NIS 2: What do companies need to do? (Part 3)

This article is part of the series on NIS 2 . Find out what the NIS 2 Directive is and what requirements are imposed on companies .

To advance information security in entities, the EU sets a whole range of requirements with the NIS 2 Directive. As a first step, responsibilities within the company should be established. NIS 2 makes it clear that information security is a matter for executive management and defines explicit requirements for the management of affected entities.

Obligations of Executive Management

Executive management must implement and monitor certain risk measures . Consequently, executive management must be trained in handling information security risks at least every three years. The training must provide the ability to identify and assess risks and their impact and to take appropriate measures.

If they culpably breach their duties, executive management can now even be held personally liable for damages incurred.

Some implementation duties can be delegated. However, the duty to monitor and the training required to monitor effectively always remain with the executive management.

Reporting Obligation

When significant security incidents occur, companies must make a series of reports to the BSI. In certain cases, the BSI may also order that customers or the public be informed about the incidents.

The BSI will further define exactly how a report must be carried out. However, a design similar to the existing reporting obligation for operators of critical infrastructure is likely.

A security incident is considered significant if it leads to, or could lead to, severe operational disruptions, financial losses, or significant damage to third parties. Most entities must define for themselves how this assessment is carried out in detail.

For all entities falling under the first implementing regulation, there are concrete specifications on how significant security incidents must be assessed.

Registration with the BSI

Affected entities are obliged to register with the BSI. In addition to general company and contact data, information on the industry and the EU countries in which the company operates must be submitted. Changes to this information must be reported to the BSI within two weeks.

Implementing Risk Management Measures

A central part of the NIS 2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) is the obligation to implement risk management measures:

"[...] Entities are obliged to take appropriate, proportionate, and effective technical and organizational measures to avoid disruptions in availability, integrity, authenticity, and confidentiality [...] and to keep the impact of security incidents as low as possible."

NIS 2 then describes a series of concrete measures:

  • Fundamental risk and information security concepts
  • Handling of security incidents
  • Business Continuity Management (BCM)
  • Supply chain security and system development
  • Security awareness training
  • Cryptography concepts
  • Personnel security and physical security
  • Assessment of the effectiveness of risk management

However, these are merely minimum requirements – depending on the company's risk situation, further measures may be necessary to fulfill the requirement.

When must affected entities take action?

Immediately upon the expected entry into force of the NIS 2 Directive on October 17, 2024, entities must meet the requirements for risk management measures and reporting obligations. To initiate necessary measures in a timely manner, it is therefore essential to take action now.

For all those affected at the time of entry into force, the registration of the organization with the BSI must have been completed by January 17, 2025, at the latest. For entities that become affected later, for example because the number of employees was only then exceeded, a deadline of three months applies.

What should affected entities do now?

Given the little time remaining before measures must be implemented, affected parties should act swiftly.

1. Determine affected status
Read about how affected status can be determined in the second part of the NIS 2 article series .
2. Gap Analysis
It must be determined in which areas gaps exist in fulfilling the NIS 2 requirements.
3. Define Measures
Appropriate measures must be defined for all gaps.
4. Implement Measures
Registration must be prepared, a reporting process set up, and risk management established.

The aramido consultants can support you in all these steps.

To protect the company sustainably in the face of a constantly changing threat landscape, information security must be understood as a process. New risks must be identified and addressed repeatedly – not only to fulfill legal requirements, but above all, to protect the company from significant damage.

We are happy to accompany you on the path to NIS 2 implementation. Take advantage of a free initial consultation to discuss your project with a security expert.

More on the topic of NIS 2

What is NIS 2?

Who is affected by NIS 2?