Industries in Focus

NIS-2 in practice: What management boards must do specifically now

NIS-2 in practice: What management boards must do specifically now

NIS-2 in practice: What management boards must do specifically now

Last updated:

8 min.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

Based on the research work of Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann

It is no longer a question of if, but when: the NIS-2 Implementation Act is coming – with no transitional periods. Any managing director or board member who believes that cybersecurity continues to be a matter for the IT department is sorely mistaken and risks personal liability.

The EU Directive NIS-2 (Network and Information Security 2, EU 2022/2555) requires companies to adopt a fundamentally different approach to IT security: cybersecurity becomes a management task with a statutory basis, personal responsibility, and severe sanctions. In Germany, the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) implements these requirements – the cabinet draft was sent to the Bundestag in autumn 2025, and adoption is expected shortly. This article explains what that means in concrete terms.

What is NIS-2 and who does it affect?

NIS-2 is the revised EU directive on network and information security. It replaces the first NIS Directive of 2016 and significantly expands its scope. The goal is a high, uniform level of cybersecurity across the EU.

The most important difference compared to the predecessor version: NIS-2 covers significantly more companies than before. While the old framework was primarily tailored to explicit operators of critical infrastructure (KRITIS), numerous other companies now also fall under its scope. Several tens of thousands of firms in Germany will fall under the new BSI Act (BSIG) in the future – including many that were previously not regulated (Teichmann, NIS2-Schulungspflicht der Geschäftsleitung – Regulatorische Grauzonen und nationale Umsetzung, Computer und Recht 2025, pp. 718–725).

The law distinguishes between two categories. Highly critical entities – so-called essential entities – are larger companies in critical sectors such as energy, transport, banking, health, water supply, and digital infrastructure. Other critical entities – important entities – are medium-sized companies in broader sectors such as postal services, waste management, chemicals, food, manufacturing, and digital providers.

As a rule of thumb: companies in the specified sectors with more than 50 employees or an annual turnover of more than 10 million euros should urgently check whether they are affected. The BSI offers an online check tool for this purpose. It is also important to note that group-affiliated IT service providers that provide essential services to affected parent companies can themselves fall under the scope of application (Teichmann, Computer und Recht 2025, pp. 718–725).

The paradigm shift: Cybersecurity is now a matter for the bosses

The core principle of NIS-2 is: Corporate management is personally responsible. This is not a responsibility that can be delegated to the head of IT or an external service provider.

Section 38 of the draft BSIG explicitly obliges corporate management of essential and important entities to approve and monitor technical and organizational cybersecurity measures, to regularly participate in training in the area of IT security, and to assume personal liability in the event of infringements.

Teichmann emphasizes that this does not represent a fundamental break with existing law, but rather brings a decisive focus and tightening: for the first time, cybersecurity is explicitly regulated as a management task (Teichmann, Cybersicherheit als Führungsaufgabe: Die BSI-Handreichung zur NIS-2-Schulungspflicht, Betriebs-Berater 2026, pp. 74–77). What was previously only body-liability-based, derivable from general management liability norms such as Section 43 of the GmbHG and Section 93 of the AktG, is now written in black and white in the law. Managing directors who neglect the implementation of NIS-2 measures face not only fines against the enterprise – they are also personally liable, and the company can seek recourse (Teichmann, Strafbare Non-Compliance: Persönliche Haftung von Geschäftsleitern und Organen bei Verstößen gegen die NIS2-Richtlinie, CyberStR 2026, pp. 65–73).

The five central duty areas

Risk management is the first and fundamental duty area. Companies must implement appropriate, proportionate technical and organizational measures to manage security risks. These include concepts for risk analysis and information security, measures for handling security incidents, a functioning business continuity management system with backup and emergency concepts, active protection of the supply chain, as well as regular training and awareness-raising of employees. The standard is not perfect security, but the state of the art in conjunction with an appropriate cost-benefit ratio. The typical benchmark is ISO/IEC 27001 (Teichmann, Auswirkungen der EU-NIS-2-Richtlinie auf Unternehmen, ZWH 2026, pp. 6–11).

Reporting obligations form the second duty area and are particularly demanding in practice. NIS-2 introduces a strict 24-hour reporting obligation for significant security incidents. An incident is significant if it has caused, or is capable of causing, severe operational disruption or significant financial loss. The reporting process operates in three stages: an initial warning must be sent to the BSI within 24 hours, a complete incident notification with an initial assessment within 72 hours, and a final report must be submitted within one month. Anyone who reports too late or fails to report at all risks substantial fines. Companies therefore need functioning internal detection and escalation processes to ensure that relevant incidents reach management level in good time (Teichmann, Die neue 24-Stunden-Meldepflicht für Cyberangriffe nach ISG, Jusletter, 29 September 2025).

The management training obligation is the actual novelty of NIS-2. Board members and managing directors must regularly participate in cybersecurity training. The explanatory memorandum of the act specifies "regularly" as at least once every three years. Furthermore, the BSI recommends adjusting this frequency based on risk – a sooner training is advisable in the event of a change in management, changed business processes, or an elevated threat situation. In terms of content, according to the BSI guidance of 30 September 2025, training must cover at least the basics of NIS-2 and the personal obligations of management, methods for risk detection and assessment, the significance of technical and organizational protection measures, and the legal consequences of breaches of duty. In-depth IT expert knowledge is not required – but a solid understanding of what cyber risks mean for one's own company and how to steer against them as a leader is. Trainings must be documented and proven to the BSI upon request (Teichmann, Cybersicherheit als Führungsaufgabe, BB 2026, pp. 74–77).

Supply chain responsibility is the fourth duty area and is frequently underestimated in practice. NIS-2 requires companies to actively manage the security of their entire supply chain. Service providers, software suppliers, and other third parties with access to IT systems must be included in the risk assessment. Contractual clauses, security audits, and concrete security requirements for suppliers are therefore not optional, but a legal duty (Teichmann, IT-Sicherheit in der Lieferkette, Der Betriebswirt 2024, pp. 251–265).

The sanctions make it clear that the legislature is serious. Highly critical entities risk fines of up to 10 million euros or 2% of total worldwide annual turnover – whichever is higher. For other critical entities, it is up to 7 million euros or 1.4% of annual turnover. In addition, some national implementation laws provide for the possibility of a temporary suspension of management personnel. Furthermore, there is the personal internal liability of management towards their own company (Teichmann, Strafbare Non-Compliance, CyberStR 2026, pp. 65–73).

No transitional period: Why action must be taken now

A common misconception must be cleared up: the NIS-2 Implementation Act will enter into force without any transitional periods. On the day after publication in the Federal Law Gazette, all obligations apply. Anyone who has not taken measures by then faces immediate risk.

Teichmann explicitly warns: companies must prepare now, as no transitional periods are provided for (Teichmann, Computer und Recht 2025, pp. 718–725). The delay in the legislative process – NIS-2 should originally have been implemented by October 2024 – should not be understood as an all-clear, but as preparation time gained. Those who utilize this time will gain a real head start.

What already applies today: Management liability

Irrespective of NIS-2, the following already applies today: Managing directors and board members who culpably neglect IT security act in breach of duty under Section 43 of the GmbHG and Section 93 of the AktG, respectively. General leadership responsibility includes the duty to ensure appropriate risk management – cyber risks included. Anyone who, despite warning signs, fails to introduce an incident response concept, rejects necessary security investments, or ignores available security standards exposes themselves to the danger of personal internal liability. In Teichmann’s words: it would not be a dutiful exercise of discretion if management decided against appropriate IT security management (Teichmann, Cybersicherheit als Führungsaufgabe, BB 2026, pp. 74–77).

NIS-2 defines and tightens this already existing responsibility. Anyone aligning themselves with the NIS-2 requirements today is therefore not only protecting themselves against future sanctions – they are also fulfilling their statutory duties as corporate management today.

Interactions with other regulations

NIS-2 does not stand alone. In the financial sector, DORA requirements (Digital Operational Resilience Act) have been in force since January 2025, which, as a more specific body of law, largely override NIS-2 requirements. Banks, insurance companies, and investment firms must use DORA as their primary framework (Teichmann, Digital Operational Resilience Act – EU-weit einheitliche IT-Sicherheitsregeln für Finanzinstitute, BB 2025, pp. 2760–2770). Manufacturers of connected products will also face the requirements of the Cyber Resilience Act (CRA) from 2027, which elevates cybersecurity to a binding product feature (Teichmann, Cybersicherheit als Produkteigenschaft, NJW 2025, pp. 2577–2582). And since data protection violations frequently accompany cyber incidents, reporting obligations under NIS-2 and GDPR must be coordinated – parallel reporting to the BSI and the data protection authority is possible and should be planned for in practice.

Conclusion: Cybersecurity as a strategic advantage

NIS-2 is not a peripheral bureaucratic agenda – it represents a fundamental shift in the legal responsibility of corporate management for cybersecurity. The message from Teichmann's extensive research is clear: anyone waiting until the law enters into force acts too late.

However, those who view cybersecurity not as a mere cost obligation, but as a strategic advantage, gain more than compliance: trust among customers, better insurance terms, competitive advantages in public contracts, and a more resilient organization that can withstand even a serious cyberattack. The scholarly support for this approach exists – and it is clear.

All sources refer to published academic contributions by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in his publication index (as of May 2026).

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

We use cookies to improve your experience. By continuing, you agree to our cookie policy.