Comment, News NIS2 implementation law has been passed: When does NIS2 come into effect? - Recommended action

Constantina Budi — 17. Nov 2025
Reading time: 1:19 minutes

Unternehmen aufgepasst: NIS2 ist da – wann geht es los mit NIS2? Hier finden Sie wesentliche Handlungsempfehlungen

On 13 November 2025, the German government's draft bill to implement the NIS 2 Directive was passed. What companies need to do now.

On 13 November 2025, the German Bundestag finally passed the NIS2 implementation law at the German level, which had been rolled out by the EU almost three years ago. It took several rounds of discussions and intensive talks with experts and political representatives. Last week, the German government's draft bill ‘on the implementation of the NIS 2 Directive and the regulation of essential principles of information security management in the federal administration’ was passed within half an hour.

NIS2 Implementation Act now also passed in Germany

NIS2 has been a law applicable throughout the EU since 16 January 2023. Germany did not manage to pass the NIS2 Implementation Act (NIS2UmsuCG) by the deadline of 17 October 2024. Since then, infringement proceedings have been underway, which could result in fines for Germany from the EU as long as the law that has now been passed has not actually come into force – which is expected to happen at the end of 2025, but no later than the beginning of 2026.

The reason for this delay (which can be found in detail at Storage Insider) – and thus also for accepting possible fines from the EU – was the inconsistent decision-making process on how the NIS2 Directive should be implemented at national level. There was significant criticism from experts, including on data protection issues, ambiguities in competences and responsibilities, and exceptions for the concrete implementation of NIS2 in public authorities and administration compared to the private sector, which are now to be balanced out in the final draft law.

NIS2: No longer a blueprint for greater cyber resilience in companies

The law will take effect immediately after its promulgation: After companies have had more than three years to take note of the NIS2 directive and prepare for it, the legislator requires companies and organizations to implement NIS2 on the date it takes effect without any further transition periods, also in light of the urgency of the process of adapting to the EU directive.

Companies should therefore start preparations now. These include obligations such as

  • Comprehensive risk management measures
  • Incident reporting
  • Technical security
  • Corporate governance.

Is my company affected: To whom does NIS2 apply?

The NIS2 Implementation Act (NIS2UmsuCG) affects companies in a wide range of economic sectors, such as healthcare, utilities, transportation, public administration, but also digital infrastructure and manufacturing, with 50 or more employees or annual turnover or balance sheet total of 10 million euros or more. However, NIS2 applies to operators of critical infrastructures (KRITIS) without restriction.

Recommended action: Cyber resilience assessment and step-by-step implementation of NIS2

Start immediately – ideally with a gap analysis to close the gaps between your company's current security standard and the requirements of the NIS2 Implementation Act.

It's even faster with professional help: Our Empalis Cyber Resilience Assessment will quickly and accurately show you how to implement the necessary measures step by step. Feel free to contact us.

Sources

https://www.bundestag.de/dokumente/textarchiv/2025/kw46-de-nis-2-1123138

https://www.bundesregierung.de/breg-de/aktuelles/nis-2-richtlinie-deutschland-2373174

https://www.security-insider.de/nis-2-umsetzung-expertenkritik-a-245704149efbd8e2d66d3da866e58c6e/?cflt=rdt 

https://www.security-insider.de/bundestag-beschliesst-nis-2-umsetzungsgesetz-a-6b67d5b503bf7404553cc5de4f0dbbb0/

Philip Röder, Head of Business Development & Consulting

Do you have questions about NIS2, emergency planning, or the Cyber Resilience Assessment? Feel free to write to me.

Philip Röder, Head of Business Development & Consulting
Phone +49 162 4196789

You were interested in this, then you may also be interested in...