The NIS2 Audit: How Companies Prepare for the First Inspection
8 Min. Reading Time
48 percent of affected companies are still unsure whether they fall under NIS2. Only 12.1 percent have fully implemented the requirements for the December 2025 deadline. The law applies without a transition period. And the personal liability of management with personal assets is non-negotiable: No shareholder resolution can exclude it. The first BSI audits are underway. What auditors are finding and what companies need to do now.
Key Takeaways
- Readiness Status: Only 12.1 percent of affected companies have fully implemented NIS2 by the deadline, while 48 percent are unsure if they are even affected
- 10 Mandatory Measures: Paragraph 30 of the BSIG defines ten minimum measures from risk analysis to incident management and MFA – all must be documented and provable
- Personal Liability: Managers are personally liable with their personal assets under Paragraph 38 of the BSIG, and any liability waiver is legally excluded
- Fines: Up to 10 million Euros or 2 percent of global annual revenue for critical infrastructure
- ISO 27001 Gap: Covers 70-80 percent of NIS2 requirements, but three critical gaps remain: Reporting obligations, management liability, and enterprise-wide scope
The BSI’s Audits Reveal: Insights from the Initial Audits
Since January 2026, the BSI has gradually assumed its supervisory responsibilities. The registration portal was launched on January 6, 2026, and the registration deadline ended on March 6, 2026. Over 30,000 companies in Germany have been classified as either critical or important institutions and must meet the requirements.
The BSI identifies affected companies through multiple channels: commercial and business registers, industry associations, self-reporting, and collaboration with sector regulators such as the Bundesnetzagentur (Energy) and the BfArM (Health). The escalation process is tiered: informal registration request, formal written request if there is no response, administrative proceedings, and finally, fines with public disclosure.
The initial practical experiences from BSI audits reveal three recurring critical gaps. First: The reporting process is documented but not operational. Companies have incident response plans, but no one can identify the responsible BSI contact person within an hour in practice. No real drills, no time-pressured tests. Second: Supply Chain Blind Spots – An eight-year-old ERP interface provider was changed, with no documentation on access rights and current security status. Third: Fragmented Log Management – Logs run for 30 days on local devices instead of being centrally aggregated. The BSI is examining centralized log infrastructure.
Sources: Proliance Study 2025, Schwarz Digits Cyber Security Report 2026, NIS2UmsuCG §30 BSIG
The 10 Mandatory Measures: What Paragraph 30 BSIG Requires
Paragraph 30, Section 2 of the BSIG specifies ten minimum measures that all affected institutions must implement and demonstrate compliance with. These measures are proportionate – the size, risk profile, and potential impact of the organization are taken into account in the evaluation. However, “proportionate” does not mean “voluntary.”
Measure 1: Risk Analysis and IT Security Concepts. A documented, systematic risk identification process with annual review. This is the foundation – without this analysis, auditors cannot assess whether the other measures are adequate.
Measure 2: Incident Management. Documented processes for the detection, analysis, containment, and recovery following security incidents. This includes the incident response capability, which the BSI critically examines: 24-hour early warning to the BSI, 72-hour detailed report.
Measure 3: Business Continuity Management. Backup strategies, disaster recovery plans, and regular testing. A plan that has never been tested is not a plan. Auditors verify not only the existence of a document but whether recovery actually works. The ransomware resilience directly depends on this measure.
Measures 4 and 5: Supply Chain Security and Secure Procurement. Supplier evaluation with contractual security requirements and security controls throughout the IT system lifecycle. The BSI not only checks if contracts exist but also if they include concrete standards and audit rights.
Measure 6: Effectiveness Review. Internal audits, penetration tests, and KPI monitoring. Companies must demonstrate that they regularly review the effectiveness of their security measures – not just implement them but validate them.
Measure 7: Training and Awareness. Mandatory training for all employees, including senior management. The executive board must personally participate in cybersecurity training – every three years, with proof.
Measures 8-10: Cryptography, Access Control, and MFA. Encryption policies for data at rest and during transmission. Documented authorization management with authentication protocols. And multi-factor authentication for critical systems – the measure whose absence enabled the South Westphalia IT attack.
ISO 27001: 80% Coverage, Three Critical Gaps
Companies with an existing ISO 27001 ISMS have a significant head start. According to expert estimates, ISO 27001 covers 70-80% of NIS2 requirements. Seven out of ten Paragraph 30 measures are fully covered by an ISO 27001 ISMS. Both ISO 27001 and BSI IT-Grundschutz are legally recognized as the foundation for NIS2 compliance.
Three critical gaps remain. Gap 1: Reporting Obligations. ISO 27001 mandates incident management processes but does not require reporting to authorities. NIS2 specifies a 24-hour early warning to the BSI and a 72-hour detailed report. This necessitates an operational reporting process with clear responsibilities and round-the-clock accessibility.
Gap 2: Personal Liability of Management. ISO 27001 requires “Leadership Commitment” as a general principle. Paragraph 38 BSIG imposes personal training obligations on board members and executives, along with personal liability tied to their personal assets. This is a fundamental difference: ISO commitment is a management system principle, while NIS2 liability is a legal requirement.
Gap 3: Enterprise-Wide Scope. ISO 27001 allows limited scopes, enabling a company to certify only its IT department or a single data center. NIS2 applies enterprise-wide and across all sites. If a company has three locations and only one ISO 27001-certified, it does not meet NIS2 requirements.
The expert recommendation: Expand the existing ISO 27001 ISMS instead of building parallel compliance structures. Gap analysis, scope expansion, and governance adjustments are the three key steps. This approach saves costs and maximizes the use of existing compliance infrastructure.
An ISO 27001 certification or an IT-Grundschutz attestation significantly simplifies NIS2 compliance. However, there is no official “NIS2 certification.” Compliance is demonstrated through documented implementation of the ten mandatory measures and the ability to present them during audits.
Management Liability: What Paragraph 38 BSIG Means
Paragraph 38 BSIG makes board members and executives personally liable for damages resulting from non-compliance. The key point: Liability extends to their personal assets. A shareholders’ resolution to waive liability is legally invalid. The Business Judgment Rule, which typically protects directors from personal liability for business judgment errors, does not apply here.
Three core obligations fall directly on management. First: Actively approve NIS2 risk measures – not just rubber-stamping but engaging substantively. Second: Actively monitor implementation – not just receiving status updates but ensuring measures are effective. Third: Regular and documented participation in cybersecurity training (every three years).
In the event of a dispute, management bears the burden of proving compliance – the burden of proof shifts. It is not the claimant’s responsibility to prove management acted negligently, but management’s responsibility to prove they took all necessary actions. Even if operational responsibility is delegated to a CISO, delegation does not absolve personal liability – it is an organizational measure, not a legal safeguard.
For boards that already recognize NIS2 compliance as a site advantage, personal liability becomes the decisive motivator: It’s not just about corporate fines, but personal exposure.
The Readiness Level: Where German Companies Stand
The numbers are disconcerting. According to a Proliance study, by the time NIS2 takes effect in December 2025, only 12.1 percent of affected companies will have fully implemented NIS2. An additional 20.4 percent are in the final stages, while 31.3 percent are in the middle of the process. About a quarter has not even started.
The Schwarz Digits Cyber Security Report 2026 (1,001 respondents) highlights another issue: 48 percent of the companies surveyed incorrectly assess their regulatory NIS2 exposure and may mistakenly believe they are not affected. With over 30,000 regulated companies, this means thousands are affected and unaware.
A G-Data/Statista/Brand-Eins study found that 63 percent of companies have either started or are in the process of implementing NIS2. This sounds like progress, but the quality of implementation varies significantly. “In the process” can mean: strategically planned and structured. It can also mean: the CISO has requested a budget that has not yet been approved.
Fines are tiered: particularly important institutions (over 250 employees or over 50 million Euro in revenue) risk fines of up to 10 million Euros or 2 percent of global annual revenue. Important institutions (50-249 employees or 10-50 million Euro in revenue) risk fines of up to 7 million Euros or 1.4 percent. Additionally, there are binding BSI orders, public disclosure of violations (reputational damage), and the possibility of interim suspension of management functions. For executives familiar with the DSGVO, the message is clear: enforcement activities will be moderate in the first few years and then increase exponentially. By 2024, DSGVO fines had accumulated to over 2.9 billion Euros in the EU.
Audit Preparation: The Practical Checklist
Based on the ten mandatory measures and insights from the first BSI audits:
1. ISMS Concept with Risk Analysis. Documented, systematic, and with proof of annual review. Without this document, no audit can begin.
2. Current Asset Inventory. All IT systems, interfaces, and third-party providers documented. The BSI checks whether the inventory is complete and up-to-date, not just whether it exists.
3. Operational Incident Response Plan. With specific contact persons, availability, and escalation paths. The plan must function under pressure, not just exist on paper. Recommendation: Conduct at least one drill annually to test the 24/7 reporting chain.
4. Pentests and Effectiveness Evidence. Regular penetration tests and internal audits with documented results and action protocols.
5. Training Certificates for All Employees. Including the executive board. No exceptions. The BSI specifically checks whether the leadership has received personal training.
6. Encryption Policies and MFA Documentation. Which systems are encrypted, which algorithms are used, and where MFA is implemented. The Post-Quantum Cryptography Migration will become increasingly relevant in the coming years.
7. Supplier Contracts with Security Requirements. Any external service provider with system access needs a contract that specifies concrete security standards and audit rights.
8. Centralized Log Management. Not local logs with 30-day retention, but centrally aggregated and evaluable. This is the measure that was most frequently criticized in the first BSI audits.
Who Conducts: External Audit Providers in Germany
There is no unified “NIS2 Certification” – Companies conduct audits and penetration tests and use certificates (ISO 27001 with NIS2 mapping, BSI IT-Grundschutz) as evidence to the BSI. For critical infrastructure operators and facilities, a three-year evidence cycle is required.
The established audit providers in Germany: TÜV Rheinland offers NIS2 Readiness Assessments and consulting. TÜV NORD has developed a certification program “NIS-2 Expert (TÜV)” for auditors. TÜVIT specializes in KRITIS and NIS2 audits. DEKRA provides NIS2 guideline certification and consulting. Additionally, major consulting firms (PwC, Deloitte, EY, KPMG) have built NIS2-specific audit services.
Recommendation: Start with a Gap Analysis that aligns the current state with the ten mandatory measures. Companies with ISO 27001 typically need three to six months for NIS2 extension. Companies without an existing ISMS should plan for 12 to 18 months. The longer a company waits, the more expensive it becomes – and the more likely the first BSI contact will not be a friendly letter but an administrative procedure.
The most common gaps found in Gap Analyses are not technical issues: SIEM infrastructures exist but are not fully integrated. Business Continuity Plans are in place but never tested. Supplier contracts contain general clauses but no specific security requirements. And the biggest blind spot: The ISO 27001 scope covers only part of the company, while NIS2 applies to everything. Starting with a Gap Analysis now provides a clear roadmap. Waiting results in a compliance issue that becomes more expensive with each month of delay.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
What Does the BSI Check During a NIS2 Audit?
Implementation of the ten mandatory measures according to Section 30 BSIG: Risk analysis, incident management, business continuity, supply chain security, secure procurement, effectiveness testing, training, cryptography, access control, and MFA. The BSI particularly scrutinizes the operational reporting process and centralized log management.
Is There a NIS2 Certification?
No, there is no official NIS2 certification. ISO 27001 and BSI IT-Grundschutz are recognized as evidence, but they do not replace NIS2-specific documentation. Companies demonstrate compliance through documented measures and audit results.
How Much Does ISO 27001 Cover of NIS2?
According to expert estimates, 70 to 80 percent. Three critical gaps: Reporting obligations to the BSI (24/72 hours), personal liability of business leaders (Section 38 BSIG), and the company-wide scope (ISO 27001 allows limited scopes).
Is the CEO Personally Liable?
Yes, according to Section 38 BSIG with personal assets. Liability waivers are legally void, and the burden of proof lies with the company. Delegating to a CISO does not protect against personal liability.
How Much Time Does NIS2 Preparation Take?
Companies with ISO 27001 typically need three to six months for the extension. Without an existing ISMS: 12 to 18 months. Critical infrastructure operators must submit evidence to the BSI every three years.
Read More
- NIS2 as a Location Advantage: Why Cybersecurity Regulation Strengthens the Business Location
- Supply Chain Security: From Compliance Obligation to Competitive Advantage
- Reboot Germany: 735 Billion, Three Medium-Sized Enterprises, and the Question of Whether the Crisis Is Really That Bad
Source Title Image: Pexels / Sora Shimazaki (px:5668858)