Topics/NIS2
NIS2 HUB

Everything on NIS2.

The Directive, the German NIS2UmsuCG, Art. 21 ten measures, affected entities, penalties, and how 29,000 German organizations can operationalize it. One page, all the content.

English articles

Deutsche Artikel

By industry

NIS2

NIS2 for Banking

NIS2 compliance for banks and credit institutions. How NIS2 interacts with DORA, BaFin expectations, essential-entity obligations, supply chain security.

NIS2

NIS2 for SaaS & Cloud Providers

NIS2 for SaaS, cloud computing, managed services and digital infrastructure providers. Essential-entity status, registration obligations, incident notification to ENISA and BSI.

NIS2

NIS2 for Telecom & Electronic Communications

NIS2 for telecom operators, ISPs, and electronic communications providers. Overlap with European Electronic Communications Code (EECC), TKG in Germany, BSI + BNetzA supervision.

NIS2

NIS2 for Public Sector & Government

NIS2 compliance for public administration, federal ministries, state authorities, and municipal IT. BSI supervision, BSI IT-Grundschutz alignment, public-sector-specific requirements.

NIS2

NIS2 for Pharmaceuticals & Life Sciences

NIS2 compliance for pharma manufacturers and life sciences. Integration with GxP, Annex 11 GMP, medical-device cybersecurity, clinical-trial data security.

NIS2

NIS2 for Water & Wastewater

NIS2 compliance for drinking water and wastewater operators. Essential-entity status, OT/ICS security for SCADA systems, BSI supervision, sector-specific guidance.

NIS2

NIS2 for Logistics & Transport

NIS2 compliance for transport and logistics operators. Annex I essential entity coverage across air, rail, shipping, and road. OT security, supply-chain obligations, BSI supervision.

NIS2

NIS2 for Digital Infrastructure (DNS, TLD, Trust Services)

NIS2 compliance for DNS operators, TLD registries, trust service providers (eIDAS), and core internet infrastructure. Size-independent essential-entity obligations.

Frequently asked questions

Ab wann gilt NIS2?+

Die EU-Richtlinie (EU) 2022/2555 ist seit 18. Oktober 2024 in Kraft. Deutschland hat mit dem NIS2UmsuCG verspaetet umgesetzt — Stand April 2026 in parlamentarischer Verabschiedung. Materielle Pflichten gelten bereits jetzt, Aufsichtsbehoerden wenden NIS2-Massstaebe an.

Wer ist von NIS2 betroffen?+

Wesentliche Einrichtungen (Grossunternehmen >= 250 MA oder >= 50 Mio. Umsatz in Anhang-I-Sektoren) und wichtige Einrichtungen (50-249 MA oder 10-50 Mio. Umsatz in Anhang-II-Sektoren). Einige Entitaeten (Vertrauensdiensteanbieter, TLD-Registries, oeffentliche Verwaltung) unabhaengig von Groesse. In DE ca. 29.000 Unternehmen.

Welche Bussgelder drohen?+

Wesentliche Einrichtungen: bis 10 Mio. EUR oder 2% des weltweiten Jahresumsatzes. Wichtige Einrichtungen: bis 7 Mio. EUR oder 1,4%. Plus persoenliche Haftung der Geschaeftsleitung (§ 38 BSIG-neu).

Ready to tackle NIS2?

Matproof covers NIS2 in one EU-hosted platform alongside 10 other frameworks. 30-minute demo tailored to your scope.