77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
NIS-2 for SMEs: Threshold, exceptions and the operational path for SMEs
IT Security & NIS-2

NIS-2 for SMEs: Threshold, exceptions and the operational path for SMEs

11 August 202614 min readBy Lena Vogt
CIVAC

Not every SME is affected by NIS 2, but the threshold of 50 employees and 10 million euros in annual sales already applies to medium-sized businesses in eleven sensitive sectors. This analysis organises sectors, obligations, deadlines and operational implementation with CIVAC.

The law implementing the NIS 2 directive in Germany (NIS2UmsuCG) was passed on October 17, 2024 and is aimed at around 29,500 companies, significantly more than the around 2,000 KRITIS operators under the old NIS 1 regime. In 2026, the most common question among supervisory boards and management of medium-sized companies is no longer whether, but when exactly the NIS 2 obligation applies and which requirements from Section 30 ff. of the BSI Act must specifically be implemented in a company with 80, 120 or 240 employees.

This article does not focus on the regime in general, because that is what the CIVAC NIS-2 primer page. He answers the SME-specific question: How does the threshold of 50 employees and 10 million euros annual turnover combine with the sector list, when is an SME an important or essential institution, what exceptions are there, what obligations arise from day one, and what does the operational path look like without a 200-person medium-sized company having to set up its own cybersecurity department. CIVAC operates as a compliance platform and officer-as-a-service.

Key Takeaways

  • NIS-2 covers SMEs with 50 or more employees and an annual turnover of 10 million euros in eleven sensitive sectors; The small exception according to Article 2 Paragraph 2 NIS-2 only applies below this threshold and not for providers of public electronic communications or trust services.
  • Essential facilities with 250 employees or 50 million euros in sales are threatened with fines of up to 10 million euros or 2% of group sales; important institution with up to 7 million euros or 1.4%.
  • The 24/72 reporting path according to Section 32 of the BSI Act, the risk analysis according to Section 30 and the compulsory training of management are mandatory from day 1, with no transition period for the requirements themselves.

Threshold and sector list: Who is actually covered

The scope of application of the NIS 2 directive and its German implementation in the BSI law is based on two criteria that must be met cumulatively. Firstly, the company must belong to one of the sectors listed in Annex I or Annex II of the NIS 2 Directive, in Germany reflected in Section 28 of the BSI Act. Secondly, the employee and turnover threshold according to Article 2 Paragraph 1 NIS-2 in conjunction with the SME Recommendation 2003/361/EC must be exceeded: at least 50 employees or more than 10 million euros in annual turnover and annual balance sheet total.

The sector list includes energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, Space and, among the important institutions, postal and courier services, waste management, chemicals, food, manufacturing (with subgroups such as medical devices, mechanical engineering, electrical engineering, motor vehicles), digital providers and research institutions. This means that eleven sectors are defined as essential facilities and six as essential facilities; The division has direct consequences for fines.

Medium-sized mechanical engineers, medical device manufacturers, chemical companies, IT service providers and food producers with 50 or more employees fall into the scope of application if they have sales and balance sheet totals exceeding 10 million euros. A small SME exemption under Article 2(2) NIS-2 only applies below this threshold and does not apply to public electronic communications providers, trust services, top-level domain registries, DNS services or the sole service providers of a Member State; these are recorded regardless of size.

Essential vs. important: The two categories and their consequences

NIS-2 divides facilities into two categories. Essential Annex I entities operate in the energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management (B2B), public administration and space sectors and typically exceed the medium size range (250 employees, €50 million in turnover or €43 million in total assets). Important facilities according to Annex II include the remaining sectors plus all essential facilities below the medium size class.

The consequence is within the framework of fines. According to Section 60 of the BSI Act, essential facilities can be fined up to 10 million euros or 2 percent of the previous year's global turnover, and important facilities can be fined up to 7 million euros or 1.4 percent. In addition, there is the personal responsibility of the management: Section 38 of the BSI Act requires that members of the management approve risk management measures, monitor their implementation and take part in training. Violations of this supervisory obligation can also be punished personally against the management in accordance with Section 130 OWiG.

Supervision is distributed asymmetrically. Essential facilities are subject to proactive supervision by the BSI with on-site inspections, security audits and authority to issue instructions. Important institutions are subject to reactive supervision; the BSI takes action when tipped off or reported. The registration requirement according to Section 33 of the BSI Act applies equally to both categories and had to be completed by the end of the transition period. The ISB role at CIVAC is tailored to this asymmetry.

Obligations according to Section 30 of the BSI Act in detail

Section 30 of the BSI Act defines the minimum risk management measures that each affected institution must implement. The list covers ten subject areas: concepts for risk analysis and security in information technology, management of security incidents, continuity of operations including backup management and crisis management, security of the supply chain including security-related aspects of relationships with vendors and service providers, security in the acquisition, development and maintenance of network and information systems.

Next: concepts and procedures for assessing the effectiveness of risk management measures, basic cyber hygiene and training, concepts and procedures for the use of cryptography and encryption, security of the Personnel, concepts for access control and asset management, as well as the use of solutions for multi-factor authentication or continuous authentication, secured voice, video and text communication as well as secured emergency communication systems.

For an SME with 80 to 250 employees, these obligations can practically only be mapped via a structured information security management system (ISMS), ideally in accordance with ISO/IEC 27001:2022 with its 93 controls. Building from scratch typically takes 12 to 18 months. With the CIVAC workspace, which delivers the 93 controls as preconfigured modules with audit templates, the setup is shortened to 4 to 6 months. Audit-proof, documented, § 30-proof.

The 24/72 reporting path according to Section 32 of the BSI Act

Section 32 of the BSI Act prescribes a three-stage reporting path for significant security incidents. Level one: an early warning to the BSI without undue delay, at the latest within 24 hours of becoming aware of the incident. Stage two: an incident report with an update of information, including an initial assessment of the incident, its severity and impact, as well as indicators of compromise, no later than 72 hours after becoming aware of it. Stage three: a final report no later than one month after the incident was reported.

Deadline expires as soon as we become aware of it. In Section 32 Paragraph 6 of the BSI Act, the concept of knowledge is linked to the point in time from which the facility becomes aware of a significant security incident within the meaning of Section 32 Paragraph 5. Significant is an incident that has caused or may cause a serious operational disruption, or has caused or may cause financial losses, or has or may affect other natural or legal persons through significant material or immaterial damage.

The path must exist before the first incident, not be practiced in the incident. CIVAC delivers the 24/72 reporting path as a workflow in the workspace with escalating deadline counters, ready-made BSI-compliant reporting templates and escalation logs to management. The auditor calls, the evidence is ready. Licence the workspace for your internal representatives, or have our representatives order it.

Management obligations according to Section 38 of the BSI Act

Section 38 of the BSI Act tightens the personal responsibility of management in four points. First, senior management must approve the cybersecurity risk management measures to be taken. Second, they must monitor their implementation. Thirdly, they may be held responsible for breach of these obligations in accordance with the applicable legal provisions, without affecting the responsibility of the legal entity. Fourth, they must regularly participate in training and offer comparable training for their employees.

The training requirement is not a one-time compliance appointment. Section 38 (3) requires recurring training with documented evidence. Content typically includes identifying risks, assessing cybersecurity risk management practices and their impact on the services provided by the facility. According to Section 64 of the BSI Act, the supervisory authority can order that management be temporarily excluded from carrying out their management tasks in the event of violations.

The consequence is uncomfortable for SMEs: management cannot hide behind an information security officer. The ISB appointment is not a prerequisite for personal responsibility, but rather facilitates it. CIVAC documents management's training participation in the workspace with date, learning objective and certificate. The appointment certificate, signed, filed, verifiable.

Supply Chain Security: The Underrated Duty

Section 30 Paragraph 2 No. 4 BSI Act requires measures to ensure the security of the supply chain, including security-related aspects of relationships with providers and service providers. For SMEs, this means a risk analysis of their own suppliers and IT service providers and an assessment of their cybersecurity practices. The requirement is not just conceptual, but operational: contracts must contain security requirements, audits must be agreed upon, incidents at suppliers must be included in the company's own reporting system.

The interaction with the Supply Chain Due Diligence Act (LkSG) is relevant. LkSG focuses on human rights and the environment, NIS-2 on cybersecurity; Both regimes use similar instruments (risk analysis, contractual clauses, complaint system, report) and can be mapped in a consolidated process. Medium-sized companies with 200 to 1,000 employees, which will be subject to the LkSG from 2024, have a scale advantage here.

In concrete terms, this means: cybersecurity requirements in order processing contracts (Art. 28 GDPR), in framework contracts with IT service providers (Microsoft, Salesforce, AWS) and with OT suppliers (SCADA, MES, ERP). The requirements must be measurable: patch latency, incident response SLA, ISO/IEC 27001:2022 certification of the provider, subcontractor transparency. CIVAC provides templates for 37 audit scenarios and a supplier risk matrix as a module in the workspace.

Deadlines, registration and transitional regulations

The NIS2UmsuCG does not provide for a transition period for the material requirements from Section 30 of the BSI Act. The obligations apply from the date of entry into force. The registration requirement according to Section 33 of the BSI Act had to be fulfilled within three months of its entry into force; The BSI has set up an electronic reporting portal for this purpose. Providers of DNS services, TLD registries and comparable digital services must also maintain a database of their domain name registration data.

The institution is obliged to self-assess whether they are affected. There is no list of covered companies that the BSI publishes. Each company must check whether it is affected based on the sector list, the threshold and the job description and, if in doubt, register it to be on the safe side. False registration is less risky than non-registration; the latter is a separate fine offense.

Group structures make the assessment difficult. Subsidiaries are usually considered individually; the group as such only falls under NIS-2 if it is itself an entity within the meaning of the directive (e.g. as an energy supplier). For medium-sized family businesses with several subsidiaries, the impact analysis must be carried out for each subsidiary. CIVAC offers this analysis as a structured workshop, the results of which are documented in the workspace and can be subsequently verified.

Operational implementation in an SME with 150 employees

A typical medium-sized company profile illustrates the reality: 150 employees, 35 million euros in sales, mechanical engineering, three locations, one IT service provider, no internal ISB. The company is an important institution according to Section 28 of the BSI Act and must fulfil all obligations under Section 30 without being able to set up its own cybersecurity team. The reality is: External ISB according to Section 30 of the BSI Act, workspace for ongoing documentation, outsourcing of 24/72 reporting path support in the first 12 months.

The schedule typically looks like this: Month 1 impact analysis and registration, month 2 ISB order with reporting line to management, months 3 to 4 risk analysis and supply chain assessment, months 4 to 6 structure of the ten Subject areas according to § 30 with mapping to the 93 ISO controls, month 6 training of the management, from month 7 ongoing operations with quarterly control appointments. The order SLA at CIVAC is two working days, which noticeably shortens the start time.

The cost line depends on the model choice. Workspace licences for internal representatives or officer-as-a-service with external appointment of both roles (ISB and DSB) are typically in the low five-figure range per year for a 150-person SME. Compared to a fine of up to 7 million euros or 1.4% of group sales, the investment is economically justifiable; Compared to building up a 1.5 FTE security department internally over 18 months, it is significantly cheaper and more effective.

Turn reading into an assignment

NIS-2 is not a theoretical risk for SMEs, but a chain of obligations that will be active in 2026 with a three-tiered fine and personal liability for management. The threshold of 50 employees and 10 million euros in annual sales in eleven sensitive sectors affects classic medium-sized businesses, not just corporations. Anyone who is not yet registered in 2026 should complete the impact analysis within the next few weeks and implement the first obligations under Section 30 of the BSI Act.

CIVAC operates as a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives, or have our representatives order it. The dual model covers the ISB obligation according to Section 30 of the BSI Act, the ISMS according to ISO/IEC 27001:2022 with all 93 controls and the 24/72 reporting path in one tenant, with EU data residency and an order SLA of two working days. 490 audit templates and 25 representative roles supplement the ISB function with the parallel data protection, money laundering, whistleblower protection and AGG obligations.

Turn reading into a mandate. Send a short description of your company size, your sector and your current ISB status to info@civac.de or use the contact form on civac.de. An impact analysis with written results is part of the initial consultation; The ordering of the ISB and the setup of the workspace follow within the two-working day SLA. The CIVAC ISB page.

provides a more in-depth view of the role

FAQ

From how many employees does an SME fall under the NIS 2 requirement?

The threshold is 50 employees and either more than 10 million euros in annual turnover or more than 10 million euros in annual balance sheet total, cumulative with sector affiliation according to Annex I or II of the NIS 2 Directive. Providers of public electronic communications, trust services, DNS services and TLD registries are covered regardless of size class, including below the SME threshold.

What is the difference between essential and important facility?

Essential facilities according to Annex I of the NIS 2 Directive are subject to proactive BSI supervision and fines of up to 10 million euros or 2% of group turnover. Important Annex II facilities are subject to reactive supervision and fines of up to 7 million euros or 1.4% of group turnover. The categorization depends on the sector and size class and is specified in Section 28 of the BSI Act, including the eleven essential and six important sectors.

How does the 24/72 hour reporting period work exactly?

If a significant security incident is known in accordance with Section 32 Paragraph 5 of the BSI Act, the facility must send an early warning to the BSI within 24 hours, a complete incident report with assessment and indicators of compromise within 72 hours, and a final report within one month. The period begins with positive knowledge, not with the objective occurrence of the incident. Deadline begins as soon as we become aware of it.

Does management have to attend training courses in person?

Yes. Section 38 Paragraph 3 of the BSI Act requires members of management to regularly participate in cybersecurity training. Participation must be documented and proven in the audit. In the event of violations in accordance with Section 64 of the BSI Act, the supervisory authority can order that members of the management be temporarily excluded from their management tasks, which represents a significant personal sanction.

Does the ISB appointment replace the personal responsibility of management?

No. The appointment of an information security officer makes it easier to fulfil the obligation, but does not replace the personal responsibility of management in accordance with Section 38 of the BSI Act and Section 130 of the OWiG. The ISB advises, documents and monitors; The approval of the risk management measures and the responsibility for their implementation remain with the management. This construction is comparable to the DSB logic according to Art. 24 GDPR.

How quickly can CIVAC order an external ISB for an SME?

The CIVAC SLA for issuing the appointment certificate and setting up the workspace is two business days after the scoping discussion. The traditional search for a qualified ISB usually takes two to six weeks, which is unacceptable given the ongoing risks of fines and supervision. The appointment certificate, the reporting line and the first workspace structure are standard scope of delivery.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles