THREAT BRIEFING · 23.09.2026 DEENFRES

News

NIS2 Enforcement 2026: BSI Audit Phase and DACH Checklist

By Alec Chizhik · May 3, 2026 · 1 min read

On April 18, 2026, Belgium’s first NIS2 enforcement deadline for essential entities expired. In Germany, the BSI registration deadline passed on March 6, 2026. Those who have not registered by then are now under the scrutiny of a supervisory system that imposes fines of up to 10 Mio. EUR or 2 percent of annual turnover and can hold managing directors personally liable. The enforcement wave is no longer a mere threat.

What NIS2 Requires from Regulated Entities

What is NIS2? The EU Directive on Network and Information Security (NIS2, Directive 2022/2555) establishes binding cybersecurity obligations for critical sectors. It replaces the 2016 NIS Directive, significantly expands its scope, and introduces a uniform sanctions regime with personal liability for managers.

The NIS2UmsuCG has been in force since December 6, 2025. The often-cited “appropriate security” has now been concretized by the ENISA Technical Implementation Guidance (June 2025) – this is the difference from older compliance frameworks that allowed more room for interpretation. Anyone arguing they lacked clarity on what exactly needed to be done has a research problem, not a regulatory problem.

Art. 21 NIS2 defines ten categories of measures that a regulated entity must have implemented and documented. ENISA further clarified in Q1 2026: MFA for privileged access, remote access accounts, and vendor accounts is “practically always appropriate” – leaving little room for interpretation through “where appropriate.”

What Many Already Have

  • Firewall and Endpoint Protection
  • Backup Routine (mostly without recovery test)
  • Patch Management – somehow
  • Antivirus on Endpoints
  • Basic Password Policy

What Is Typically Missing

  • Documented Incident Response Plan
  • ISMS with Risk Register
  • 24h BSI Reporting Process (Contact Point, Escalation Chain)
  • MFA on All Privileged Accounts
  • Supply Chain Risk Analysis for IT Service Providers

DACH Region’s Implementation Status

Germany was one of the last EU members to implement it. The NIS2UmsuCG came into force on December 6, 2025, almost 15 months after the European implementation deadline. Between its adoption and operational BSI enforcement, affected companies had approximately 13 weeks – less than a quarter – for risk management setup, documentation, and registration.

Austria adopted the NISG 2026 on December 12, 2025. Effective: October 1, 2026. Affected Austrian companies thus have a short window to establish their compliance foundations before the new supervisory authority – the Federal Office for Cybersecurity – enters its operational phase. Scope: approximately 4,000 companies from 18 sectors.

Poland implemented one of the most far-reaching implementations in the EU with the KSC Act on April 3, 2026: 42,000 regulated entities, expanded from previously around 400. This is not a typo. For German-Polish supply chains and nearshoring partners, this means immediate compliance pressure on both sides.

Switzerland: Not an EU member, no direct NIS2 obligation. For Swiss companies acting as IT service providers for NIS2-regulated EU entities

What IT Teams Must Check Now

Five steps cover the most common compliance gaps. None of these points require ISO 27001 – but all demand written proof.

1
Check Scope. Does the company fall into one of the 18 NIS2 sectors according to Annex 1 or 2 BSIG? Threshold: from 50 employees OR 10 Mio. EUR annual turnover, combined with sector affiliation. Classification as an “important” or “essential” entity determines the fine framework.
2
Complete BSI Registration. The deadline expired on March 6, 2026. The BSI has so far indicated leniency, but the leeway is narrowing. Registration in the BSI portal is step one before any further compliance proof becomes relevant.
3
Document Risk Management Measures. The ten categories from Art. 21 NIS2 must be demonstrably implemented. No risk register means, in an audit context: no proof. No full ISO 27001 certification is necessary, but the document must exist.
4
Activate Reporting Process. Who is the BSI contact person in the company? Is there a written escalation chain for the 24h reporting obligation for significant incidents? Know the BSI reporting portal, communicate internally, appoint a responsible person.
5
Evaluate Suppliers. Which IT service providers have direct access to critical systems? Supply chain security is not an optional component but part of the risk analysis. Obtain written security proofs from key suppliers.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What Qualifies as an ‘Essential Entity’ under NIS2?

Essential entities are companies in sectors of high criticality (Annex 1 BSIG) with at least 250 employees or 50 Mio. EUR annual turnover and 43 Mio.

The 24-hour Reporting Obligation in Detail

In the event of a significant security incident – defined as an incident with considerable impact on the service – an initial report must be submitted to the BSI within 24 hours. A more detailed assessment follows within 72 hours, and a final report after one month. Reporting is done via the BSI reporting portal. A “significant incident” is a term that the BSI will further specify – when in doubt: report, don’t wait.

Must Suppliers Themselves Be NIS2-Compliant?

Not necessarily in the form that suppliers themselves must be registered. However, regulated entities are obliged to assess and manage security risks in their supply chain. This means: written evidence of security practices from IT service providers with critical access, minimum contractual requirements, and audit rights. Those who fail to do so bear the liability risk themselves.

More from the MBF Media Network

cloudmagazinArchitecture Drives Compliance Costs: How to Cut ThemMyBusinessFutureCSRD Post-2026: Reporting Changes and ESRS Relief for SMEsDigital ChiefsFrom Operator to Orchestrator: What the Deloitte 2026 Study Means for DACH Executives Evaluating Their Tech Leadership

Further reading

A magazine by Evernine Media GmbH