
Insights · IT security
NIS 2 Directive: how should companies implement the cyber security requirements?
- Published
- 10 June 2024
- Reading time
- 5 min read
Author: Dr Markus Hülper, lawyer
Increasing connectivity and digitalisation bring not only numerous benefits but also considerable risks. Cyber attacks and IT security incidents can have serious consequences for companies and society. To counter this, the EU’s NIS 2 Directive imposes stricter cyber security requirements on companies. The directive obliges a large number of companies in various sectors to take comprehensive security measures.
Germany has already taken measures to transpose the NIS 2 Directive into national law. It is pursuing a comprehensive approach encompassing legal, technical and organisational measures. (Read more in the article NIS 2 Directive: implementation and current status in Germany)
Who is subject to the obligations?
The NIS 2 Directive applies to companies and organisations operating in certain critical sectors. The 18 sectors affected include:
Energy
Healthcare
Manufacturing
Finance
Transport
Digital infrastructure and digital services
Public administrations
Food production and processing
These sectors were selected because they are considered particularly critical to the functioning of society and the economy. A failure or disruption in these sectors would have far-reaching consequences.
Around 30,000 organisations in Germany are affected by the NIS 2 Directive. In principle, the directive applies to companies with more than 50 employees or annual revenue of more than EUR 10 million. Smaller companies may also be affected if they are particularly important to a sector. This means that a broad range of organisations must take measures to meet the directive’s requirements.
A word of caution: companies and public bodies must determine for themselves whether they fall within the scope and proactively implement the required cyber security measures.
What requirements apply?
The NIS 2 Directive imposes a number of technical, operational and organisational requirements on affected companies, including:
Registration
Once organisations have identified “critical” areas, they must register themselves as an “obligated organisation” with the Federal Office for Information Security (BSI) after the implementing act enters into force. Essential and important entities must register within three months of its entry into force.
Contact point
Companies must designate and operate a contact point for their critical areas and provide evidence of it to the BSI. Organisations must be reachable through the contact point at all times and fulfil their reporting obligation in the event of significant IT disruptions.
Reporting obligations
Companies are required to report significant IT security incidents to the Federal Office for Information Security (BSI). The reporting deadlines are tight: an initial report must be submitted within 24 hours of becoming aware of the incident, a full report with an initial assessment within 72 hours, and a final report with a detailed description within one month. These strict requirements are intended to ensure that security incidents are identified and reported quickly so that effective countermeasures can be initiated.
Risk management
Companies must operate comprehensive risk management that also includes supply chain security. This encompasses documented risk analyses, processes for the ongoing evaluation of measures taken, and business continuity and emergency management. Systematic risk management helps identify potential threats early and take suitable measures to minimise risks.
Training
Regular cyber security training for management and employees is mandatory. This training is intended to raise awareness of secure behaviour when using IT systems and ensure that all employees understand the importance of cyber security and act accordingly. E-learning tools can help deliver training measures regularly and comprehensively.
Technical and organisational measures
NIS 2 obliges companies to take technical and organisational measures to improve cyber security. These include using state-of-the-art security technology, implementing security policies and procedures, and regularly reviewing effectiveness and testing security measures. The measures are intended to ensure that IT infrastructure is robust and resilient to attacks.
What must companies consider?
Different parts of a company are involved in implementing the NIS 2 Directive (IT, compliance, data protection, HR, quality management and others). Holistic risk management involving all stakeholders is therefore essential. Companies should pay particular attention to the following points:
Compliance with reporting obligations
Meeting the strict reporting deadlines is crucial to avoiding penalties. Companies should ensure that suitable contact points, reporting channels and responsibilities are in place. Clear assignment of responsibilities and efficient reporting processes are essential.
Integrated risk management
The NIS 2 requirements should be integrated into the company’s general risk management. A holistic approach facilitates implementation and ensures effective risk control. Integration into existing risk management processes allows synergies to be used and duplication avoided.
Training measures
Regular training is essential to strengthen cyber security awareness and ensure compliance with security policies. E-learning tools can provide an efficient way to deliver training flexibly and in line with needs.
Documentation and evidence
Companies must be able to document and demonstrate compliance with security requirements in detail. This includes regular audits and the preparation of comprehensive reports. Complete documentation is important not only for compliance reasons, but also as a basis for continuous improvements in IT security.
Act now to avoid penalties
Implementing the NIS 2 Directive presents companies with considerable challenges, but also offers an opportunity to strengthen their own cyber security and protect themselves more effectively against threats. Companies should take the NIS 2 Directive’s requirements seriously and implement the necessary measures in good time.
We will be glad to support you in implementing the NIS 2 Directive. We offer comprehensive advice and practical assistance with implementing the required security measures, meeting reporting obligations and training your employees. Contact us to find out how we can help you meet the requirements of the NIS 2 Directive successfully and avoid penalties.
Do you have questions about this topic?
We can assess what the development means for your organisation and advise you directly.


