI, name a contact, assign responsibility within management. If the deadline has passed, register immediately and document the reasons.
  3. Weeks 3 to 6: assess the current state. Check the ten areas against reality: inventory, permissions, backup, patch status, remote access, supplier contracts. The scope of a structured security check is described on the page Cybersecurity.
  4. Weeks 6 to 10: quick measures. MFA on all remote access, separated backup, patch deadlines, reporting process with template and contact, management training.
  5. Weeks 10 to 13: document and plan. Risk analysis, action plan with dates and owners, supplier assessment, review cycle.

Key points

  • Affected is anyone in one of the 18 sectors with 50 employees or 10 million euros in turnover; suppliers to affected customers are hit indirectly.
  • Backup, vulnerability management and MFA are the mandatory areas with the biggest gaps and the greatest effect.
  • Management is personally liable for approving and monitoring the measures and needs a decision, a budget and regular reports.

How DEVACON structures security strategy, budget and priorities is described on the page IT consulting and strategy.

Topics NIS2 Compliance Mid-sized companies Risk management Incident reporting

This article comes from the DEVACON blog and was editorially revised for the new website.