{"id":13807,"date":"2026-05-03T09:28:15","date_gmt":"2026-05-03T09:28:15","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/05\/03\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was\/"},"modified":"2026-05-20T20:28:17","modified_gmt":"2026-05-20T20:28:17","slug":"nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was\/","title":{"rendered":"NIS2 Enforcement 2026: BSI Audit Phase &#038; DACH Checklist"},"content":{"rendered":"\n<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">6 Min. read<\/p>\n\n<p><strong>On April 18, 2026, the first NIS2 enforcement deadline for particularly important entities expired in Belgium. In Germany, the BSI registration deadline passed on March 6, 2026. Those who failed to register by then are now under the scrutiny of a supervisory system that can impose fines of up to 10 million EUR or 2 percent of annual turnover and hold managing directors personally liable. The enforcement wave is no longer just a threat.<\/strong><\/p>\n\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">29,500 regulated entities in Germany.<\/strong> The NIS2UmsuCG has expanded the German scope from 4,500 to 29,500 entities. Many are still unaware that they are affected.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Enforcement phase active since May 2026.<\/strong> Belgium&#8217;s first deadline was April 18, 2026. The BSI has been in the operational review phase since May 2026. Austria follows with implementation on October 1, 2026.<\/li>\n<li style=\"margin-bottom:12px;color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">Fine framework: 10 million EUR or 2 percent.<\/strong> For particularly important entities. Additionally, in Germany, personal manager liability can reach up to 500,000 EUR &#8211; affecting the individual, not the legal entity.<\/li>\n<li style=\"color:rgba(255,255,255,0.92);\"><strong style=\"color:#69d8ed;\">84 percent not ready.<\/strong> According to CyberSmart (April 2026), 84 percent of enforcement-exposed organizations are not compliance-ready. The gap between regulatory requirements and operational reality has not diminished.<\/li>\n<\/ul>\n<\/div>\n<p><strong>Related: <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/gdpr-fines-2026-why-regulators-are-now-targeting-smes\/\">GDPR Fines 2026: Why Supervisory Authorities Are Now Targeting SMEs<\/a><\/strong><\/p>\n\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#69d8ed;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/28\/eu-ai-act-high-risk-deadline-august-2026-supervisory-gap\/\" style=\"color:#333;text-decoration:underline;\">EU AI Act: High-risk systems from August 2, 2026<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/29\/beprime-breach-lack-of-mfa-causes-data-leak\/\" style=\"color:#333;text-decoration:underline;\">BePrime Breach April 2026: The Cost of Missing MFA<\/a><\/p>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What the enforcement phase means in concrete terms<\/h2>\n<p>Enforcement is no longer an orientation phase. In Germany, the BSI registration deadline for regulated entities expired on March 6, 2026. Those who did not register have missed a deadline. This is not a formal error in the NIS2 context, but a formal violation &#8211; a fine of up to 100,000 EUR is possible even without further elements of the offense.<\/p>\n<p>In Belgium, the first compliance proof obligation for particularly important institutions expired on April 18, 2026. CyFun conformity, ISO 27001 certification, or direct inspection by the Centre for Cybersecurity Belgium &#8211; one of these had to be demonstrated. The pattern emerging there will become a reference point in Germany, Austria, and Switzerland. What is considered a minimum standard in Belgium will become the benchmark.<\/p>\n<p>In Q4 2025, the BSI sent formal notices to 47 institutions due to lack of registration. This is not a final measure, but the beginning of an escalation chain. From May 2026, the BSI will be in the operational audit phase &#8211; focusing on registration status, risk management measures under Art. 21 NIS2, and incident reporting processes.<\/p>\n\n<div style=\"margin:32px 0;background:#0a1628;color:#fff;padding:32px;border-radius:10px;text-align:center;\">\n<div style=\"font-size:0.75em;text-transform:uppercase;letter-spacing:2px;color:#69d8ed;margin-bottom:8px;\">Regulated institutions in Germany according to NIS2UmsuCG<\/div>\n<div style=\"font-size:clamp(2.2em,8vw,3.5em);font-weight:800;line-height:1;color:#fff;\">29.500<\/div>\n<div style=\"font-size:0.95em;margin-top:8px;color:rgba(255,255,255,0.65);\">previously: 4,500 | Source: BSI, December 2025<\/div>\n<\/div>\n\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What NIS2 requires of regulated institutions<\/h2>\n<p><strong>What is NIS2?<\/strong> The EU Directive on Network and Information Security (NIS2, Directive 2022\/2555) establishes binding cybersecurity obligations for critical sectors. It replaces the 2016 NIS Directive, significantly expands its scope, and introduces a uniform sanctions regime with personal manager liability.<\/p>\n<p>The NIS2UmsuCG has been in force since December 6, 2025. The often-cited &#8220;appropriate security&#8221; has now been concretized by the ENISA Technical Implementation Guidance (June 2025) &#8211; this is the difference from older compliance frameworks that allowed more room for interpretation. Anyone who argues that they did not have clarity about what specifically needed to be done has a research problem, not a regulatory problem.<\/p>\n<p>Art. 21 NIS2 defines ten categories of measures that a regulated institution must have implemented and documented. In Q1 2026, ENISA additionally clarified: MFA for privileged access, remote access accounts, and vendor accounts is &#8220;practically always appropriate&#8221; &#8211; there is little room for &#8220;where appropriate&#8221; there anymore.<\/p>\n\n<div style=\"margin:32px 0;display:flex;flex-wrap:wrap;gap:20px;\">\n<div style=\"flex:1;min-width:220px;background:#f7f7f7;padding:24px;border-radius:8px;\">\n<p style=\"font-weight:700;color:#69d8ed;margin:0 0 14px 0;font-size:0.95em;text-transform:uppercase;letter-spacing:0.06em;\">What many already have<\/p>\n<ul style=\"margin:0;padding-left:18px;line-height:1.7;color:#333;font-size:0.93em;\">\n<li>Firewall and endpoint protection<\/li>\n<li>Backup routine (often without recovery test)<\/li>\n<li>Patch management &#8211; somehow<\/li>\n<li>Antivirus on endpoints<\/li>\n<li>Basic password policy<\/li>\n<\/ul>\n<\/div>\n<div style=\"flex:1;min-width:220px;background:#0a1628;padding:24px;border-radius:8px;\">\n<p style=\"font-weight:700;color:#69d8ed;margin:0 0 14px 0;font-size:0.95em;text-transform:uppercase;letter-spacing:0.06em;\">What is typically missing<\/p>\n<ul style=\"margin:0;padding-left:18px;line-height:1.7;color:rgba(255,255,255,0.85);font-size:0.93em;\">\n<li>Documented incident response plan<\/li>\n<li>ISMS with risk register<\/li>\n<li>24h BSI reporting process (contact point, escalation chain)<\/li>\n<li>MFA on all privileged accounts<\/li>\n<li>Supply chain risk analysis for IT service providers<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">How the DACH Region Stands on Implementation<\/h2>\n<p>Germany was one of the last EU members to implement the changes. The NIS2UmsuCG came into force on December 6, 2025, almost 15 months after the European deadline. Between enactment and operational BSI enforcement, affected companies had around 13 weeks\u2014less than a quarter to build risk management, document, and register.<\/p>\n<p>Austria passed the NISG 2026 on December 12, 2025. Effective date: October 1, 2026. Affected Austrian companies thus have a short window to establish their compliance basics before the new supervisory authority\u2014the Federal Office for Cybersecurity\u2014enters the operational phase. Scope: around 4,000 companies from 18 sectors.<\/p>\n<p>Poland enacted one of the EU&#8217;s most extensive implementations with the KSC Act on April 3, 2026: 42,000 regulated entities, expanded from previously around 400. This is not a typo. For German-Polish supply chains and nearshoring partners, this means immediate compliance pressure on both sides.<\/p>\n<p>Switzerland: Not an EU member, no direct NIS2 obligation. For Swiss companies acting as IT service providers for NIS2-regulated EU entities, indirect pressure arises through the supply-chain requirements of the client side.<\/p>\n\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What IT Teams Need to Check Now<\/h2>\n<p>Five steps cover the most common compliance gaps. None of these points require ISO 27001\u2014but all require written evidence.<\/p>\n\n<div style=\"margin:28px 0;counter-reset:steps;\">\n<div style=\"display:flex;gap:16px;margin-bottom:20px;align-items:flex-start;\">\n<div style=\"background:#69d8ed;color:#0a1628;font-weight:800;font-size:1.1em;min-width:36px;height:36px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">1<\/div>\n<div><strong>Check the scope.<\/strong> Does your company fall under one of the 18 NIS2 sectors according to Annex 1 or 2 BSIG? Threshold: from 50 employees OR 10 million EUR annual revenue, combined with sector affiliation. Classification as an &#8220;important&#8221; or &#8220;particularly important&#8221; entity determines the fine framework.<\/div>\n<\/div>\n<div style=\"display:flex;gap:16px;margin-bottom:20px;align-items:flex-start;\">\n<div style=\"background:#69d8ed;color:#0a1628;font-weight:800;font-size:1.1em;min-width:36px;height:36px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">2<\/div>\n<div><strong>Catch up on BSI registration.<\/strong> The deadline was March 6, 2026. The BSI has so far indicated leniency, but the leeway is narrowing. Registration in the BSI portal is step one before any further compliance evidence becomes relevant.<\/div>\n<\/div>\n<div style=\"display:flex;gap:16px;margin-bottom:20px;align-items:flex-start;\">\n<div style=\"background:#69d8ed;color:#0a1628;font-weight:800;font-size:1.1em;min-width:36px;height:36px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">3<\/div>\n<div><strong>Document risk management measures.<\/strong> The ten categories from Art. 21 NIS2 must be demonstrably implemented. No risk register means no evidence in the audit context. No full ISO 27001 certification is necessary, but the document must exist.<\/div>\n<\/div>\n<div style=\"display:flex;gap:16px;margin-bottom:20px;align-items:flex-start;\">\n<div style=\"background:#69d8ed;color:#0a1628;font-weight:800;font-size:1.1em;min-width:36px;height:36px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">4<\/div>\n<div><strong>Activate the reporting process.<\/strong> Who is the BSI contact person in your company? Is there a written escalation chain for the 24-hour reporting obligation in case of significant incidents? Know the BSI reporting portal, communicate internally, and appoint a responsible person.<\/div>\n<\/div>\n<div style=\"display:flex;gap:16px;margin-bottom:20px;align-items:flex-start;\">\n<div style=\"background:#69d8ed;color:#0a1628;font-weight:800;font-size:1.1em;min-width:36px;height:36px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">5<\/div>\n<div><strong>Evaluate suppliers.<\/strong> Which IT service providers have direct access to critical systems? Supply chain security is not an optional component but part of the risk analysis. Obtain written security evidence from key suppliers.<\/div>\n<\/div>\n<\/div>\n\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<h3>What qualifies as an &#8220;essential entity&#8221; under NIS2?<\/h3>\n<p>Essential entities are companies in highly critical sectors (Annex 1 BSIG) with at least 250 employees or 50 million Euro annual turnover and 43 million Euro balance sheet total. For them, the higher fine range of up to 10 million Euro or 2 percent of global annual turnover applies, whichever amount is higher. Important entities from Annex 2 or with lower thresholds have a range of 7 million Euro or 1.4 percent.<\/p>\n\n<h3>What are the concrete costs of missing the BSI registration deadline?<\/h3>\n<p>The NIS2UmsuCG provides for a fixed fine of up to 100,000 Euro for failing to register with the BSI &#8211; regardless of annual turnover. This is not a percentage of turnover, but a separate offense. In addition, the BSI can request information and take further measures if there is a lack of cooperation.<\/p>\n\n<h3>Does NIS2 also apply to Swiss companies?<\/h3>\n<p>Not directly. Switzerland is not an EU member. However, Swiss companies that act as IT service providers for NIS2-regulated EU entities come under pressure due to the supply chain requirements of their clients. Those who operate systems for a German hospital, energy supplier, or government agency can expect their clients to demand security evidence.<\/p>\n\n<h3>What are the details of the 24-hour reporting obligation?<\/h3>\n<p>In the event of a significant security incident &#8211; defined as an incident with significant impact on the service &#8211; an initial report must be made to the BSI within 24 hours. A more detailed assessment follows within 72 hours, and a final report after one month. The report is submitted via the BSI reporting portal. A &#8220;significant incident&#8221; is a term that the BSI will further specify &#8211; when in doubt, report, don&#8217;t wait.<\/p>\n\n<h3>Must suppliers themselves be NIS2-compliant?<\/h3>\n<p>Not necessarily in the sense that suppliers themselves must be registered. However, regulated entities are required to assess and manage security risks in their supply chain. This means: written evidence of IT service providers&#8217; security practices with critical access, contractual minimum requirements, and audit rights. Those who fail to do so bear the liability risk themselves.<\/p>\n\n<h3>More from the MBF Media Network<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.cloudmagazin.com\/2026\/04\/28\/bsi-kritis-cloud-multi-cloud-compliance-nis2-c5-dach-2026\/\" target=\"_blank\" rel=\"noopener\"><strong class=\"mag-cm\">cloudmagazin:<\/strong> BSI-KRITIS and Cloud Use &#8211; Multi-Cloud Compliance under NIS2 and C5<\/a><\/li>\n<li><a href=\"https:\/\/mybusinessfuture.com\/csrd-eu-omnibus-2026-berichtspflicht-esrs-vsme-mittelstand\/\" target=\"_blank\" rel=\"noopener\"><strong class=\"mag-mbf\">MyBusinessFuture:<\/strong> CSRD after the EU Omnibus 2026 &#8211; who still has reporting obligations<\/a><\/li>\n<li><a href=\"https:\/\/www.digital-chiefs.de\/deloitte-2026-operator-orchestrator-tech-leadership-dach-vorstand\/\" target=\"_blank\" rel=\"noopener\"><strong class=\"mag-dc\">Digital Chiefs:<\/strong> From Operator to Orchestrator &#8211; Deloitte Study 2026 for DACH Boards<\/a><\/li>\n<\/ul>\n\n<p style=\"text-align:right;font-style:italic;color:#888;font-size:0.85em;\">Photo: Pexels \/ cottonbro studio<\/p>\n\n<p style=\"text-align:right;font-style:italic;color:#666;\"><em>Source title image: Wikimedia Commons \/ Wolkenkratzer (CC BY-SA 3.0)<\/em><\/p>","protected":false},"excerpt":{"rendered":"The BSI has been in the operational testing phase since May\u202f2026. This is what the NIS2 enforcement wave means for the 29,500 regulated entities in\u2026","protected":false},"author":8,"featured_media":13800,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"NIS2 Enforcement","_yoast_wpseo_title":"NIS2 Enforcement 2026: BSI Audit Phase & DACH Checklist","_yoast_wpseo_metadesc":"BSI enforcement from May 2026: Fines up to \u20ac10M, mandatory registration, and compliance checklist for NIS2-regulated entities in DACH.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was-dach-unternehmen-bei-der-eigenen-compliance-jetzt-pruefen-muessen-cover-hero.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/05\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was-dach-unternehmen-bei-der-eigenen-compliance-jetzt-pruefen-muessen-cover-hero.jpg","_yoast_wpseo_twitter-image-id":0,"_wp_old_slug":[],"footnotes":""},"categories":[3,251],"tags":[],"class_list":["post-13807","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aktuelles","category-news"],"wpml_language":"en","wpml_translation_of":13796,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13807","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=13807"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13807\/revisions"}],"predecessor-version":[{"id":14925,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13807\/revisions\/14925"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/13800"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=13807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=13807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=13807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}