This document is under active development and has not been finalized.
Skip to content

Regulatory Framework

Legal SourceStatusRelevance
NIS 2 Directive (EU) 2022/2555In force since 16.01.2023EU framework directive
NIS2UmsuCG (Omnibus Act)In force since 06.12.2025German implementation
BSIG (Revised)In force since 06.12.2025Central obligations
Implementing Regulation (EU) 2024/2690In forceDetailed technical requirements
KRITIS Umbrella ActAdopted 29.01.2026Physical resilience

Applicability

The NIS2 Directive distinguishes two categories:

CategoryCriteriaSanctions
Essential entitiesAnnex I sectors, ≥250 employees or ≥€50M turnoverUp to €10M or 2% of global annual turnover
Important entitiesAnnex I/II sectors, ≥50 employees or ≥€10M turnoverUp to €7M or 1.4% of global annual turnover

§30 BSIG – Ten Risk Management Measures

No.MeasureDocumentation
1Risk analysis and information system security conceptsRisk Management
2Incident handlingIncident Management
3Business continuity (BCM, backup, disaster recovery, crisis management)Business Continuity
4Supply chain securitySupply Chain Security
5Security in acquisition, development and maintenanceVulnerability Management
6Effectiveness assessment concepts and proceduresEffectiveness Review
7Basic cyber hygiene practices and trainingTraining & Awareness
8Cryptography concepts and proceduresCryptography
9Personnel security, access control conceptsAccess Control
10Multi-factor authentication, secured communicationAccess Control

Additional Obligations

SectionObligationDocumentation
§32 BSIGReporting obligations for significant security incidentsIncident Management
§33 BSIGRegistration obligation with BSIOrganizationally implemented
§38 BSIGApproval, supervision and training obligations of managementGovernance

CRA Synergy

CRA-compliant processes (vulnerability management, incident response, supply chain) largely fulfil the corresponding NIS2 requirements. Details in the CRA Compliance Documentation.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT