NIS2 Passed: What the New Law Means for SMEs
11.01.2026 | Author: Torsten Enk
With the passage of the NIS2 Implementation Act (NIS2-Umsetzungsgesetz) in November, the German Bundestag has transposed the European Directive (EU) 2022/2555 into binding German law. This significantly expands and tightens the previous NIS regime. For the first time, numerous small and medium-sized enterprises (SMEs) fall directly within the scope of statutory cybersecurity requirements.
NIS2 marks a clear paradigm shift: information security is no longer purely an IT issue, but a mandatory organizational and business responsibility. Executive management is explicitly held accountable for managing risks, deciding on measures and monitoring their effectiveness.
- Passage by the Bundestag – what it means for SMEs
With the Bundestag's decision, NIS2 becomes binding for companies that:
- have at least 50 employees or annual revenue of EUR 10 million, and
- operate in one of the sectors defined in the directive (including IT services, digital services, manufacturing with a critical supply chain function, transportation, energy-related services and healthcare).
Particularly relevant for SMEs: whether they are affected no longer depends only on their own criticality, but increasingly on their role as a service provider or supplier. Many SMEs will be indirectly required to implement NIS2 requirements through customer demands, contractual clauses and audits.
- What is actually new compared to the previous draft bill?
During the parliamentary process, several substantive clarifications were made that have a significant impact on SMEs in particular.
Clearer distinction between “important” and “essential” entities
Lawmakers have sharpened the criteria for when companies qualify as “important entities.” Many SMEs fall into this category. The key point: “important entities” are also subject to extensive security and reporting obligations that differ only slightly from those of “essential entities.”
Explicit accountability of executive management
New and especially relevant for SMEs is the clear codification of management accountability. Executive management must approve security measures, monitor their implementation and receive regular reports. Cybersecurity thus becomes an organizational leadership task and can no longer be informally delegated to IT.
Higher requirements for demonstrable compliance
The Bundestag has made clear that measures must not only be implemented, but also documented in a traceable way. In the event of security incidents or audits by the BSI (Germany's Federal Office for Information Security), what counts is not whether individual measures exist in practice, but how they are structurally embedded, assigned and documented.
More specific supply chain requirements
What's new is the clear expectation that SMEs, too, must systematically assess and manage risks arising from IT service providers, cloud services and external operators. Simply passing on responsibility by contract is not sufficient.
- NIS2 focus areas
The core technical requirements of NIS2 derive mainly from Article 20 (governance) and Article 21 (cybersecurity risk-management measures) of the directive.
Information security risk management (Art. 21(1))
Companies must establish systematic risk management for their network and information systems. This requires identifying relevant IT assets, assessing risks to availability, integrity and confidentiality, and deriving appropriate measures.
Business impact analysis and resilience (Art. 21(1)(b) and (c))
NIS2 requires companies to assess the impact of security incidents on business operations, identify critical processes and define recovery objectives.
Technical and organizational safeguards (Art. 21(2))
These include access controls, malware protection, patch management, backup and recovery procedures, and network security – always risk-based and proportionate.
Supply chain and service provider management (Art. 21(2)(e))
Cyber risks from IT service providers and cloud services must be systematically assessed and addressed in contracts.
Governance and management accountability (Art. 20)
Executive management is responsible for approval, oversight and training in the area of cybersecurity.
Incident handling and reporting obligations including deadlines (Art. 21(1)(d) and Art. 23 NIS2)
One of the key innovations of NIS2 is clearly defined, tiered reporting obligations with fixed deadlines. Companies must be able not only to detect and handle security incidents, but also to report them on time.
Security incidents must be reported if they:
- cause or are capable of causing severe operational disruption,
- result in financial losses,
- significantly impair the availability, integrity or confidentiality of network and information systems.
NIS2 sets out the following mandatory reporting deadlines:
- Early warning within 24 hours Initial assessment of whether a significant security incident has occurred or is imminent.
- Incident notification within 72 hours More detailed information on the nature of the incident, its initial impact and, where applicable, the measures taken.
- Final report no later than one month after the incident Full analysis including root causes, impact, countermeasures taken and lessons learned.
- What should SMEs do now?
For SMEs, a structured and pragmatic approach is key. The first step is an applicability assessment to determine your own role and need for action. Building on this, we recommend taking stock of existing security measures.
The next step is a risk-based analysis that links IT assets, business processes and potential impacts. On this basis, measures can be prioritized and implemented in a targeted way.
A key success factor is clear, lean documentation: policies and procedure descriptions should be short, understandable and auditable – not extensive, but effective.
- Is an ISMS a prerequisite for NIS2?
Formally, NIS2 does not require certification. In substance, however, it is clear that the requirements can hardly be met efficiently without a structured information security management system (ISMS).
NIS2 explicitly refers to international standards, in particular ISO/IEC 27001. This standard is an excellent methodological foundation for:
- systematically covering NIS2 requirements,
- assessing the relevance of individual controls,
- implementing measures tailored to your company.
We recommend using ISO 27001 as a reference framework, selecting the relevant controls in light of NIS2 requirements, and documenting them concisely, precisely and traceably in policies and procedure descriptions.
For efficient implementation, we recommend using a GRC tool to centrally manage and track risks, assets, processes, business impact analyses, measures and deviations.
blu – your partner for NIS2 implementation in SMEs
blu Guard GmbH specifically supports SMEs in implementing NIS2 in a practical and proportionate way:
- Applicability assessment and classification
- NIS2 gap analysis at a fixed price
- Documentation of existing procedures and controls
- Implementation consulting based on ISO/IEC 27001
- CISO and ISO as a service – including for SMEs without in-house resources
Our approach combines regulatory certainty with economically viable implementation.
Conclusion
NIS2 is not an end in itself, but a binding framework for increasing digital resilience. For SMEs, the key to success lies in a structured, risk-based implementation with clear accountability and traceable documentation. Acting now reduces regulatory risk and strengthens your competitiveness for the long term.
Not sure whether your company is affected by NIS2 or how much action you actually need to take? blu Guard GmbH supports you with a clearly structured applicability assessment and an NIS2 gap analysis at a fixed price – pragmatic, easy to understand and tailored specifically to SMEs.