Skip to content
Law, security & funding

NIS2: what affects mid-size companies — duties and deadlines

The revised network and information security directive: who is in scope, how supply chains pull in smaller firms and what can be prepared before transposition.

15 min read NIS2IT-SicherheitLieferketteMeldepflichtenRisikomanagement

The revised European directive on network and information security has widened the circle of obligated companies considerably. It no longer applies only to energy suppliers, hospitals and data centres: across 18 sectors (European Commission) it now also captures mid-size manufacturers, suppliers, wholesalers, logistics operators, waste and food businesses and providers of technical services. Companies from 50 employees upwards (European Commission) may therefore be directly obligated for the first time. A far larger circle of smaller firms is reached indirectly, because regulated customers have to pass their requirements down by contract. For management this raises a question that cannot be delegated to the IT department: are we in scope, and if so, what must we be able to evidence when something goes wrong? This article sets out who falls under the directive, which duties follow from it, which deadlines apply after a security incident and what a company can prepare now without waiting for every detail of national transposition. It describes the requirements factually and does not replace legal review of an individual case. Binding classification of your own company belongs with a lawyer; everything that follows in technical and organisational terms is work on day-to-day IT operations and therefore within your control.

Key takeaways

  • The directive covers 18 sectors (European Commission), including manufacturing, chemicals, food, waste, postal services and logistics. What matters is sector and company size, no longer a designation as critical infrastructure by an authority.
  • From 50 employees or 10 million euros in annual turnover a company in a covered sector counts as an important entity; from 250 employees or 50 million euros in the highly critical sectors it becomes an essential entity under stricter supervision (European Commission).
  • Smaller firms below the thresholds are reached through the supply chain: regulated customers must account for the security of their suppliers and service providers and pass requirements on as questionnaires, contract clauses or evidence obligations.
  • A significant incident starts three deadlines: an early warning within 24 hours, a notification with a first assessment within 72 hours and a final report within one month (European Commission). Without a named responsibility even the first is hard to meet.
  • Transposition has applied since 6 December 2025 with no transition period; registration closed on 6 March 2026, the extended deadline on 31 July 2026 (German federal authority for information security). A system register, access rights and tested backups remain the foundation.

What the revised directive changes compared with the earlier version

The first European directive on network and information security, dating from 2016 (European Commission), applied to a narrow circle: operators expressly designated as critical infrastructure by the member states. Anyone who received no such notice was out of scope and never had to consider the question. That principle has been abandoned. Instead of designation by an authority, the revised version relies on self-assessment: a company has to check for itself whether it falls into one of the covered sectors and whether it meets the size thresholds. If the answer is yes, duties arise even though nobody points them out.

Second, the range of sectors has been widened substantially. Alongside energy, transport, health, water, digital infrastructure and public administration, the scope now includes postal and courier services, waste management, chemicals, food production and distribution, large parts of manufacturing, and research. That brings companies into view which never regarded themselves as security-relevant: the machine builder with connected equipment, the supplier of vehicle parts, the manufacturer of electronic assemblies, the regional food processor.

Third, responsibility has moved upwards. Implementing the risk management measures is explicitly a matter for the management body: it must approve the measures, oversee their implementation and take part in training itself (European Commission). That is the real break with previous practice, in which IT security could be treated as a technical side issue. The directive turns it into a management task with personal accountability.

Directive, transposition act, implementing rules

A European directive does not apply directly inside a company. It obliges member states to transpose it into national law; the transposition deadline fell in October 2024 (European Commission). German transposition arrived later than planned but is now in place: the implementing act has applied since 6 December 2025 with no transition period, the registration portal of the German federal authority for information security has been open since 6 January 2026, and the registration deadline expired on 6 March 2026; the extended deadline granted by the authority ended on 31 July 2026 (German federal authority for information security). Companies in scope that have not yet registered should do so now — waiting is no longer an option. In practice that means the substantive requirements of the directive are settled and will not change fundamentally through transposition, while the formalities of registration and reporting may still shift. The German federal authority for information security (BSI) publishes the current status; binding classification of your own company remains a matter for legal advice.

Who is directly in scope: sectors and size thresholds

Scope follows from two criteria that must both apply: sector and company size. The directive lists the sectors in two annexes. The first covers eleven sectors of high criticality (European Commission): energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, management of information and communication technology services for third parties, public administration and space. The second annex names seven further critical sectors (European Commission): postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.

For mid-size companies the manufacturing sector matters most in practice, because it is drawn broadly: medical devices, computer, electronic and optical products, electrical equipment, machinery and equipment, motor vehicles and parts, and other transport equipment. A supplier with 80 employees (project experience, as a typical order of magnitude) producing assemblies for machine builders may therefore be directly in scope, even though nobody in the business has ever spoken of critical infrastructure.

The size thresholds follow the European definition of medium-sized enterprises. From 50 employees, or an annual turnover and balance sheet total each above 10 million euros (European Commission), a company in a covered sector normally counts as an important entity. From 250 employees, or an annual turnover above 50 million euros or a balance sheet total above 43 million euros (European Commission), and within a sector of the first annex, it becomes an essential entity. For certain business types — providers of particular digital infrastructure services, for example — special rules apply regardless of size.

CriterionEssential entityImportant entity
Typical sizefrom 250 employees or above 50 million euros turnover (European Commission)from 50 employees or above 10 million euros turnover (European Commission)
Sectorsbroadly the eleven highly critical sectors of the first annexboth annexes, including manufacturing, chemicals, food, waste, postal services
Catalogue of dutiesidentical substantive requirements for risk managementidentical substantive requirements for risk management
Supervisioninspections possible without a specific triggeras a rule triggered by an incident or a complaint
Maximum penaltiesup to 10 million euros or two per cent of worldwide annual turnover (European Commission)up to 7 million euros or 1.4 per cent of worldwide annual turnover (European Commission)
Practical consequenceevidence must be ready to show at any timeevidence must be producible at short notice when required

The most important point in this table is often overlooked: the substantive catalogue of duties does not differ between the two categories. What differs is supervision and the penalty range. Anyone reassuring themselves that they are merely an important and not an essential entity faces exactly the same work — only with a lower probability of being asked about it unannounced.

The supply chain route: why smaller suppliers are affected too

The directive expressly requires regulated entities to address the security of their supply chain, including security-related aspects of their relationships with direct suppliers and service providers (European Commission). A regulated company cannot meet that duty without asking questions of its suppliers. This is exactly how the regulation reaches firms far below any threshold: the contract manufacturer with twelve staff, the engineering office, the regional maintenance provider, the software partner who looks after an order management system.

In practice it arrives not as legislation but as post from the purchasing department: a security questionnaire with several dozen items, a new annex to the framework agreement, a self-declaration with a return date, occasionally a request for evidence of tested backups or of multi-factor sign-in on remote access. A firm that cannot answer rarely loses the contract straight away — but it lands on an internal list, and that list has an effect at the next award decision.

For smaller companies that is uncomfortable and at the same time the easier variant: the questionnaire shows what matters without any authority being involved. Answers worked out properly once can be reused for years instead of starting from scratch with every new enquiry.

  • Remote access from outside. Who maintains your machines, your merchandise management system, your telephone system remotely? By which route, with which account, with what second factor beyond a password, and is the access logged?
  • Data handovers. Which files and records leave the company regularly, to whom, by which route? Unencrypted attachments and open transfer paths are the most frequent findings.
  • Accounts of former staff. A register of every account per person plus a fixed procedure on departure answers several questionnaire items at once.
  • Backups and recovery. The question is not whether a backup exists, but the date of the last successful restore test.
  • Reporting path for incidents. Who does your company inform after a security incident, within what time, and who decides whether the customer has to be notified?
  • Subcontractors. If you pass on part of your service, the question does not stop with you; you need the same information from your own partners.

The duties in detail: what risk management actually requires

The catalogue of risk management measures is drafted as a minimum list (European Commission). It is deliberately technology-neutral: it does not say which tool to use, only which subject has to be governed. The measures must be appropriate to the risk — a company with 60 employees will not build the same thing as a grid operator, but it has to cover all the topics.

In practice the list condenses into six fields of work. None of them is new; most companies already have parts of them without calling them that. The difference lies in evidence: what sits today in the head of the person looking after the systems has to exist in writing and be current.

Risk analysis and security policies

Which systems and data does the company hold, what happens if they fail or leak, which measures follow from that? The basis is a register of systems, locations, access paths and data flows.

Incident handling

A described procedure setting out who does what on suspicion, who decides, who reports and how people are reachable outside working hours. Without named individuals the procedure has no effect.

Business continuity

Backups, recovery and crisis management. What counts is the tested restore: how long does it actually take until the central workflow runs again, and how much data is lost in the process?

Supply chain security

Requirements for service providers and suppliers, anchored in contracts and reviewed regularly. That includes remote maintenance carried out on your own systems by external partners.

Procurement, development, maintenance

Handling vulnerabilities and updates: who follows security advisories for the systems in use, how quickly are fixes applied, and how is that recorded?

Access, staff, training

Rights assigned by role, multi-factor sign-in on sensitive access, encryption where required, plus regular training for staff and for management.

One item on the minimum list stands out: policies to assess the effectiveness of the measures (European Commission). Issuing a rule is therefore not enough. It has to be checked and recorded whether the rule works in daily operation. This is where many existing security folders fail: they describe a target state that stopped matching the business years ago.

Reporting deadlines: 24 hours, 72 hours, one month

The reporting duty is the part of the directive that creates the most pressure in a real incident, because it has to be met under time pressure and with operations disrupted. What must be reported are significant incidents — those capable of causing severe operational disruption or financial loss, or of affecting other natural or legal persons by causing considerable damage (European Commission). The company itself has to judge whether an incident is significant, and it has to do so early.

The clock runs from becoming aware of the incident, not from its start. That is both a relief and a trap: a relief, because an undetected attack does not start the clock; a trap, because the moment of awareness is reconstructed afterwards, and the logs then show when the first anomaly was visible.

A short initial notice to the competent authority (European Commission). It contains no analysis, only the statement that a significant incident has occurred, whether unlawful or malicious action is suspected and whether cross-border effects are possible.

In practice it is not knowledge of these deadlines that decides whether they are met, but preparation. What is needed is a named person with a deputy, a known reporting channel including credentials, a template for the initial notice and a decision on who judges significance. These four points fit on a single page, can be produced in an afternoon and make the difference between a timely report and a frantic search for responsibilities on a Saturday evening.

Management accountability: approval, oversight, training

The directive addresses management bodies directly. They must approve the risk management measures, oversee their implementation and take part in training regularly so that they can assess risks and management practices (European Commission). The rules also provide for management responsibility in the event of breaches. Execution can be delegated; accountability cannot.

For a mid-size company that has a very practical consequence: security work which used to run on the side now needs a dated approval. A management decision that endorses the plan of measures, names budget and responsibility and sets a review date is not a formality. It is the evidence that the management duty was exercised — and it stops the work being dropped at the first burst of order pressure.

A security measure without a named responsible person and without a review date is a statement of intent. When it matters, what counts is who approved it and when, and who last checked it.

Principle from rollout practice (project experience)

The training duty is often underrated because it does not feel like a technical task. Yet it is the point where evidence can be produced most cheaply: attendance lists, contents and dates are documented quickly and cover an audit point completely. It makes sense to combine it with the training and rollout that new workflows require anyway, rather than scheduling a separate session that nobody attends.

Registration, supervision and penalties in perspective

Alongside risk management and reporting there is a third, formal duty: regulated entities must register with the competent body, providing basic details, sector, contact information and the member states concerned (European Commission). Registration is the point at which self-assessment goes on record. It is also why the question of scope cannot be left open: a company that is in scope and does not register breaches a duty regardless of how well its technology is protected.

On supervision the directive distinguishes between the two categories. Essential entities can be inspected without a specific trigger; for important entities supervision generally requires a trigger, such as a reported incident or a complaint. Supervisory authorities can order audits, demand information, issue instructions and impose penalties.

Fines are not the real lever

The stated ceiling of up to 10 million euros or two per cent of worldwide annual turnover for essential entities, and up to 7 million euros or 1.4 per cent for important entities (European Commission), describes an upper limit, not an expected payment. For a mid-size company the more effective pressure comes from elsewhere: customers demanding evidence, insurers asking about recovery concepts, and the standstill after an incident, against which no penalty ceiling says anything. Anyone justifying the work purely with the risk of a fine will struggle to get it accepted internally.

What to do now — transposition already applies

The most common mistake in this situation is waiting. As long as the last implementing rule is unpublished, every investment looks premature. In reality the remaining uncertainty concerns formalities above all: the registration procedure, notification forms, deadlines for first registration, the assignment of particular business types. The substance has been settled since the directive was adopted, and it largely coincides with what a company needs anyway in order to be able to work again after an outage.

Framing the preparation as an IT security project makes it larger than it needs to be. It carries much better as an inventory exercise: which systems exist, which data moves between them, who has access to what, what happens on failure? These are the same questions that open every process analysis — the results pay for themselves twice.

Preparation plan, six weeks alongside daily work
Week 1  Establish scope
        - check sector (both annexes), evidence the size thresholds with figures
        - record the result in writing, even if it is negative
        - hand open questions to legal counsel

Week 2  Take inventory
        - list every system, location, cloud service, remote access path
        - per system: owner, data type, consequence of failure

Week 3  Put access in order
        - accounts per person, rights per role, leaver procedure
        - multi-factor sign-in on remote access and administrator accounts

Week 4  Test the backups
        - restore test of one central system, measure the duration
        - log the result with a date, note the gaps

Week 5  Define the reporting path
        - name the responsible person and a deputy
        - clarify reachability outside working hours
        - create a template for the initial notice

Week 6  Approval and review date
        - present the plan of measures to management
        - decision with date, budget, responsibility
        - enter the next review date

Six weeks is not a promise but an order of magnitude from projects of this kind (project experience). What matters is not the pace but that every week ends with a result on paper. An asset register that is 80 per cent complete (project experience) helps more in an inspection than a perfect one that was never started.

Evidence: what has to be available when it matters

Supervisors and customers do not examine intentions, they examine documents. The difference between a well-protected company and a demonstrably compliant one is the folder recording what was done, when and by whom. These records cannot be created retrospectively; they have to be written as work proceeds, otherwise exactly the period being asked about is missing.

It helps to separate evidence into three kinds. First, descriptions: what applies in the company, who is responsible, which rule governs what. Second, proof of execution: logs, attendance lists, test reports, the date of the last restore test. Third, proof of effectiveness: figures showing that the rule works in daily operation, such as the share of accounts with multi-factor sign-in or the time between a security fix becoming known and being applied.

Evidence should arise from the workflow, not from a binder

Records produced specifically for an inspection go stale between inspections and consume time at every update. It carries better to let them arise as a by-product of daily work: the ticket system records when an account was created and when it was withdrawn. The backup software logs the restore test. The personnel system supplies the leaving date that triggers withdrawal of access. Anchored this way, the evidence already exists when the inspection comes — and the underlying work is done only once.

For companies with existing process documentation this is not a new format. The workflows are already described; what has to be added are the security-related details — responsibility, access rights, consequence of failure, review interval. Companies with no documentation at all should not start it because of the directive, but take the directive as the occasion to finally start it.

What this means for legacy systems and grown IT landscapes

Most mid-size companies run at least one system that has received no updates for years: a production control system, an older merchandise management system, a machine controller with a fixed operating system, a time recording server under a desk. Such systems are the hardest point in risk management, because they cannot be secured by patching and because replacing them often collides with production.

The directive does not demand replacement. It demands that the risk is identified, assessed and treated with appropriate measures. Containment is usually the workable answer: separate the system on the network from the rest of the business, limit access to named people and routes, run data exchange through controlled handover points, secure the logs and prepare a recovery of the whole system. Documented and justified, a contained legacy system withstands an inspection; ignored, it is the open point every inspection finds first.

Where containment reaches its limits — because the system sits centrally in the data flow, or because the vendor provides no support at all — replacing the legacy system becomes a medium-term task. It then belongs in the plan with a date and a budget, not in the category of known problems. A known, scheduled shortcoming is judged differently in supervision than an unknown one.

An afternoon that settles a lot

Sit down with the person who looks after your IT and answer four questions in writing: which systems would stop our business within a day if they failed? Who can reach them from outside? When was a restore from backup last tested successfully? Whom do we call on a Sunday if something happens? If any of these questions stays open, you have found your starting point — regardless of how national transposition turns out in detail.
This article is based on data from: European Commission (directive on measures for a high common level of cybersecurity across the Union, including its definitions and annexes) and the German federal authority for information security (BSI) (publications on transposition and on the state of IT security in Germany), together with our own project experience from assessments in mid-size companies.

Related Articles

Law, security & funding

Cyber Resilience Act: a reporting process in 24 hours

From 11 September 2026 the reporting duty in Article 14 applies. Who reports to whom, what happens in the first 24 hours and which records remain at the end.

16 min read
Law, security & funding

Account Access When Staff Join and Leave the Company

How access is ready on the first working day and reliably ends after someone leaves: taking stock, roles, a trigger from the HR system, annual review.

13 min read
Law, security & funding

Backups that hold up: copies, distance and a proven way back

Several copies, one off site, one without a permanent connection: how firms set recovery time and tolerable data loss, and how to test restores for real.

14 min read