NIS2
Safe on paper. In a real incident?
NIS2 asks for more than documents: risk management that works when it matters. Business continuity is part of it: backups, recovery and crisis management.
Two countries, two laws
Germany
- The NIS2 implementation act (NIS2UmsuCG) has applied since 6 December 2025.
- The BSI handles registration, reporting and supervision.
- Operators of critical facilities also fall under the KRITIS umbrella act for physical resilience.
Denmark
- The Danish NIS 2 Act has applied since 1 July 2025.
- Supervision lies with the competent authority of each sector.
- If you operate or deliver in both countries, you need both legal frameworks in view.
Three possible outcomes
Directly in scope
Your sector and size put you under NIS2. Registration, risk management, reporting and management training are mandatory.
Indirectly in scope
You are not covered yourself, but your customers are. They will ask about your resilience through contracts and questionnaires.
Not in scope
Then the question remains whether your business survives a longer outage. The answer is worth having even without a law.
Frequently asked questions
We have fewer than 50 employees. Does this apply to us?
Usually not directly. The threshold is generally 50 employees or more than 10 million euros in turnover and balance sheet. Some sectors are covered regardless of size, and you can be in scope indirectly through your customers.
What are the penalties?
The directive provides for fines of up to 10 million euros or 2 percent of worldwide annual turnover for essential entities, and up to 7 million euros or 1.4 percent for important entities. Management is also personally accountable.
Is an ISO 27001 ISMS enough?
It is a good foundation. Business continuity, crisis management and tested recovery are often missing, or exist only on paper.
Clarify whether you are in scope in one meeting.
See the readiness check