All articlesNIS2 · Governance

NIS2 is in force: five things management boards must settle now

Germany’s NIS2 implementation act (the NIS2UmsuCG) has been in force since 6 December 2025. That shifts the question from when the new duties arrive to whether your organisation actually meets them today. The BSI, Germany’s federal cyber security authority, estimates that roughly 29,500 companies fall under the amended BSIG, many of them mid-sized businesses that have never dealt with cyber regulation before.

Two dates are already behind us. The registration deadline with the BSI expired on 6 March 2026, and the BSI’s reporting and contact-point portal (MUK) has been in full operation since 1 June 2026. An organisation that is still planning instead of executing is not vaguely late; it is formally in default. The workload, though, condenses into five points a management board can genuinely own.

1. Establish scope, and register late rather than never

The first step is unglamorous and overdue: determine whether your organisation qualifies as an essential or important entity under the amended BSIG, and complete the BSI registration immediately if it is still missing. The deadline passed on 6 March 2026, which makes registration urgent, not obsolete. Registering now corrects a default; waiting extends one that a supervisor will later find on file.

2. Read §38 BSIG: it is addressed to you, personally

§38 BSIG is not written for the IT department or the information security officer. It is written for managing directors and board members, and it assigns three duties that cannot be delegated away:

  • Approve: the management body must itself approve the cybersecurity risk-management measures required by §30 BSIG; a signature under a concept nobody at the table can explain will not carry far.
  • Oversee: it must monitor the implementation of those measures, continuously, not as a one-off resolution.
  • Train: its members must take part in training on a regular basis, so they can actually judge risks and the adequacy of the measures.

The lever behind all three: §38 BSIG provides for the liability of the management body where these duties are breached. In substance, this is Germany spelling out the governance duties of the NIS2 Directive in national law, and it turns cyber risk into a matter of directors’ duties, with everything that implies for board meetings, D&O conversations and personal diligence.

3. Build crisis management: §30 BSIG asks for more than technology

§30 BSIG obliges covered entities to implement risk-management measures and explicitly counts business continuity and crisis management among them. Firewalls and patch cycles do not satisfy that paragraph. What it demands is an organisation that holds up in a real incident: a crisis team with defined roles and deputies, alerting paths that work at night, recovery priorities set by the business rather than by IT alone, and the ability to communicate internally and externally when the usual channels are down.

Much of this already exists in most companies, on paper. Which is exactly the problem point five is about.

4. Prepare the reporting chain to the BSI

For significant incidents, §32 BSIG requires a three-stage notification to the BSI. The clock starts when you become aware of the incident, not when the chaos is over:

StageDeadlineCore content
Early warningwithin 24 h of awarenessfirst notice to the BSI via the MUK portal (fully operational since 1 June 2026)
Incident notificationwithin 72 h of awarenessupdate of the early warning with an initial assessment of severity and impact
Final reportwithin 1 monthdetailed description of the incident, its cause, and the countermeasures taken

Preparation means answering four questions in advance: who judges whether an incident is significant, who drafts the early warning, who holds the portal credentials, and who stands in for each of them during the holidays. On the day itself, these four answers decide between on time and late.

5. Exercise, because paper proves nothing

The common thread through points two to four: each duty eventually requires evidence. And this is where the playbook parts ways with the defensible proof. A crisis manual documents an intention; whether alerting paths work, deputies step in and the management board stays decision-capable under time pressure is only revealed by a practical test. Germany’s own reference standards say as much: BSI Standard 200-4 is the national benchmark for business continuity management, and the IT-Grundschutz emergency-management course devotes a chapter of its own to rehearsing emergencies.

For a management board, an exercise pays twice. First, it is the most effective training format there is: deciding on a ransom demand, a customer escalation and a 24-hour early warning at the same time, on a running clock, teaches more about your crisis management than any slide deck. Second, a documented exercise produces exactly the evidence §38 BSIG asks for: timestamps showing which decisions the board took, when, and on what basis. Training record and oversight record in one artefact.

The sequence, then, is clear: complete the registration, fix responsibilities and the reporting chain, stand up the crisis organisation, and then prove that it works. Not on paper, but in a live run.

Keep reading

Turn reading into rehearsal.

A live exercise shows in 90 minutes what no article can: how your team actually decides under pressure.