Implementing NIS2 in Your Existing ISMS
25.03.2025 | Author: Torsten Enk
Dear readers, the NIS2 Directive is a European regulation designed to improve cybersecurity, and member states must transpose it into national law. In Germany, this is expected to happen through the NIS2 Implementation Act (NIS2UmsG). The legislative process has not yet been completed, but infringement proceedings have already been opened against Germany because the deadline for transposing the directive into national law has passed. It is therefore safe to assume that the federal government will complete the legislative process quickly. The NIS2UmsG is expected to be passed shortly after the Bundestag's summer recess, making it realistic for the law to take effect in 2025. Companies should therefore start preparing for the new requirements now to avoid compliance gaps and potential sanctions. With the implementation of NIS2, the requirements for IT security and compliance increase considerably. Companies need to engage more closely with the legal requirements to avoid penalties and risks. To make the transition easier for you, we explain in detail what is changing, which companies are affected and what measures are required.
Which companies are affected?
The NIS2 Directive significantly expands the range of companies subject to its obligations. In addition to operators of critical infrastructure, it now also covers a wide range of other sectors, including: – Energy and water supply (power grid operators, gas suppliers, drinking water supply) – Healthcare (hospitals, pharmaceutical companies, laboratories) – Digital infrastructure (data centers, cloud services, DNS providers) – Public administration and municipalities – Transport and logistics (airports, rail operators, freight forwarders) – Manufacturers of ICT products and services – Finance and insurance – Food industry and chemical industry
Criteria for being in scope
A company falls under the NIS2 Directive if it meets certain criteria. The decisive factors are: – Company size (e.g. more than 50 employees or more than EUR 10 million in annual revenue) – The company's importance for public services or the economy – The extent to which other companies or sectors depend on its services
Why can small companies be affected too?
In principle, NIS2 applies to companies with at least 50 employees and an annual revenue or balance sheet total of more than EUR 10 million, with the following exceptions: – Size-independent obligation: certain companies, such as providers of DNS services, TLD name registries and operators of public electronic communications networks or services, are subject to the NIS2 requirements regardless of their size. – Indirect impact via the supply chain: small and medium-sized enterprises (SMEs) can be indirectly affected if they provide services or products to companies that fall directly under the NIS2 Directive. To ensure the security of the entire supply chain, large customers may require comparable security measures from their suppliers and partners.
Management liability and enforcement powers of supervisory authorities
With the implementation of the NIS2 Directive, the responsibilities of management and the powers of supervisory authorities are expanded considerably. Companies that fail to meet the requirements risk not only heavy fines but also direct supervisory measures that can severely disrupt their operations.
Personal liability of management
A key difference from previous regulations is that management will in future be personally responsible for compliance with cybersecurity requirements.
- Management must be able to demonstrate that the company takes the necessary security measures.
- The obligation to train and raise awareness among executive and management board members in the area of cybersecurity is explicitly set out in the NIS2 Directive.
- In cases of negligence or failure to implement essential security precautions, management faces personal liability claims.
Sanctions and fines
The NIS2 Directive establishes uniform sanction mechanisms across Europe, which are enforced by the national supervisory authorities.
Fines for violations can be substantial:
- Up to EUR 10 million or 2% of global annual revenue for “essential entities”
- Up to EUR 7 million or 1.4% of global annual revenue for “important entities”
The penalty depends on the severity of the violation, the degree of negligence and the countermeasures taken.
Supervisory measures and intervention rights of the authorities
The competent supervisory authorities have far-reaching powers to review and enforce compliance with the regulations. Among other things, they can:
- Conduct investigations and security inspections at companies
- Order mandatory audits and require evidence of the company's security posture
- Prescribe preventive measures to minimize risk
- Issue immediate measures to avert danger if an acute security incident is imminent
- Order the appointment of an external security officer
- Temporarily suspend certain IT systems or services in the event of a serious violation
- Issue direct instructions to management to close specific security gaps
Consequences of non-compliance
If a company fails to take adequate measures to improve its cybersecurity despite being instructed to do so by the authorities, it faces stricter sanctions:
Publication of violations (“naming and shaming”) on government websites Restriction or revocation of the business license for critical digital services Liability risks for managing directors and board members, especially in the case of repeated or grossly negligent violations
Our approach: workshop and ISMS implementation
We offer a NIS2 workshop in which we clarify the following points:
- Initial applicability assessment
- Defining the extended scope of the ISMS
- Identifying the critical business processes
- Checking that all required resources have been fully identified (staff, applications, infrastructure, service providers, etc.)
- Mapping the NIS2 requirements to the controls in place (gap analysis)
- Assessing the maturity and implementation status of the ISMS based on the relevant controls, with a focus on NIS2
- Evaluating the documentation with a focus on NIS2 requirements
Based on the results, we identify initial gaps and plan the measures required for implementation. If necessary, we carry out detailed analyses afterward.
The workshop lays the foundation for a follow-up project that builds seamlessly on the results.
Recommendation: prepare now and minimize risks
Companies should prepare early for the stricter monitoring and enforcement mechanisms. A structured information security management system (ISMS) and clear cybersecurity governance are essential to avoid both fines and regulatory intervention.
If you need support, we will be happy to help you adapt your ISMS accordingly and implement NIS2 successfully. 📩 Contact us for personalized advice!