NIS-2 Implementation Germany: How to Operate the 2026 Deadline as an Officer, Not a Project
The 2026 implementation phase of NIS-2 in Germany shifts the burden from legal interpretation to operational execution. This guide focuses on the officer angle: how to staff, structure, and report a NIS-2 program under Section 38 BSIG without burning out the team.
The German transposition of NIS-2 through the BSIG amendment moved from political debate into operational execution by mid-2025, with the supervisory regime running from 2026 onward. Approximately 29,500 entities are in scope in Germany, split into essential and important categories with different fine ceilings: up to EUR 10 million or 2 percent of group turnover for essential, up to EUR 7 million or 1.4 percent for important.
By 2026 the discussion has shifted from whether your firm is in scope to how the Information Security Officer (ISB) under Section 38 BSIG actually runs the day-to-day program. This guide takes the officer angle: staffing models, the 24-hour early warning and 72-hour follow-up reporting cycle, ISO/IEC 27001:2022 control alignment, and the operational reality of a four-week onboarding. CIVAC operates as a compliance platform and officer-as-a-service: license the workspace for your in-house officers, or appoint our officers.
Auf einen Blick
- By 2026 the NIS-2 conversation in Germany shifts from scoping to operations: ISB staffing, 24h/72h reporting under Section 32 BSIG, and ISO/IEC 27001:2022 control alignment.
- An external Information Security Officer under Section 38 BSIG typically costs EUR 24,000-84,000 annually for mid-market firms, against EUR 90,000-140,000 fully loaded for in-house recruitment.
- The 24-hour early warning and 72-hour follow-up reporting cycle should be exercised in a tabletop drill at least once per year, otherwise it will not function under live conditions.
Scope reality in 2026: who is essential, who is important, who is out
The German NIS-2 transposition through the BSIG amendment defines roughly 29,500 entities in scope across 18 sectors, divided into essential and important categories. Essential entities operate in highly critical sectors such as energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.
Important entities operate in critical sectors including postal services, waste management, chemicals, food, manufacturing of medical devices, computers and electronics, machinery, motor vehicles, digital providers, and research. The fine ceilings differ: EUR 10 million or 2 percent of group turnover for essential, EUR 7 million or 1.4 percent for important.
The reporting deadlines do not differ between categories. Both must submit a 24-hour early warning to BSI under Section 32 BSIG, a 72-hour follow-up notification, and a one-month final report. The deadlines run from awareness, not from incident occurrence.
Many mid-market firms in 2026 still operate without an internal scoping decision. The diagnostic question is simple: are you in one of the 18 listed sectors, do you exceed 50 employees, and is your annual turnover above EUR 10 million? If yes, expect essential or important classification.
By 2026 the BSI has begun routine supervisory contact with essential entities, with notification on company registry data. Important entities are typically contacted in 2027 after the first audit wave of essential entities completes.
A detailed primer on the regulation is available at civac.de/news/nis-2-umsetzung-deutschland-2026. This article focuses on the officer execution angle.
The Section 38 BSIG Information Security Officer: appointment in practice
The Section 38 BSIG Information Security Officer is the legally accountable function for NIS-2 implementation in Germany. The appointment letter must specify scope, reporting line to management, deputies, and termination protections analogous to those of the DPO under Article 38 GDPR.
Three operational models exist. First, in-house full-time ISB with reporting line to the CEO or CISO. Fully loaded cost between EUR 90,000 and EUR 140,000 annually for a qualified candidate with CISSP, CISM, or ISO/IEC 27001:2022 lead auditor credentials.
Second, in-house part-time ISB combining the role with adjacent functions such as IT security manager or internal audit. Workable for smaller scope but creates conflict-of-interest risks the appointment letter must address explicitly.
Third, appointed external ISB under a formal mandate, with quarterly reports to management and a defined service level for incident support. Cost between EUR 24,000 and EUR 84,000 annually depending on complexity, with no recruitment lag and immediate documentation experience.
For mid-market firms with 250-1,500 employees, the appointed external ISB is often the most economical path for the first 24-36 months of a NIS-2 program. The role can be internalized after the workspace artifacts stabilize and the audit pattern is predictable.
The appointment letter must be signed, filed, and retrievable. The deadline runs from awareness. CIVAC operates the appointed ISB function with documented service level agreements and standardized reporting templates. The ISB role page details the scope and operating model.
The 24h/72h reporting cycle: timer mechanics under Section 32 BSIG
The Section 32 BSIG reporting cycle replaces the older Section 8b BSIG single-shot notification with a three-stage cascade. Stage one: 24-hour early warning to BSI containing minimum information about the incident, suspected cause, and known impact. The 24-hour timer runs from awareness.
Stage two: 72-hour follow-up notification with assessment of severity, indicators of compromise, and any preliminary mitigation steps. Stage three: one-month final report with root cause analysis, corrective measures, and lessons learned.
The timer mechanic requires automated detection in the operational workspace. An incident is logged once, classified against GDPR Article 33 (72-hour), Section 32 BSIG (24h/72h), and where applicable Section 14 HinSchG. Each applicable deadline runs an independent timer with its own escalation chain.
The hardest operational reality is not the legal text but the on-call rotation. The 24-hour timer is brutal during weekends, public holidays, and holiday seasons. The ISB needs a documented deputy under Section 38 BSIG, a 24/7 incident hotline, and pre-approved BSI notification templates that can be filed within minutes once content is ready.
An untested incident reporting workflow fails at the first live event. A tabletop exercise once per year is the operational minimum. CIVAC includes a Section 32 BSIG drill template in the workspace, with simulated supervisory contact and post-drill remediation log.
The auditor calls, the evidence is ready. The facts page documents the standard incident workflow.
Mapping NIS-2 controls to ISO/IEC 27001:2022 Annex A
NIS-2 Article 21 lists ten minimum security measures: risk policy, incident handling, business continuity, supply chain security, network security, vulnerability handling, effectiveness assessment, basic cyber hygiene and training, cryptography, access control, and multifactor authentication. These map cleanly to ISO/IEC 27001:2022 Annex A in the 2022 revision.
The 93 controls of Annex A 2022 cover the NIS-2 minimum measures with substantial overlap. A firm with a mature ISO/IEC 27001:2022 implementation typically satisfies 80-90 percent of NIS-2 technical requirements through the existing ISMS.
The mapping should be documented in the Statement of Applicability with explicit NIS-2 cross-references. Each NIS-2 measure under Article 21 lists the corresponding Annex A controls, the implementation owner, and the evidence location in the workspace.
The 2013 revision of ISO/IEC 27001 is no longer sufficient. The transition window closed in October 2025, and all re-certifications from 2026 onward must demonstrate the 93-control Annex A in the 2022 version. Firms still operating against the 2013 revision are running expired assurance and miss the NIS-2 alignment benefit.
Supplementary controls that NIS-2 emphasizes more heavily than ISO/IEC 27001:2022 include supply chain security with explicit attestation requirements and management training under Section 38 BSIG. The ISB must document board-level training on NIS-2 obligations.
Audit-tested, documented, Section 32 BSIG-tested. CIVAC delivers the SoA template pre-mapped to NIS-2 Article 21 and includes 490 audit templates across the integrated workspace.
Vendor and supply chain due diligence under NIS-2
Supply chain security is one of the two areas where NIS-2 expands well beyond the older BSIG regime. Section 30 of the German transposition obliges essential and important entities to assess the cybersecurity posture of their direct suppliers and service providers, with documented evidence and ongoing monitoring.
The practical implementation requires four artifacts. First, a vendor risk register classifying suppliers by criticality, data sensitivity, and access scope. Second, a due diligence questionnaire covering ISO/IEC 27001:2022 status, breach history, sub-processor disclosure, and incident response capacity.
Third, contractual clauses requiring breach notification to your firm within hours of vendor awareness, with a clear lookup of where the notification gets routed in your own Section 32 BSIG reporting cycle. Fourth, ongoing monitoring through annual attestation, periodic spot checks, and reassessment after material vendor changes.
For most mid-market firms, the supply chain workload is the single largest delta between pre-NIS-2 and post-NIS-2 operations. A firm with 200 active suppliers and 30 critical ones can expect 80-120 hours of annual due diligence work, beyond the initial onboarding effort.
The workspace must hold the vendor register, the questionnaires, the contractual evidence, and the reassessment cycle in one searchable location. Excel and SharePoint do not scale beyond 30 suppliers without quality degradation.
CIVAC includes vendor due diligence templates in the standard onboarding. The CIVAC FAQ documents the data model. Appointment documents signed, filed, retrievable.
Cost reality: in-house ISB, external mandate, or hybrid
The full-cost picture for a German mid-market NIS-2 program over three years has six components. First, the Information Security Officer. In-house: EUR 90,000-140,000 annually fully loaded. External mandate: EUR 24,000-84,000 annually. Hybrid combining external mandate with internal coordinator: EUR 60,000-100,000 annually.
Second, the compliance platform license. Specialized platforms between EUR 8,000 and EUR 60,000 annually depending on headcount and modules. Traditional GRC suites start at EUR 40,000 annually.
Third, ISO/IEC 27001:2022 certification or surveillance. Initial certification audit between EUR 25,000 and EUR 60,000 for mid-market firms, annual surveillance between EUR 12,000 and EUR 25,000.
Fourth, training. Management training under Section 38 BSIG, staff awareness training, and incident response drills. Between EUR 15,000 and EUR 40,000 annually for a firm of 250-500 employees.
Fifth, technical infrastructure. Endpoint detection, log management, vulnerability scanning, multifactor authentication. Strongly dependent on existing baseline, but typically EUR 50,000-200,000 incremental annually for mid-market firms with average prior investment.
Sixth, avoided fines. Essential entities risk up to EUR 10 million or 2 percent of group turnover per violation, important entities up to EUR 7 million or 1.4 percent. A single severe violation often exceeds five years of compliance program cost.
License the workspace for your in-house officers, or appoint our officers. The combination typically delivers full NIS-2 coverage at 50-70 percent of traditional consulting-led implementation cost.
Four-week NIS-2 onboarding: from scoping to first drill
A NIS-2 program does not require an 18-month implementation. The CIVAC four-week onboarding delivers a productive baseline that already meets minimum Section 32 BSIG reporting capability by the end of week four.
Week one: scoping and appointment. The two-hour kickoff captures the regulatory classification (essential, important, or out of scope), the existing security baseline, current ISB status, and reporting lines. The Section 38 BSIG appointment letter is drafted and signed.
Week two: data migration and control mapping. Existing security policies, the ISO/IEC 27001:2022 SoA if available, vendor register, training records, and prior incident files are uploaded. The NIS-2 Article 21 controls are mapped to the Annex A 2022 controls in the workspace.
Week three: training and reporting setup. ISB, deputies, management, IT operations, and HR contacts run through their role-specific packages. The Section 32 BSIG reporting templates are configured with on-call routing, BSI submission addresses, and approval workflows.
Week four: tabletop drill. A simulated incident triggers the 24-hour early warning, the 72-hour follow-up, and the one-month final report cycle end-to-end. Supplementary scenarios cover a vendor breach notification under Section 30 and a GDPR Article 33 dual-classification.
At the end of week four, the program operates against the BSIG with documented evidence trails. Other vendors run compliance like a filing cabinet. We run it like software. The deadline runs from awareness.
Common implementation mistakes the supervisory regime now flags
By 2026 the BSI supervisory function has begun routine contact with essential entities, and a pattern of common mistakes is visible in the early audit results. Mistake one: missing or invalid Section 38 BSIG appointment letter. An appointment with unclear scope, no deputy, or no documented reporting line typically draws an immediate finding.
Mistake two: untested 24h/72h reporting workflow. Firms with sophisticated security architectures often fail the operational test because the ISB cannot reach BSI within 24 hours due to procurement freezes, holiday cover gaps, or unclear submission routing.
Mistake three: ISO/IEC 27001:2013 still in force. The 2013 certificate provides no NIS-2 audit credit by 2026, and firms relying on the older revision typically need a costly accelerated transition project.
Mistake four: supply chain due diligence delegated to procurement without ISB oversight. The vendor register exists but is not linked to the security organization, so the cybersecurity assessment never happens in practice.
Mistake five: management training under Section 38 BSIG never documented. The legal text is explicit: management must be trained on NIS-2 obligations, and the training must be evidenced.
Mistake six: incident classification logic incomplete. An incident must be assessed against Article 33 GDPR, Section 32 BSIG, Section 14 HinSchG where applicable, and contract-based notification obligations to customers and vendors. Single-classification logic misses parallel deadlines.
Mistake seven: no exit clause from compliance vendor contracts. The auditor calls, the evidence is ready, until your prior vendor refuses to release the export.
From reading to action: workspace or officer-as-a-service
The 2026 implementation phase of NIS-2 in Germany rewards firms with operational discipline, not firms with the longest project plan. CIVAC offers two routes to the same audit-ready baseline, with the same workspace, the same templates, and the same reporting paths.
Route one: you appoint your own Information Security Officer under Section 38 BSIG and license the CIVAC workspace for daily operations. The 24h/72h reporting cycle, the ISO/IEC 27001:2022 control mapping, the supply chain due diligence, and the management training all run in one system.
Route two: you appoint a CIVAC ISB as your formal Section 38 BSIG officer. Quarterly reports flow to your management with documented acknowledgement, the incident hotline operates with defined service levels, and the workspace artifacts are maintained as part of the mandate.
License the workspace for your in-house officers, or appoint our officers. Both routes produce identical audit outputs from a compliance platform and officer-as-a-service.
Turn this read into an engagement. Contact info@civac.de or use the contact form on civac.de, with NIS-2 classification, employee headcount, and current ISB status.
You will receive a structured proposal within two business days, with module selection, fee range, and the four-week implementation plan including the first tabletop drill. The deadline runs from awareness.
FAQ
Which firms are in scope for NIS-2 in Germany by 2026?
Roughly 29,500 entities across 18 sectors, classified as essential or important. Generally, firms in the listed sectors with at least 50 employees and EUR 10 million annual turnover are in scope. Specific size thresholds vary by sector under the BSIG amendment.
What is the 24h/72h reporting requirement under Section 32 BSIG?
A 24-hour early warning to BSI, a 72-hour follow-up notification, and a one-month final report. The deadline runs from awareness of the incident, not from its occurrence. Both essential and important entities are subject to this cascade.
What does an Information Security Officer under Section 38 BSIG cost?
In-house fully loaded between EUR 90,000 and EUR 140,000 annually. External appointed mandate between EUR 24,000 and EUR 84,000 annually depending on complexity. Hybrid models with external mandate plus internal coordinator typically EUR 60,000-100,000 annually.
Does ISO/IEC 27001:2022 satisfy NIS-2 requirements?
ISO/IEC 27001:2022 with the 93-control Annex A covers 80-90 percent of the NIS-2 Article 21 minimum measures. Supplementary controls for supply chain security and management training are needed beyond the standard ISMS. The 2013 revision is no longer sufficient.
What are the fines for NIS-2 violations in Germany?
Essential entities face up to EUR 10 million or 2 percent of group turnover per violation. Important entities face up to EUR 7 million or 1.4 percent of group turnover. The supervisory authority is the BSI, with sector-specific competent authorities in some cases.
How long does a four-week NIS-2 onboarding cover?
Scoping and Section 38 BSIG appointment in week one, data migration and control mapping in week two, training and reporting setup in week three, and a tabletop drill of the 24h/72h cycle in week four. The program operates against the BSIG by week four.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.