NIS2 Enforcement 2026: BSI Audit Phase and DACH Checklist
On April 18, 2026, Belgium’s first NIS2 enforcement deadline for essential entities expired. In Germany, the BSI registration deadline passed on March 6, 2026. Those who have not registered by then are now under the scrutiny of a supervisory system that imposes fines of up to 10 Mio. EUR or 2 percent of annual turnover and can hold managing directors personally liable. The enforcement wave is no longer a mere threat.
What is NIS2? The EU Directive on Network and Information Security (NIS2, Directive 2022/2555) establishes binding cybersecurity obligations for critical sectors. It replaces the 2016 NIS Directive, significantly expands its scope, and introduces a uniform sanctions regime with personal liability for managers.
The NIS2UmsuCG has been in force since December 6, 2025. The often-cited “appropriate security” has now been concretized by the ENISA Technical Implementation Guidance (June 2025) – this is the difference from older compliance frameworks that allowed more room for interpretation. Anyone arguing they lacked clarity on what exactly needed to be done has a research problem, not a regulatory problem.
Art. 21 NIS2 defines ten categories of measures that a regulated entity must have implemented and documented. ENISA further clarified in Q1 2026: MFA for privileged access, remote access accounts, and vendor accounts is “practically always appropriate” – leaving little room for interpretation through “where appropriate.”
What Many Already Have
- Firewall and Endpoint Protection
- Backup Routine (mostly without recovery test)
- Patch Management – somehow
- Antivirus on Endpoints
- Basic Password Policy
What Is Typically Missing
- Documented Incident Response Plan
- ISMS with Risk Register
- 24h BSI Reporting Process (Contact Point, Escalation Chain)
- MFA on All Privileged Accounts
- Supply Chain Risk Analysis for IT Service Providers
DACH Region’s Implementation Status
Germany was one of the last EU members to implement it. The NIS2UmsuCG came into force on December 6, 2025, almost 15 months after the European implementation deadline. Between its adoption and operational BSI enforcement, affected companies had approximately 13 weeks – less than a quarter – for risk management setup, documentation, and registration.
Austria adopted the NISG 2026 on December 12, 2025. Effective: October 1, 2026. Affected Austrian companies thus have a short window to establish their compliance foundations before the new supervisory authority – the Federal Office for Cybersecurity – enters its operational phase. Scope: approximately 4,000 companies from 18 sectors.
Poland implemented one of the most far-reaching implementations in the EU with the KSC Act on April 3, 2026: 42,000 regulated entities, expanded from previously around 400. This is not a typo. For German-Polish supply chains and nearshoring partners, this means immediate compliance pressure on both sides.
Switzerland: Not an EU member, no direct NIS2 obligation. For Swiss companies acting as IT service providers for NIS2-regulated EU entities
What IT Teams Must Check Now
Five steps cover the most common compliance gaps. None of these points require ISO 27001 – but all demand written proof.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
What Qualifies as an ‘Essential Entity’ under NIS2?
Essential entities are companies in sectors of high criticality (Annex 1 BSIG) with at least 250 employees or 50 Mio. EUR annual turnover and 43 Mio.
The 24-hour Reporting Obligation in Detail
In the event of a significant security incident – defined as an incident with considerable impact on the service – an initial report must be submitted to the BSI within 24 hours. A more detailed assessment follows within 72 hours, and a final report after one month. Reporting is done via the BSI reporting portal. A “significant incident” is a term that the BSI will further specify – when in doubt: report, don’t wait.
Must Suppliers Themselves Be NIS2-Compliant?
Not necessarily in the form that suppliers themselves must be registered. However, regulated entities are obliged to assess and manage security risks in their supply chain. This means: written evidence of security practices from IT service providers with critical access, minimum contractual requirements, and audit rights. Those who fail to do so bear the liability risk themselves.
More from the MBF Media Network
cloudmagazinArchitecture Drives Compliance Costs: How to Cut ThemMyBusinessFutureCSRD Post-2026: Reporting Changes and ESRS Relief for SMEsDigital ChiefsFrom Operator to Orchestrator: What the Deloitte 2026 Study Means for DACH Executives Evaluating Their Tech Leadership
Further reading
WithSecure: From Antivirus Pioneer to Cloud Security Specialist
WithSecure has been F-Secure’s B2B spin-off since 1 July 2022. Its Elements platform, co-security services and European data-protection focus aim to give security teams …


