NIS2
In short: An EU cybersecurity directive that prescribes minimum standards for risk management and reporting obligations for security incidents for companies in certain sectors (including energy, health, digital infrastructure).
In more detail: NIS2 (“Network and Information Security Directive 2”) considerably widens the circle of affected companies compared with its predecessor and obliges operators of “essential” and “important” entities to take technical and organisational security measures and to report significant security incidents within tight deadlines (initial report within 24 hours). Unlike the GDPR (protection of personal data), NIS2 primarily aims at the resilience of critical infrastructure against cyberattacks.
In Depth
NIS2 distinguishes two categories of affected organisations with obligations of differing strictness:
"Essential" entities - e.g. energy, health, transport, banking,
digital infrastructure (stricter control,
proactive supervision)
"Important" entities - e.g. postal/courier services, waste management,
food production (reactive supervision,
only when there's a specific reason)
The required measures include, among other things: risk management concepts for IT security, incident handling (clear processes if something does happen), business continuity planning (how does operation continue in an emergency?), supply chain security (suppliers/service providers also have to be taken into account) and regular training. Management itself explicitly bears responsibility and is personally liable for gross negligence — NIS2 thus deliberately shifts cybersecurity from a pure IT topic to a leadership topic.
The reporting obligation follows a staged procedure: an early warning within 24 hours of becoming aware of a significant incident, a more detailed report after 72 hours, and a final report after one month at the latest. This is considerably more tightly timed than the GDPR’s 72-hour reporting deadline for data breaches — the two sets of rules complement each other but apply to different kinds of incidents (NIS2: operational security in general, GDPR: specifically personal data).
Historical context: from NIS to NIS2
The original NIS directive of 2016 was the first EU-wide cybersecurity regulation of all, but only covered a comparatively narrow circle of critical infrastructure operators and was implemented very differently in the individual member states. NIS2 (adopted in 2022, to be implemented in Germany by the NIS2 Implementation Act) reacts directly to these weaknesses: it massively expands the circle of affected sectors (from originally 7 to more than 15 sectors), harmonises the requirements much more strongly across the EU and considerably tightens the possible sanctions — estimates assume that the number of affected companies in Germany rises through NIS2 from a few hundred to several tens of thousands.
Personal liability of management
A particularly far-reaching aspect of NIS2: management (executive board, managing directors) has to APPROVE and MONITOR the implementation of the cybersecurity measures itself — it can’t fully delegate this responsibility to the IT department. If this duty is grossly negligently neglected, management faces personal liability risks, similar to other compliance areas (e.g. tax law or occupational safety). This explicit leadership responsibility is meant to prevent cybersecurity from being treated as a pure “IT problem” and given low priority in budget decisions.
Fines and supervision
Violations can lead to fines of up to 10 million euros or 2% of worldwide annual turnover for “essential” entities (somewhat lower for “important” entities) — an order of magnitude below the GDPR’s maximum fines, but one that also creates considerable financial pressure. In Germany, the Federal Office for Information Security (BSI) is the central supervisory authority for NIS2, with its own inspection and enforcement powers vis-à-vis affected companies.