← Back to Blog

NIS2 Compliance Checklist for German Businesses

28.03.2026 · 4 min read ·Nullbreach Team
NIS2ComplianceCybersecurityGermany
Table of Contents

What Is the NIS2 Directive?

The NIS2 Directive (Network and Information Security Directive 2) is the revised EU directive on network and information security. It replaces the original NIS Directive from 2016 and places significantly stricter cybersecurity requirements on companies and organizations across the European Union.

Germany transposed NIS2 into national law in December 2025. An estimated 29,000 German companies are now directly affected — many without knowing it.

Who Is Affected by NIS2 in Germany?

NIS2 applies to organizations in 18 sectors, divided into two categories:

Essential Entities (Wesentliche Einrichtungen)

Important Entities (Wichtige Einrichtungen)

Size thresholds: Companies with 50+ employees OR €10M+ annual revenue in these sectors are generally covered. Some critical entities are covered regardless of size.

The Complete NIS2 Compliance Checklist

1. Determine If You're Affected

2. Governance & Leadership Responsibility

3. Risk Management (Article 21)

NIS2 Article 21 requires measures across 10 categories:

4. Incident Reporting

NIS2 mandates strict reporting timelines:

5. Technical Security Measures

6. Dark Web & Breach Monitoring

Nullbreach provides automated dark web monitoring, breach detection, and NIS2 compliance reporting. Start your free scan →

7. Supply Chain Security

8. Documentation & Evidence

Penalties for Non-Compliance

NIS2 introduces significant penalties:

Entity Type Maximum Fine
Essential entities €10 million or 2% of global annual revenue
Important entities €7 million or 1.4% of global annual revenue

Additionally, management can be held personally liable and temporarily suspended from executive functions.

Timeline

Date Milestone
December 2025 NIS2 transposed into German law
Q1 2026 BSI begins registration process
Q2 2026 First compliance audits expected
Ongoing Continuous compliance required

How Nullbreach Helps with NIS2 Compliance

Nullbreach covers several NIS2 Article 21 requirements out of the box:

Check your NIS2 readiness →

Conclusion

NIS2 is not optional. With penalties up to €10 million and personal liability for directors, German businesses must act now. Start with this checklist, implement the required measures systematically, and use automated tools like Nullbreach to maintain continuous compliance.

Start your free security scan →

Protect your business — try Nullbreach free

Dark web monitoring, breach detection and NIS2 compliance in one platform.

Start Free Scan