IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

With the Indicium report, compliance teams document the reliability of key personnel before access is granted: registry data, sanctions and adverse media with dated sources and human final review.

NIS2 Compliance in Germany: Who Is Affected, What Applies, When

NIS2 compliance in Germany since 6 December 2025: who qualifies under § 28 BSIG, registration after the 6 March 2026 deadline, core duties and fines.

NIS2 has been binding national law in Germany since 6 December 2025: organisations qualify as besonders wichtige or wichtige Einrichtungen under § 28 BSIG on the basis of sector plus size, must register with the BSI within three months, and no general transition period applies.

What the NIS2UmsuCG changed

The NIS2UmsuCG transposes Directive (EU) 2022/2555 into German law, 14 months after the EU deadline of 17 October 2024. Promulgated in BGBl. 2025 I Nr. 301, it entered into force on 6 December 2025 with no general transition period; the duties apply immediately. Practitioners call the result BSIG n.F., the recast Act on the Federal Office for Information Security.

Scope is the headline change: a BSI estimate, reported via Handelsblatt and the IDW knowledge paper, puts the count at around 29,500 regulated entities, up from roughly 4,500 in the KRITIS era.

Who is affected by NIS2 in Germany?

Scope follows § 28 BSIG, which distinguishes two regulated categories plus a residual group, and no authority announces the classification: the BSI does not notify organisations, so entities self-assess (BSI FAQ).

Besonders wichtige Einrichtungen (§ 28(1)) cover operators of critical facilities, qualified trust service providers, and operators of TLD registries or DNS service providers, each regardless of size; telecom operators with at least 50 employees or turnover and balance sheet each above 10 million euros; and every other Anlage 1 entity with 250 employees, or turnover above 50 million euros and a balance sheet above 43 million euros.

Wichtige Einrichtungen (§ 28(2)) cover non-qualified trust service providers, small telecommunications operators (fewer than 50 employees and at most 10 million euros), and all other entities in an Anlage 1 or Anlage 2 activity with at least 50 employees, or turnover and balance sheet each above 10 million euros. Below both thresholds sit the other entities; they too self-assess.

Anlage 1 lists seven sector groups: energy, transport and traffic, finance, health, water, digital infrastructure and space. Anlage 2 adds postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research, often compressed into “18 sectors”. Health shows how far the net reaches: pharmacies count as health service providers, and a Bundesärztekammer estimate puts roughly 800 MVZ and 200 association practices newly in scope.

Two boundary rules matter: § 28(3) lets negligible (“vernachlässigbar”) activities be disregarded, and § 28(6) carves DORA-regulated financial entities out of the core duties. Operators of critical facilities should also note the KRITIS-Dachgesetz, which applies in parallel with its own deadlines: our article on the KRITIS framework act.

Must you still register after the 6 March 2026 deadline?

Yes, and this is where many entities stand today. § 33 BSIG requires registration within three months of first becoming a particularly important or important entity. The portal has been live since 6 January 2026, and the statutory deadline for entities already in scope expired on 6 March 2026. Practitioner reporting described a grace period running to 31 July 2026. Count that window or not: the duty has not lapsed.

Late registration remains mandatory and separately sanctionable, with fines of up to 500,000 euros, and § 33(3) allows the BSI to substitute the registration itself if an entity fails to act. The sequence is unchanged: assess your status under § 28, document it, register, keep the portal data current. Our readiness checklist poses ten questions that expose an organisation’s real status.

The core duties under sections 28 to 32 BSIG

§ 30 BSIG anchors risk management: entities must take proportionate technical and organisational measures to protect the availability, integrity and confidentiality of the systems they use to deliver services. § 30(2) names ten minimum measure areas: risk analysis and IT security concepts; incident handling; business continuity, backup and crisis management; supply-chain security; security in acquisition, development and maintenance, including vulnerability handling; effectiveness evaluation; training and awareness; cryptography concepts; personnel security, access control and asset management; multi-factor authentication and secured communications. § 30(1) sentence 3 adds a documentation duty, which the BSI compares to GDPR accountability (Art. 5(2)). Measures that cannot be shown leave the duty unmet.

§ 32 BSIG adds the incident-reporting duty: significant incidents must reach the BSI through a staged process with fixed clocks, covered in our article on NIS2 incident reporting.

Supervision differs by category: § 61 BSIG gives besonders wichtige Einrichtungen proactive, ex-ante supervision, § 62 reactive supervision for wichtige Einrichtungen, which may be asked to demonstrate their framework before any incident occurs.

What penalties and what management liability does NIS2 bring?

§ 65 BSIG sets the fine architecture. Core violations, including risk-management and reporting failures, carry caps of 10 million euros for besonders wichtige and 7 million euros for wichtige Einrichtungen; above a global annual turnover of 500 million euros a turnover-based cap applies in addition, and the higher amount governs (§ 65(6) and (7)). Missed registration sits in its own tier, with fines of up to 500,000 euros.

§ 38 BSIG turns oversight into personal responsibility. Management must implement and monitor the § 30 measures and attend regular cybersecurity training (§ 38(3)). Liability follows general company law: managers answer for culpably caused damage. Cybersecurity is a board agenda item with named accountable individuals, not a delegated IT topic.

Personnel security as part of risk management

The systems § 30(1) protects are most easily harmed by people holding legitimate access. § 30(2) Nr. 9 therefore requires concepts for personnel security, access control and the administration of ICT systems, products and processes: personnel is a risk vector in its own right.

Operationally, the duty means verifying people before access is granted and calibrating depth to the access level: need-to-know and least privilege are the reference points, role changes and departures part of the concept. Where Commission Implementing Regulation (EU) 2024/2690 applies under § 30(3) BSIG, Annex point 10 concretises it: recruitment conditions, screening of personnel, termination handling, surviving confidentiality obligations and a documented disciplinary process. Recital (22) is the EU’s citable basis for background screening: reliability checks can include querying a criminal record or reviewing past professional performance, where appropriate to the tasks.

Employee background verification is the evidence-producing measure: registry data, sanctions lists, adverse media and employment history from public sources, finished with human review. Indicium structures this step with dated sources and human final review, so the decision is documented and reviewable. Screening remains a proportionate measure within a concept duty, not an automatic mandate for every employee; it maps to ISO/IEC 27001:2022 A.6.1, employment terms to A.6.2, termination to A.6.5.

The operational depth sits in our article on personnel security under § 30 BSIG.

Frequently asked questions

Who is affected by NIS2 in Germany?

Entities active in a sector listed in Anlage 1 or Anlage 2 BSIG that meet the size thresholds of § 28. For wichtige Einrichtungen the mark is 50 employees, or turnover and balance sheet each above 10 million euros; higher thresholds and several size-independent categories, such as operators of critical facilities and DNS providers, produce the besonders wichtige rank. Every entity self-assesses.

From how many employees does NIS2 apply?

The 50-employee mark is the common trigger: in an Anlage 1 or Anlage 2 activity it makes an entity a wichtige Einrichtung even without turnover. From 250 employees in an Anlage 1 activity, or with turnover above 50 million euros and a balance sheet above 43 million euros, the entity ranks as besonders wichtig. Several categories count regardless of headcount.

Do you still have to register with the BSI even though the deadline expired on 6 March 2026?

Yes. The deadline of 6 March 2026 has passed and the communicated grace period ended on 31 July 2026, but late registration remains mandatory and separately sanctionable, with fines of up to 500,000 euros. § 33(3) also lets the BSI substitute the registration. Register now and document the § 28 assessment.

Does NIS2 apply to banks and insurers despite DORA?

Financial entities fully regulated under DORA are exempt from the core duties under § 28(6) BSIG, specifically from §§ 30, 31, 32, 35, 36, 38 and 39; their personnel-security expectations follow DORA’s own rules. Entities outside full DORA scope, including critical-facility operators, health entities and energy companies, remain within the BSIG.

This article gives general orientation on NIS2 and does not constitute legal advice; for a binding assessment of your obligations, consult qualified counsel.

Ready to move from reading to doing?

See how a reviewable risk report is built – from name to verdict in minutes, not weeks.

Book a demo See a sample report