“Does NIS2 apply to us?” — lately I hear this question from almost every mid-sized company in my region. Understandable: the directive covers far more businesses than its predecessor, and the uncertainty about what exactly applies is huge. The good news: whether you’re probably in scope can be narrowed down with three questions. That’s what this article is about.
What NIS2 is — and where Germany stands now
The NIS2 Directive ((EU) 2022/2555) is the successor to the first NIS Directive and requires member states to make cybersecurity mandatory for essential and important entities. At its core: organised risk management, reporting of significant incidents, and management responsibility.
Important current status: The German implementing law (NIS2UmsuCG, BGBl I 2025 No. 301) has been in force since December 6, 2025 — and the statutory registration deadline has already passed (March 2026). In-scope entities must register via an ELSTER organisation certificate („Mein Unternehmenskonto“) and in the BSI portal (§ 33(6) BSIG). If you are in scope and have not registered yet: register immediately — the BSI is explicitly calling for it. Alongside registration, the obligations apply: risk management, reporting deadlines, management training.
The BSI also offers an official NIS-2 scope-of-application check — sensible as a first rough assessment. The three questions below show the logic behind that assessment.
The three questions that decide
1. Sector
The directive distinguishes two groups of sectors:
- Sectors of high criticality: energy, transport, banking and finance, health, drinking and waste water, digital infrastructure including ICT service management for businesses, public administration, space.
- Other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing (e.g. machinery, vehicles, electronics), digital providers such as marketplaces and search engines, research.
If you’re not active in any of these sectors, a direct obligation is unlikely — but keep reading, because there are exceptions.
2. Size
The sector alone isn’t enough; company size matters:
- Large companies (typically 250+ employees or more than €50 million annual turnover) in high-criticality sectors are usually essential entities — with the most extensive obligations.
- Medium-sized companies (typically 50+ employees or more than €10 million annual turnover) in high-criticality sectors, plus medium and large companies in other critical sectors, are usually important entities.
3. Role
And then there are service providers that can be in scope regardless of their sector: managed service providers (running IT operations for clients), managed security service providers, cloud hosting and data centres, as well as DNS and domain services. IT providers who see themselves as “just a small shop” are more often in focus than they think.
Even without an obligation: the supply chain comes for you
This is often overlooked: even if you don’t fall directly under NIS2, you will feel the directive through your customers. Companies in scope must secure their supply chain and are increasingly passing security requirements on to their partners and suppliers. If you don’t have the basics under control (risk management, MFA, tested backups, an incident response plan), you’ll notice it at the latest when the next big customer sends their security questionnaire.
What you can do concretely
- Clarify applicability. Sector, size, role — that narrows the probability down well. For exactly these questions I built a NIS2 self-assessment that gives you a first assessment. Runs entirely in your browser, takes a few minutes.
- Assess your current state. If NIS2 probably applies: where do you stand on risk management, reporting, baseline measures?
- Prioritise the gaps. Not everything at once — first the measures with the biggest risk impact.
- Execute and document the roadmap. Authorities and customers don’t ask “What did you think?”, they ask “What did you implement?”.
If you want clarity after the self-assessment: that’s exactly what my NIS2 Readiness Check is for — applicability analysis, gap analysis, and a prioritised action plan. Before that, you can meet me in the free 30-minute intro call.
The self-assessment is an orientation based on the EU directive and does not constitute legal advice — the binding German implementation may regulate details differently.