THREAT BRIEFING · 10.09.2026 DEENFRES

Practice & Implementation

NIS2 for Mid-Sized Firms: Achievable Steps, Avoidable Mistakes

By Alec Chizhik · May 18, 2026 · 8 min read

The NIS2 Implementation Act has been in force in Germany since 6 December 2025 – with no transition period. The registration deadline with the BSI expired on 6 March 2026. Around 29,500 companies in Germany now fall under the new obligations, many of them mid-sized and many still unregistered. The question is no longer whether NIS2 is coming, but how a mid-sized company can pragmatically implement it without turning it into a major project.

Key Takeaways

  • The deadline has passed, but the obligation remains. NIS2 has applied since December 2025 without any transition period. Those who are not yet registered must catch up – the late registration process is still possible.
  • Ten areas of action, not a mega-project. The law requires structured risk management. Most mid-sized companies already have the building blocks in place – they just aren’t documented.
  • Senior management is personally liable. NIS2 makes the approval and oversight of measures a board-level responsibility. This duty cannot be delegated to IT.
  • The reporting chain must be practiced. 24-hour early warning, 72-hour notification, one-month final report. An untrained reporting path will burn the first deadline with administrative overhead.

What is NIS2? NIS2 is the EU Directive on Network and Information Security, transposed into German law via the NIS2 Implementation Act (NIS2UmsuCG). It obliges companies classified as essential or important to maintain documented cybersecurity risk management, register with the BSI, and report significant security incidents.

Related:Where mid-sized firms still fall short on NIS2’s technical minimums  /  EU AI Act: 2 August 2026 – Where the high-risk compliance gap yawns

The deadline has already passed

Most NIS2 articles over the past two years ended with a future date. This one doesn’t. The NIS2 Implementation Act was published in the Federal Law Gazette on 6 December 2025 and has been in force ever since. There is no phased roll-out or grace period, as many companies had hoped. The obligations take effect immediately upon publication.

According to estimates by the BSI and BMI, this affects around 29,500 companies. The range spans from classic KRITIS operators deep into the mid-market, across sectors such as mechanical engineering, logistics, food production, chemicals, and IT service providers. Some of these companies still aren’t sure whether they’re affected. That’s the first practical mistake: NIS2 requires self-assessment. No one will send you an official notice.

around 29,500
companies in Germany fall under NIS2 obligations, a significant portion of them mid-market enterprises.
Source: BSI / BMI, estimate on NIS2 implementation

The registration deadline with the BSI ended on 6 March 2026. Missing it doesn’t let you off the hook – you’re simply late. Registration via the BSI portal remains possible and must be completed; it requires an ELSTER organisation certificate. This step is small but essential, and in practice it’s the one most often postponed.

What practical implementation demands

NIS2 doesn’t impose an exotic set of requirements. The law mandates risk management across ten areas: risk analysis, incident response, business continuity including backup management, supply-chain security, secure procurement and development, effectiveness assessment, basic cyber hygiene and training, cryptography, personnel security and access control, and multi-factor authentication plus secure communication.

The good news for most mid-market firms: much of this already exists in operations. Backups are running, access is managed, updates are applied. What’s often missing isn’t the substance but the structured documentation and proof that measures are effective. NIS2 doesn’t just ask whether a backup exists – it asks when it was last successfully restored.

The second component is the reporting obligation. A significant security incident triggers a three-tier timeline: an early warning to the BSI within 24 hours, a more detailed report within 72 hours, and a final report within one month. The 24-hour clock starts when the incident is known. Companies without an internal escalation path burn most of that window on internal coordination instead of reporting.

The roadmap in four steps

NIS2 implementation can be run as a major project or as a structured sequence of four steps. For mid-market companies, the second approach is more reliable. It follows risk: clarify status first.

Step 1: Determine scope and register

Start with self-assessment: does the company fall under NIS2 based on size and sector, and if so, as an essential or important entity? This classification determines supervisory intensity and penalties. Once decided, register via the BSI portal. Without this step, every subsequent measure remains legally incomplete.

Step 2: Gap analysis across the ten areas

For each measure, honestly record what already exists, what exists but isn’t documented, and what’s missing. The result is usually less daunting than feared. The effort rarely lies in new technology but in making existing measures visible and verifiable.

Step 3: Establish and rehearse the reporting chain

The reporting path needs named roles, substitute rules, and fallback communication. The decisive factor is a dry run. Companies that simulate the 24-hour path from detection to BSI acknowledgment uncover organisational gaps before an actual incident – not during one.

Step 4: Involve Management and Secure Evidence

NIS2 requires management to approve risk measures and monitor their implementation. This duty cannot be delegated. In practice, this means: a documented resolution, regular review, and traceable evidence storage. Anything not documented may, in doubt, be considered undone.

NIS2 doesn’t ask whether a backup exists, but when it was last successfully restored.

Costly Implementation Mistakes

Four patterns reliably cause problems in practice, and none of them are technical.

The first mistake is postponing registration because it seems unimportant. It is the formal anchor of all compliance and the first point an authority examines. The second mistake is ignoring the supply chain. NIS2 explicitly holds service providers and suppliers accountable. Focusing only on your own IT draws the scope too narrowly.

The third mistake is management attempting to delegate liability to the IT department. The law does not allow this, and an uninvolved leadership becomes immediately visible during audits. The fourth mistake is a reporting chain that exists on paper but has never been tested. An escalation path first used during an incident will not meet the 24-hour deadline.

The technical side – what specific minimum measures a mid-sized company still owes – is explored in more depth in our analysis on NIS2 technical minimums. This article stays on the organizational level because most implementations fail there.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

When did NIS2 enter into force in Germany?

The NIS2 Implementation Act was promulgated on 6 December 2025 and has been in force since then. There is no transition or grace period; obligations apply immediately upon enactment. The originally planned phased rollout never materialized.

My company missed the registration deadline – what now?

The registration window at the BSI closed on 6 March 2026, but late registration remains possible and should be completed without delay. It is filed via the BSI portal and requires an ELSTER organization certificate. Registration is the prerequisite for all subsequent measures to be legally complete.

What reporting deadlines apply to a security incident?

A significant incident triggers three deadlines: an early warning to the BSI within 24 hours, a detailed report within 72 hours, and a final report within one month. The clock starts when the company becomes aware of the incident, not upon external notification.

Is management personally liable?

Yes. NIS2 obliges management to approve risk-management measures and monitor their execution. This duty cannot be fully delegated to the IT department. A documented resolution and regular oversight by management are therefore part of compliance.

Is NIS2 a major project for mid-sized firms?

Usually not. Most of the ten measure areas are already partially covered in daily operations. The effort lies mainly in structured documentation, effectiveness assessment, and establishing a tested reporting chain – not in building fundamentally new technology.

Editor’s Picks

Editor’s Pick72 percent of cyber defense comes from abroadEditor’s PickCopilot Cowork Acts Alone, the SOC Doesn’t See ItEditor’s PickPrivacy Watchdogs Target Mid-Sized Firms

More from the MBF Media Network

cloudmagazinArchitecture Drives Compliance Costs: How to Cut ThemMyBusinessFutureProcess Optimization Without Permanent ProjectDigital ChiefsNIS2 Compels CIOs to Bring Edge Devices Into Audit Scope

Further reading

Practice & Implementation · July 31, 2026

Anthropic: Claude Breached Three Companies

Anthropic's Claude compromised three organizations in cyber evaluations. Harness misconfiguration, PyPI malware, and CISO checklist insights.

Practice & Implementation · July 29, 2026

Codex Security: Open Client Feeds OpenAI

Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.

A magazine by Evernine Media GmbH