NIS 2 implementation: What do companies really need to do in the first 90 days
The NIS 2 Implementation Act has been in effect since March 2026. This guide shows the operational sequence for the first 90 days, from the impact check to the ISB order to the functional reporting path to the BSI.
The NIS 2 Implementation Act, in force in Germany as an amendment to the BSIG since March 2026, obliges around 29,500 companies to a significantly stricter regime for cybersecurity, reporting and management liability. The deadline for registration with the BSI expired in spring 2026, and many companies are not yet operationally audit-proof. For essential facilities, fines range up to 10 million euros or 2 percent of group sales according to Section 64 BSIG.
This article is not an NIS 2 basic statement, but rather an operational 90-day order. Anyone who has confirmed that they are affected and needs to act now will find the sequence of steps, the pitfalls and the interface between the internal function and the CIVAC platform here. CIVAC is a compliance platform and officer-as-a-service with an operational 24/72 hour reporting path.
Key Takeaways
- The operational NIS 2 implementation runs in three 30-day phases: impact and ISB, risk and action plan, reporting path and training.
- The information security officer is not legally mandatory, but in practice is essential for the verifiable implementation of the § 30 BSIG obligations.
- The 24-hour early warning and 72-hour follow-up reporting path to the BSI must be presented as a tested workflow, not as a planned idea.
Days 1 to 14: Bindingly determine whether you are affected
The impact assessment according to Section 28 BSIG is the starting point. Companies from 18 sectors with at least 50 employees or more than 10 million euros in annual turnover fall under the NIS 2 requirement, divided into essential and important facilities depending on the sector and size.
The review is carried out in writing and is required in the audit. The result documents the classification, the calculation basis for employees and sales, the assigned sector appendix entries and the conclusion with a time stamp and approval from the management.
Common errors in this phase: overlooking subsidiaries that need to be classified separately; confusing the KRITIS thresholds with the NIS-2 thresholds; and the assumption that parent companies can automatically register for subsidiaries. Each affected company registers itself.
Registration with the BSI takes place via the BSI reporting portal with the information required by Section 33 BSIG: company name, legal form, locations, industry, contact point for cybersecurity and designated person for reports. Registration is a prerequisite for every further step.
For role-specific in-depth information, see our page on the Information Security Officer, who plays the key operational role in medium-sized companies.
Day 15 to 30: Order ISB and establish reporting line
The BSIG does not prescribe an ISB, but the Section 30 obligations on risk management, asset management, incident detection, business continuity and supply chain security require an assigned function. In practice, the ISB is the person who carries out the NIS 2 duties operationally.
The appointment is made by means of a written appointment certificate with a reporting line to the management. The appointment certificate names the ISB, the representation, the scope of the mandate, the resources and the reporting channels. The appointment certificate, signed, filed, verifiable.
The management liability according to Section 38 BSIG makes the reporting line mandatory, not an option. Management must personally oversee NIS-2 duties, attend training, and cannot delegate. The ISB is the interface that fills this personal liability with operational depth.
The choice between internal and external ISB follows the question of bandwidth and independence. CIVAC supplies both models. Licence the workspace for your internal representatives, or have our representatives order it. The external order is placed within two working days after the mandate is signed.
Notification to the BSI as the designated contact point takes place in the order workflow. Audit-proof, documented, § 38-firm.
Day 31 to 60: Risk analysis and action plan according to Section 30 BSIG
§ 30 BSIG requires appropriate and proportionate technical, operational and organisational measures. The catalogue of measures is formulated openly, but the BSI has published a specification with ten fields of measures that are considered a minimum baseline.
The ten fields include risk analysis, incident management, business continuity, supply chain security, security in the procurement of network and information systems, effectiveness assessment, basic cyber hygiene and training, cryptography, personnel security and access control, as well as multi-factor authentication and secure communication.
The risk analysis is the starting point. It identifies the assets in need of protection, the plausible threats and the controls in place. The result is a prioritised list of residual risks with suggested measures and management acceptance for those not addressed.
The action plan transfers the risk analysis into an actionable backlog with those responsible, deadlines and progress measurement. CIVAC's 490 audit templates contain the ISO/IEC 27001:2022 mapping table, with which each NIS 2 measure is linked to one of the 93 controls and the corresponding standard requirement.
Anyone who is ISO 27001 certified or is striving for it has already covered 80 percent of the NIS 2 measures. More about this in our briefing on the ISO 27001:2022 conversion.
Day 61 to 75: Establish reporting path operationally
The NIS-2 reporting path is the most demanding operational requirement. Section 32 BSIG requires an early warning within 24 hours of becoming aware of a significant security incident and a follow-up report with status and assessment within 72 hours, followed by a final report after one month.
The definition of a significant incident has two legs: significant operational disruption or financial losses, and impairment of other natural or legal persons through material or immaterial damage. The threshold is lower than under the old KRITIS regime.
The reporting path needs three components. Firstly, a detection capacity that detects a relevant incident in the first place. Secondly, an assessment and escalation chain that leads to a reporting decision within hours. Thirdly, a transmission workflow to the BSI, with content template, four-eye approval and proof of transmission.
CIVAC delivers the reporting path as a connected workflow in the workspace. The 24-hour slot, the 72-hour sequence and the month-end closing are created as processes, with automatic deadline monitoring, prepared notification and four-eye approval before BSI dispatch. The clock starts on awareness.
The operational rehearsal is a tabletop exercise with a simulated incident. If you don't keep the 24-hour slot during dry running, you won't keep it in an emergency. The auditor calls, the evidence is ready.
Day 76 to 90: Training, tabletop and completion of the roll-out phase
§ 38 BSIG obliges management to participate in cybersecurity training. The duty cannot be delegated and participation must be documented in the audit. The BSI has not prescribed a specific curriculum; practice is based on a 4- to 8-hour format with incident scenarios.
The training of the broader workforce follows the risk analysis. Anyone who works on production-related systems, anyone who handles personal data on a large scale, anyone who manages keys or access to critical systems needs specific training, not the general phishing module.
The tabletop exercise is operational quality control. A realistic scenario, a time-limited run, an external observation and a comprehensible protocol. The findings flow into the adjustment of the measures and the refinement of the reporting path.
At the end of the 90 days there is: registered institution with the BSI, ordered ISB with appointment certificate, documented risk analysis, action plan with backlog and responsible persons, operational reporting path with tested transmission, trained management and prioritised employee training.
Others run compliance like a filing cabinet. We run it like software. The 90 days are not a conclusion, but rather the ticket to continuous operation with continuous effectiveness measurement.
Supply chain in accordance with Section 30 Paragraph 2 No. 4 BSIG
Supply chain security is the most frequently underestimated field of measures. Section 30 Paragraph 2 No. 4 BSIG requires measures to ensure supply chain security, including security-related aspects of the relationships between each facility and its direct providers or service providers.
The operational translation: Every critical IT supplier needs a documented security assessment. These include cloud providers, SaaS providers, managed service providers, authentication service providers and logging backends. The assessment includes certification status, subprocessor chain, data residency, incident reporting requirement in the contract and audit rights.
Existing contracts do not all need to be renegotiated immediately. The pragmatic approach is an inventory audit of the ten to fifteen most critical contracts, the identification of gaps in the security clauses and an add-on when extending the contract. The CIVAC template for the supplier audit covers the NIS 2 requirements.
Cross-cutting is the question of whether the supplier itself is subject to NIS 2. Suppliers that fall under NIS-2 have their own reporting system. Suppliers outside the scope of application must contractually reflect the reporting obligation to you so that you can meet your 24/72-hour deadline.
The construction manager client among the CIVAC clients shows the practice: a construction company had 47 IT suppliers, 11 of which had critical access. The risk assessment took four weeks and the contract adjustments took another eight.
Fines and management liability
The sanction structure under NIS-2 has become significantly stricter compared to the old BSIG. For essential facilities, the fines according to Section 64 BSIG range up to 10 million euros or 2 percent of global group sales, whichever is higher. For important institutions up to 7 million euros or 1.4 percent.
The personal liability of the management according to Section 38 BSIG continues. Managers are responsible for approving the measures and monitoring their implementation. The liability extends to your own household, not just to the company.
The insurance law reflex is the D&O policy. Most D&O insurance policies do not cover NIS 2 fines because they are excluded as an administrative penalty. The damage resulting from a breach of duty in the internal relationship remains insurable, but only if the obligations have been documented and followed up.
The Federal Administrative Court has made it clear in interpretative notes that the BSI follows a graduated sanction practice. The first measure is the request to rectify the defect, then the penalty payment, then the fine. Anyone who provides documented evidence that implementation is ongoing avoids escalation.
Audit-proof, documented, Section 38-proof, that is the attitude that the supervisory authority employee faces in the audit. The auditor calls, the evidence is ready.
What follows after 90 days: continuous operation and effectiveness measurement
The 90-day phase lays the foundation, not the roof structure. The continuous operation follows an annual cycle of risk analysis update, measure effectiveness assessment, tabletop exercise, management report and training round.
Measuring effectiveness according to Section 30 Paragraph 2 No. 6 BSIG is an often underestimated obligation. Measures must not only be taken, but their effectiveness must also be assessed. This means measurable indicators, target value definition and periodic evaluation.
Typical indicators are mean time to detect, patch latency for critical security updates, success rate of phishing simulations, rate of timely backup restore tests and training participation rate. They are reported to management every quarter.
ISO/IEC 27001:2022 certification is not NIS 2 mandatory, but it is the commercially consistent path. The 93 controls from Appendix A largely cover the Section 30 measures, and the auditor report is established evidence for supervisory authorities, customers and insurers.
CIVAC manages the ISMS structure and the NIS 2 measures in one platform. Anyone who consolidates both regimes halves the maintenance effort and gains ISO certification as a cost-neutral side effect.
Turn reading into a mandate.: NIS-2 launch with CIVAC
The NIS 2 implementation is not a consulting project, but rather an operational structure. Anyone who chooses the right sequence in the first 90 days will have an audit-proof status. Anyone who reverses the sequence and begins training before the ISB is ordered creates gaps that will later become expensive.
CIVAC works as a compliance platform and officer-as-a-service with two equivalent delivery models for NIS-2. Licence the workspace for your internal representatives, or have our representatives order it. Both models provide the same reporting path, the same 490 audit templates and the same EU data residency.
The typical start is an impact workshop in the first week, followed by the appointment certificate for the ISB within two working days. The workspace is set up in parallel and the 90-day roadmap starts with a concrete backlog.
For medium-sized companies from the NIS 2 sectors, the interface to ISO/IEC 27001:2022 is crucial. CIVAC manages both regimes in one platform, with a mapping table, common action list and consolidated audit templates.
Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de to arrange the affectedness workshop.
FAQ
When will my company be required to comply with NIS 2?
Since the German implementation law came into force in March 2026. The obligation applies to companies from 18 sectors with at least 50 employees or more than 10 million euros in annual turnover, divided into essential and important facilities in accordance with Section 28 BSIG.
Do I have to appoint an information security officer?
The BSIG does not prescribe any ISB. In practice, an assigned function with a clear reporting line to management is necessary in order to verifiably implement the § 30 BSIG obligations. CIVAC supplies the ISB licensed internally or ordered externally.
How long do I have to report an incident?
An early warning within 24 hours of knowledge, a follow-up report with assessment within 72 hours and a final report within one month in accordance with Section 32 BSIG. The clock starts on awareness.
How much does a violation of NIS-2 cost?
For essential facilities up to 10 million euros or 2 percent of global group sales, for important facilities up to 7 million euros or 1.4 percent. In addition, there is the personal liability of the management in accordance with Section 38 BSIG.
Is ISO/IEC 27001 certification enough for NIS-2?
ISO/IEC 27001:2022 covers approximately 80 percent of the NIS 2 measures via the 93 controls from Appendix A. The NIS 2-specific reporting and supply chain security obligations must also be implemented and checked against the BSIG.
How quickly can CIVAC order an ISB?
The appointment certificate is available within two working days of signing the mandate, with simultaneous notification to the BSI as the designated contact point. Classic law firm orders typically take four to six weeks.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.