What is the NIS 2 Directive? (Part 1)

This article is part of the series on NIS 2 . Find out who is affected by NIS 2 and what requirements are imposed on companies .

The number of cyberattacks has continued to rise in recent years, driven in no small part by the ever-growing dependence on digital systems and global tensions.

The EU has responded to this threat landscape with a new Cybersecurity Strategy: in addition to strengthening European cooperation and promoting skilled professionals, joint cyber defense facilities are to be established. The strategy's goals are also to be achieved through a series of new EU directives and regulations, including the NIS 2 Directive.

As early as 2016, the EU adopted an initial directive on the security of network and information systems (NIS). In Germany, this is limited to approximately 2,000 companies from specifically defined sectors. However, attacks are now causing significant economic damage in other sectors as well. Therefore, the EU has significantly expanded the circle of affected companies for the second NIS directive. Estimates suggest that in Germany alone, up to 30,000 companies will be affected by NIS 2.

Quick Facts

  • For an initial indication of whether you are affected, please refer to our second part on NIS 2 .
  • The deadline for the first measures is October 17, 2024.
  • Most affected parties must register with the BSI by January 17, 2025.
  • We are happy to answer any further questions here .

How is NIS 2 being implemented in Germany?

Unlike, for example, the GDPR, NIS 2 is an EU directive and is not directly binding. Therefore, individual EU member states must enact national laws to implement the directive.

In Germany, there is a draft of the NIS 2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG). The draft has been approved by the cabinet but still needs to be passed by the Bundestag. However, no major changes are expected.

Additionally, the EU has reserved the option to issue implementing regulations. A draft for an initial regulation is currently under consultation. This provides specifications for the assessment of security incidents and the implementation of measures for companies that provide certain IT services, such as social network providers or managed service providers.

According to the current status, both documents are to be fully adopted by October 17, 2024.

Who is affected by NIS 2?

Whether a company is affected depends on a number of criteria. These include, among others, the industry, the size and location of the company, and whether business is conducted within the EU. More detailed information on who is affected by NIS 2 can be found in the second part of our article series .

What can affected entities expect?

The EU is also relying on technology neutrality with NIS 2. The directive specifies what must be implemented but has few requirements on how this should be done. You can find out which specific measures are required in the third part of our article series .

When must affected entities take action?

Immediately upon the expected entry into force of the NIS 2 Directive on October 17, 2024, entities must meet the requirements for risk management measures and reporting obligations. To initiate the necessary measures in a timely manner, it is recommended to take action now.

All companies affected at the time of entry into force must register with the BSI by January 17, 2025, at the latest. For companies that become affected later, for example because the number of employees was only then exceeded, a deadline of three months applies.

What happens next?

To achieve the goal of significantly increasing the level of information security in companies across the EU, the EU relies on the cooperation of these companies. To reach these objectives, NIS 2 provides for a number of obligations, the non-compliance with which can be severely penalized.

Information to determine whether a company is affected and which measures must be taken can be found in the following blog posts. The aramido consultants are also available to answer any questions.

We accompany you on the path to NIS 2 implementation! Take advantage of a free initial consultation to discuss your project with a security expert.