On 13 November 2025, the German Bundestag finally passed the NIS2 implementation law at the German level, which had been rolled out by the EU almost three years ago. It took several rounds of discussions and intensive talks with experts and political representatives. Last week, the German government's draft bill ‘on the implementation of the NIS 2 Directive and the regulation of essential principles of information security management in the federal administration’ was passed within half an hour.
NIS2 Implementation Act now also passed in Germany
NIS2 has been a law applicable throughout the EU since 16 January 2023. Germany did not manage to pass the NIS2 Implementation Act (NIS2UmsuCG) by the deadline of 17 October 2024. Since then, infringement proceedings have been underway, which could result in fines for Germany from the EU as long as the law that has now been passed has not actually come into force – which is expected to happen at the end of 2025, but no later than the beginning of 2026.
The reason for this delay (which can be found in detail at Storage Insider) – and thus also for accepting possible fines from the EU – was the inconsistent decision-making process on how the NIS2 Directive should be implemented at national level. There was significant criticism from experts, including on data protection issues, ambiguities in competences and responsibilities, and exceptions for the concrete implementation of NIS2 in public authorities and administration compared to the private sector, which are now to be balanced out in the final draft law.
NIS2: No longer a blueprint for greater cyber resilience in companies
The law will take effect immediately after its promulgation: After companies have had more than three years to take note of the NIS2 directive and prepare for it, the legislator requires companies and organizations to implement NIS2 on the date it takes effect without any further transition periods, also in light of the urgency of the process of adapting to the EU directive.
Companies should therefore start preparations now. These include obligations such as
- Comprehensive risk management measures
- Incident reporting
- Technical security
- Corporate governance.
Is my company affected: To whom does NIS2 apply?
The NIS2 Implementation Act (NIS2UmsuCG) affects companies in a wide range of economic sectors, such as healthcare, utilities, transportation, public administration, but also digital infrastructure and manufacturing, with 50 or more employees or annual turnover or balance sheet total of 10 million euros or more. However, NIS2 applies to operators of critical infrastructures (KRITIS) without restriction.
Recommended action: Cyber resilience assessment and step-by-step implementation of NIS2
Start immediately – ideally with a gap analysis to close the gaps between your company's current security standard and the requirements of the NIS2 Implementation Act.
It's even faster with professional help: Our Empalis Cyber Resilience Assessment will quickly and accurately show you how to implement the necessary measures step by step. Feel free to contact us.
Sources
https://www.bundestag.de/dokumente/textarchiv/2025/kw46-de-nis-2-1123138
https://www.bundesregierung.de/breg-de/aktuelles/nis-2-richtlinie-deutschland-2373174
https://www.security-insider.de/nis-2-umsetzung-expertenkritik-a-245704149efbd8e2d66d3da866e58c6e/?cflt=rdt
https://www.security-insider.de/bundestag-beschliesst-nis-2-umsetzungsgesetz-a-6b67d5b503bf7404553cc5de4f0dbbb0/
Do you have questions about NIS2, emergency planning, or the Cyber Resilience Assessment? Feel free to write to me.
Philip Röder, Head of Business Development & Consulting
Phone +49 162 4196789