NIS2 Is Here — What German Mid-sized Companies Need to Know Now
The EU NIS2 Directive affects more companies than most people think. Here is a pragmatic checklist of what you should have completed by Q4.
The NIS2 Directive has been transposed into German law since October 2024. Many business owners from the German Mittelstand (mid-sized companies) ask us: "Does this even affect us?" The answer: probably yes.
Who is affected?
Essential and important entities in 18 sectors — including energy, healthcare, finance, food production, chemicals, and IT service providers. Rule of thumb: if you have 50+ employees or €10 million in annual revenue and operate in one of these sectors, you are probably affected.
What has to be done, and by when?
The most important obligations:
- •Reporting obligation for security incidents within 24/72 hours
- •Risk management with documented evidence
- •Supply chain security assessment
- •Management responsibility explicitly assigned
- •Employee training conducted regularly
Violations can result in fines of up to €10 million or 2% of annual revenue (whichever is higher).
A pragmatic checklist
If you have not started yet, here is what you can achieve in 4 weeks:
- •Inventory: Which systems process critical data?
- •Risk analysis: Where are the most likely attack vectors?
- •Incident response plan: Who does what when something happens?
- •Backup strategy: 3-2-1 rule — does recovery really work?
- •Training: Phishing test + training for all employees
- •Documentation: Put everything in writing — the evidence is what counts
How we help
We offer a NIS2 audit as a fixed-price package — within 2 weeks, we deliver a clear status analysis, a gap analysis, and a prioritized action plan. Including all templates for incident reports, risk registers, and training materials.
If you have any questions, just get in touch.