{"id":13815,"date":"2026-05-03T09:28:15","date_gmt":"2026-05-03T09:28:15","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/05\/03\/nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was\/"},"modified":"2026-07-09T16:47:43","modified_gmt":"2026-07-09T16:47:43","slug":"nis2-enforcement-2026-bsi-audit-phase-and-dach-checklist","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/05\/03\/nis2-enforcement-2026-bsi-audit-phase-and-dach-checklist\/","title":{"rendered":"NIS2 Enforcement 2026: BSI Audit Phase and DACH Checklist"},"content":{"rendered":"\n<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">6 min. read<\/p>\n\n<p><strong>On April 18, 2026, Belgium&#8217;s first NIS2 enforcement deadline for essential entities expired. In Germany, the BSI registration deadline passed on March 6, 2026. Those who have not registered by then are now under the scrutiny of a supervisory system that imposes fines of up to 10 Mio. EUR or 2 percent of annual turnover and can hold managing directors personally liable. The enforcement wave is no longer a mere threat.<\/strong><\/p>\n\n<div style=\"background:#0\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What NIS2 Requires from Regulated Entities<\/h2>\n<p><strong>What is NIS2?<\/strong> The EU Directive on Network and Information Security (NIS2, Directive 2022\/2555) establishes binding cybersecurity obligations for critical sectors. It replaces the 2016 NIS Directive, significantly expands its scope, and introduces a uniform sanctions regime with personal liability for managers.<\/p>\n<p>The NIS2UmsuCG has been in force since December 6, 2025. The often-cited &#8220;appropriate security&#8221; has now been concretized by the ENISA Technical Implementation Guidance (June 2025) \u2013 this is the difference from older compliance frameworks that allowed more room for interpretation. Anyone arguing they lacked clarity on what exactly needed to be done has a research problem, not a regulatory problem.<\/p>\n<p>Art. 21 NIS2 defines ten categories of measures that a regulated entity must have implemented and documented. ENISA further clarified in Q1 2026: MFA for privileged access, remote access accounts, and vendor accounts is &#8220;practically always appropriate&#8221; \u2013 leaving little room for interpretation through &#8220;where appropriate.&#8221;<\/p>\n\n<div style=\"margin:32px 0;display:flex;flex-wrap:wrap;gap:20px;\">\n<div style=\"flex:1;min-width:220px;background:#f7f7f7;padding:24px;border-radius:8px;\">\n<p style=\"font-weight:700;color:#69d8ed;margin:0 0 14px 0;font-size:0.95em;text-transform:uppercase;letter-spacing:0.06em;\">What Many Already Have<\/p>\n<ul style=\"margin:0;padding-left:18px;line-height:1.7;color:#333;font-size:0.93em;\">\n<li>Firewall and Endpoint Protection<\/li>\n<li>Backup Routine (mostly without recovery test)<\/li>\n<li>Patch Management \u2013 somehow<\/li>\n<li>Antivirus on Endpoints<\/li>\n<li>Basic Password Policy<\/li>\n<\/ul>\n<\/div>\n<div style=\"flex:1;min-width:220px;background:#0a1628;padding:24px;border-radius:8px;\">\n<p style=\"font-weight:700;color:#69d8ed;margin:0 0 14px 0;font-size:0.95em;text-transform:uppercase;letter-spacing:0.06em;\">What Is Typically Missing<\/p>\n<ul style=\"margin:0;padding-left:18px;line-height:1.7;color:rgba(255,255,255,0.85);font-size:0.93em;\">\n<li>Documented Incident Response Plan<\/li>\n<li>ISMS with Risk Register<\/li>\n<li>24h BSI Reporting Process (Contact Point, Escalation Chain)<\/li>\n<li>MFA on All Privileged Accounts<\/li>\n<li>Supply Chain Risk Analysis for IT Service Providers<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">DACH Region&#8217;s Implementation Status<\/h2>\n<p>Germany was one of the last EU members to implement it. The NIS2UmsuCG came into force on December 6, 2025, almost 15 months after the European implementation deadline. Between its adoption and operational BSI enforcement, affected companies had approximately 13 weeks \u2013 less than a quarter \u2013 for risk management setup, documentation, and registration.<\/p>\n<p>Austria adopted the NISG 2026 on December 12, 2025. Effective: October 1, 2026. Affected Austrian companies thus have a short window to establish their compliance foundations before the new supervisory authority \u2013 the Federal Office for Cybersecurity \u2013 enters its operational phase. Scope: approximately 4,000 companies from 18 sectors.<\/p>\n<p>Poland implemented one of the most far-reaching implementations in the EU with the KSC Act on April 3, 2026: 42,000 regulated entities, expanded from previously around 400. This is not a typo. For German-Polish supply chains and nearshoring partners, this means immediate compliance pressure on both sides.<\/p>\n<p>Switzerland: Not an EU member, no direct NIS2 obligation. For Swiss companies acting as IT service providers for NIS2-regulated EU entities\n<h2 style=\"margin-top:48px;margin-bottom:18px;\">What IT Teams Must Check Now<\/h2>\n<p>Five steps cover the most common compliance gaps. None of these points require ISO 27001 \u2013 but all demand written proof.<\/p>\n\n<div style=\"margin:28px 0;counter-reset:steps;\">\n<div style=\"display:flex;gap:16px;margin-bottom:20px;align-items:flex-start;\">\n<div style=\"background:#69d8ed;color:#0a1628;font-weight:800;font-size:1.1em;min-width:36px;height:36px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">1<\/div>\n<div><strong>Check Scope.<\/strong> Does the company fall into one of the 18 NIS2 sectors according to Annex 1 or 2 BSIG? Threshold: from 50 employees OR 10 Mio. EUR annual turnover, combined with sector affiliation. Classification as an &#8220;important&#8221; or &#8220;essential&#8221; entity determines the fine framework.<\/div>\n<\/div>\n<div style=\"display:flex;gap:16px;margin-bottom:20px;align-items:flex-start;\">\n<div style=\"background:#69d8ed;color:#0a1628;font-weight:800;font-size:1.1em;min-width:36px;height:36px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">2<\/div>\n<div><strong>Complete BSI Registration.<\/strong> The deadline expired on March 6, 2026. The BSI has so far indicated leniency, but the leeway is narrowing. Registration in the BSI portal is step one before any further compliance proof becomes relevant.<\/div>\n<\/div>\n<div style=\"display:flex;gap:16px;margin-bottom:20px;align-items:flex-start;\">\n<div style=\"background:#69d8ed;color:#0a1628;font-weight:800;font-size:1.1em;min-width:36px;height:36px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">3<\/div>\n<div><strong>Document Risk Management Measures.<\/strong> The ten categories from Art. 21 NIS2 must be demonstrably implemented. No risk register means, in an audit context: no proof. No full ISO 27001 certification is necessary, but the document must exist.<\/div>\n<\/div>\n<div style=\"display:flex;gap:16px;margin-bottom:20px;align-items:flex-start;\">\n<div style=\"background:#69d8ed;color:#0a1628;font-weight:800;font-size:1.1em;min-width:36px;height:36px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">4<\/div>\n<div><strong>Activate Reporting Process.<\/strong> Who is the BSI contact person in the company? Is there a written escalation chain for the 24h reporting obligation for significant incidents? Know the BSI reporting portal, communicate internally, appoint a responsible person.<\/div>\n<\/div>\n<div style=\"display:flex;gap:16px;margin-bottom:20px;align-items:flex-start;\">\n<div style=\"background:#69d8ed;color:#0a1628;font-weight:800;font-size:1.1em;min-width:36px;height:36px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">5<\/div>\n<div><strong>Evaluate Suppliers.<\/strong> Which IT service providers have direct access to critical systems? Supply chain security is not an optional component but part of the risk analysis. Obtain written security proofs from key suppliers.<\/div>\n<\/div>\n<\/div>\n\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n\n<details><summary><strong>What Qualifies as an &#8216;Essential Entity&#8217; under NIS2?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Essential entities are companies in sectors of high criticality (Annex 1 BSIG) with at least 250 employees or 50 Mio. EUR annual turnover and 43 Mio.\n<h3>The 24-hour Reporting Obligation in Detail<\/h3>\n<p>In the event of a significant security incident &#8211; defined as an incident with considerable impact on the service &#8211; an initial report must be submitted to the BSI within 24 hours. A more detailed assessment follows within 72 hours, and a final report after one month. Reporting is done via the BSI reporting portal. A &#8220;significant incident&#8221; is a term that the BSI will further specify &#8211; when in doubt: report, don&#8217;t wait.<\/p><\/details>\n\n<details><summary><strong>Must Suppliers Themselves Be NIS2-Compliant?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Not necessarily in the form that suppliers themselves must be registered. However, regulated entities are obliged to assess and manage security risks in their supply chain. This means: written evidence of security practices from IT service providers with critical access, minimum contractual requirements, and audit rights. Those who fail to do so bear the liability risk themselves.<\/p><\/details>\n<!--ST-LOWER-CARDS lang=en--><h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/28\/architecture-drives-compliance-costs\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-bsi-kritis-cloud-multi-cloud-compliance-61618487.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Architecture Drives Compliance Costs: How to Cut Them<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/csrd-after-2026-eu-omnibus-who-still-reports-and-what-esrs-relief-means-for-smes\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-csrd-eu-omnibus-2026-berichtspflicht-esr-38916809-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">CSRD Post-2026: Reporting Changes and ESRS Relief for SMEs<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/deloitte-2026-operator-orchestrator-tech-leadership-dach\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-deloitte-2026-operator-orchestrator-tech-80856405-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">From Operator to Orchestrator: What the Deloitte 2026 Study Means for DACH Executives Evaluating Their Tech Leadership<\/span><\/span><\/a><!--\/ST-LOWER-CARDS-->","protected":false},"excerpt":{"rendered":"The BSI has been in the operational testing phase since May 2026. What the NIS2 enforcement wave means for 29,500 regulated entities in Germany.","protected":false},"author":10,"featured_media":13800,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"","_yoast_wpseo_title":"NIS2 Enforcement 2026: BSI Audit Phase and DACH Checklist","_yoast_wpseo_metadesc":"NIS2 enforcement starts May 2026: \u20ac10m fines, registration & compliance checklist required.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was","nis2-enforcement-welle-q2-2026-erste-eu-verfahren-laufen-was-2"],"footnotes":""},"categories":[3,255,259],"tags":[],"class_list":["post-13815","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aktuelles","category-praxis-umsetzung-en","category-strategie-governance-en"],"evm_reading_time_minutes":1,"wpml_language":"en","wpml_translation_of":17967,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13815","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=13815"}],"version-history":[{"count":4,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13815\/revisions"}],"predecessor-version":[{"id":21423,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/13815\/revisions\/21423"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/13800"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=13815"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=13815"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=13815"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}