Germany’s NIS2 Implementation Law: Expanded Obligations and Personal Liability
Germany is facing comprehensive IT security reform: the NIS2 implementation law extends obligations to 29,500 companies and introduces personal liability for managing directors.
After more than a year of delay, Germany is on the verge of a paradigm shift in IT security. The Federal Council is voting today on the NIS2 implementation law – wiht drastic consequences for tens of thousands of companies.
The vote in the Federal Council marks the end of a turbulent legislative marathon. The Bundestag already gave the green light on November 13th to the NIS 2 Implementation and Cybersecurity Strengthening Act.If approved today, the law is expected to come into force at the beginning of 2026, ending a regulatory impasse that had left Germany needing description across Europe.
The scale of the project is unprecedented: While the previous IT Security Act 2.0 covered around 4,500 operators of critical infrastructure, the new set of rules expands the scope of application to an estimated 29,500 “essential” and “important” facilities.This corresponds to a sixfold increase in the number of companies affected.
Many companies are not yet prepared for the new NIS2 requirements and the strict reporting deadlines (24/72 hours). While the federal government and BSI tighten surveillance and threaten personal liability, a practice-oriented guide helps to set priorities: incident response steps, risk management checklist and immediate measures for IT and management. The guide is aimed at managing directors, IT managers and compliance teams and shows how you can implement NIS2-compliant processes quickly and cost-effectively. Download the free cyber security guide for companies now
A Law with a Rocky Start
The road to today’s decision was rocky. Germany missed the EU implementation deadline of October 17, 2024 – with consequences: The EU Commission initiated infringement proceedings on November 28, 2024. The collapse of the traffic
Worth a look