Skip to content
Cybersecurity8 min readupdated 10/08/2026

NIS2 in medium-sized companies: Check whether it is affected and start correctly

By Nico Freitag, Geschäftsführer, Cybersecurity und Governance

Dashboard für Sicherheits- und Datenschutzstatus
Header image: Unsplash
THE SHORT ANSWER

The registration and reporting requirements of the NIS2 Implementation Act have been in effect in Germany since December 6, 2025. Companies should first check the sector, size and possible special rules, document the decision and, if affected, set up responsibilities, registration, risk management and reporting channels.

How does the impact assessment begin?

First check whether the activity is assigned to a covered sector and which size criteria apply. Group affiliation and special classification can influence the result. Record sources, assumptions and decisions in writing and have borderline cases examined legally. A technical security analysis does not replace this classification.

What happens if you are affected?

Appoint a responsible manager, register the company via the designated BSI portal and define a reliable reporting channel. At the same time, a risk-based security program is needed with protection requirements, measures, supply chain considerations, exercises and traceable management control.

What order is practical?

Start with critical services, responsibilities and current security posture. First, close gaps that prevent major damage with realistic effort. Reporting process, emergency contacts and recovery should be practiced early on because mere documentation is not enough in the event of an incident.

Next steps

From the answer to implementation

Sources and basis

The central statements in this article were reviewed against the following primary sources.

Frequently asked questions

Is every medium-sized company affected?
No. Sector, activity, size and possible special rules decide. The test should be documented.
Where does registration take place?
The BSI refers to its BSI portal for registration according to NIS2.
Continue reading

More specialist articles about Cybersecurity

Cybersecurity

What would this look like in your organisation?

We apply the specialist assessment to your situation and clarify a concrete next step.

Request a meeting