Skip to main content
NIS 2 Directive: implementation and current status in Germany
Back to all Insights

Insights · IT security

NIS 2 Directive: implementation and current status in Germany

Published
7 June 2024
Reading time
5 min read

Share this article

Author: Dr Markus Hülper, lawyer

In the digital age, network and information systems are indispensable to the functioning of our society and economy. To protect these systems more effectively and strengthen cyber security, the European Union adopted the NIS 2 Directive. It had to be transposed into national law by 17 October 2024.

What is the NIS 2 Directive?

The NIS 2 Directive (Network and Information Security) is a further development of the first NIS Directive, which entered into force in 2016. It aims to ensure a high common level of cyber security throughout the EU. The NIS 2 Directive extends the scope of the original directive and imposes stricter requirements on the security of network and information systems.

Main objectives of the NIS 2 Directive

Strengthening the level of cyber security in the EU

The NIS 2 Directive aims to raise the overall level of cyber security in all EU Member States so they can respond more effectively to threats.

Clarifying and harmonising the specific requirements:

The NIS 2 Directive defines and extends specific security requirements more clearly in order to ensure uniform implementation across all EU countries.

Expanding the sectors covered by the directive:

More sectors and companies, including small and medium-sized enterprises (SMEs), will now fall within the NIS 2 Directive in order to protect a broader range of network and information systems.

Strengthening resilience to cyber threats:

The directive obliges companies to take measures that improve their ability to defend against and manage cyber attacks.

Protecting critical infrastructure:

The focus is on protecting critical infrastructure to ensure that important social and economic processes continue to function.

Improving response capabilities:

The NIS 2 Directive is intended to improve the ability to respond quickly and effectively to cyber incidents throughout the EU.

Implementation of the NIS 2 Directive in Germany

Germany has already taken measures to transpose the NIS 2 Directive into national law. It is pursuing a comprehensive approach encompassing legal, technical and organisational measures.

Legislative measures

In connection with implementing the NIS 2 Directive, Germany introduced the IT Security Act 2.0, which entered into force in May 2021. Among other things, this act provides for the following measures:

Expanded reporting obligations:

Operators of critical infrastructure (KRITIS) are required to report significant IT security incidents to the Federal Office for Information Security (BSI). This ensures that the BSI is informed of security incidents at an early stage and can initiate appropriate measures.

Stricter security requirements:

Companies must demonstrate that they have appropriate security measures in place to protect their network and information systems. These include regular security reviews and the implementation of safeguards against cyber attacks.

Increased penalties:

High financial penalties may be imposed for breaches of the security requirements. Fines amount to up to EUR 10 million or 2% of worldwide annual revenue, whichever is higher. Managing directors and other governing bodies are also intended to be personally liable for breaches of the expanded cyber security obligations (see section 38 of the draft BSI Act).

Technical and organisational measures

In addition to statutory requirements, Germany also relies on technical and organisational measures to strengthen cyber security. These include:

Promoting cooperation:

Cooperation between government, business and academia is being intensified to develop joint solutions to current cyber threats. Sharing knowledge and resources makes it possible to harness synergies and improve defence against cyber attacks.

Awareness and training:

Training and awareness campaigns teach companies and their employees about the importance of cyber security. This includes both technical training and awareness measures to foster secure behaviour when using IT systems.

Strengthening the BSI:

The Federal Office for Information Security (BSI) is receiving further increases in staffing and funding so that it can perform its duties effectively. This includes providing resources to monitor and analyse cyber threats and supporting companies in implementing security measures.

Current status of the German ministerial draft

The ministerial draft for implementing the NIS 2 Directive in Germany was published in February 2023 and is currently in the consultation phase. The draft provides for the comprehensive integration of the NIS 2 Directive’s requirements into national law and for the extension and adaptation of the existing provisions of the IT Security Act 2.0.

Key provisions of the ministerial draft

In connection with implementing the NIS 2 Directive, Germany introduced the IT Security Act 2.0, which entered into force in May 2021. Among other things, this act provides for the following measures:

Expanded scope:

The draft provides that more sectors and companies, including small and medium-sized enterprises (SMEs), will fall under the provisions of the NIS 2 Directive.

Increased security requirements:

Companies must provide detailed evidence that they meet the prescribed security measures.

Stricter reporting obligations:

Reporting obligations for security incidents are being expanded while the deadlines for reporting incidents are being shortened. Companies must also establish and operate a contact point.

Cooperation and exchange:

The draft promotes cooperation and information sharing among different stakeholders in cyber security so that threats can be addressed more quickly.

Sanction mechanisms:

Penalties for breaches of security requirements are being increased to ensure compliance.

Implementation challenges

Implementing the NIS 2 Directive presents Germany with various challenges:

Complexity of the requirements

The expanded security requirements and reporting obligations require companies to make significant investments in their IT security.

Coordination effort:

Cooperation between different stakeholders must be intensified to ensure effective implementation of the directive.

Scarcity of resources:

Both companies and authorities have a substantial need for qualified personnel to implement the requirements of the NIS 2 Directive.

Conclusion: companies must act now

The NIS 2 Directive is an important step towards strengthening cyber security in the EU. Germany has already made significant progress in implementing the directive, but also faces considerable challenges. A combination of legislative measures, technical support and intensive cooperation can achieve a high level of cyber security and increase resilience to cyber threats.

For companies and organisations, this means preparing thoroughly for the new requirements. Addressing the rules early and implementing suitable security measures are crucial to meeting the statutory requirements and avoiding possible penalties.

We support you in understanding and implementing the requirements of the NIS 2 Directive. With our expertise and experience in IT security, we are at your side as a capable partner to protect your network and information systems effectively.

Enquire now

Do you have questions about this topic?

We can assess what the development means for your organisation and advise you directly.

Contact us

Would you like to stay up to date with the latest developments?

Sign up for our newsletter

From EU directives and AI to the industrialisation of different service areas, the market is undergoing significant change, and so is Clarius.

Our newsletter provides regular updates on developments that may be relevant to you.

Form loading …

Your personal contact

Matthias Schulz

Matthias Schulz

Director Sales

Get in touch by email