Germany transposed NIS2 on 6 December 2025 - with no transition period. Around 29,500 organisations are in scope, and far fewer have registered so far. This check walks you through the assessment order of section 28 BSIG.
The outcome is a non-binding initial assessment: operator of a critical installation, essential entity, important entity, or out of scope. What it explicitly is not is a binding classification or legal advice.
Does your company have an establishment in Germany, or does it provide services in Germany or the EU?
The BSIG applies to entities established or active in Germany. Providers without an establishment that nevertheless serve the EU may have to designate a representative in the EU - we can clarify that in a call.
Does your company operate an installation in any of these KRITIS sectors?
This means installations as defined in the BSI-KritisV - a power plant, a waterworks, a hospital or a data centre, for example. Operators of critical installations are always in scope regardless of company size, which is why this question comes first.
Do any of these activities apply to you?
These entity types are in scope regardless of headcount and turnover - even a company with five employees falls under NIS2 here. Multiple selections possible.
Which of these entity types describes what your company actually does?
What counts is your real activity - not the industry code in the commercial register and not your own marketing self-image. Multiple selections possible. Click a sector to expand it.
No entity type found. Adjust your search or browse the sectors.
How large is your company?
The last adopted annual financial statements are decisive. Employees count as annual work units (full-time equivalents).
Under the SME definition, the figures of linked and partner enterprises must generally be included - which is how the small German subsidiary of a large group often ends up in scope after all. Section 28 (4) sentence 2 BSIG contains a NIS2-specific exception where the entity is independent in the design and operation of its IT systems.
We will email you the result together with its reasoning. In the free initial call we then clarify what we can contribute technically - which penetration test provides the evidence in your case. The legal classification and the notification to the BSI remain with you.
The result is on its way to your inbox. We will get back to you within one business day - for urgent questions call us directly on +49 9281 5918506.
NIS2 is EU Directive 2022/2555 on cybersecurity. Germany transposes it through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), an omnibus act affecting 22 laws and regulations that, at its core, completely recasts the BSI Act. Promulgated on 5 December 2025, it has applied since 6 December 2025 - with no transition period. The number of entities supervised by the BSI rises from around 4,500 to roughly 29,500.
Two things determine your classification: which annex of the BSIG your activity is assigned to (Annex 1 or Annex 2), and which size class your company falls into. Operators of critical installations and a handful of special types - qualified trust service providers, TLD registries, DNS and telecommunications providers - are in scope regardless of size. This check applies exactly that order.
The NIS2UmsuCG enters into force. All substantive obligations apply from that day; there is no transition period.
The BSI opens its registration portal. Registration runs in two stages, via Mein Unternehmenskonto (an ELSTER organisation certificate) and then the BSI portal.
Statutory registration deadline under section 33 BSIG. By that date around 17,700 entities had registered - far fewer than the expected 29,500.
End of the BSI enforcement moratorium. It was never a deadline extension: the administrative offence had existed continuously since 7 March 2026. Since August 2026 the BSI has been inspecting sector by sector, prioritising energy, health and digital infrastructure.
Operator of a critical installation under the BSI-KritisV. Automatically counts as an essential entity, plus attack detection under section 31 and three-yearly evidence under section 39 BSIG.
Annex 1 sectors from large-enterprise size, plus - regardless of size - qualified trust service providers, TLD registries, DNS and larger telecommunications providers. Proactive supervision, fines up to EUR 10m or 2 % of worldwide turnover.
Medium-sized enterprises in Annex 1 plus every Annex 2 entity, however large it is. Same obligations, but reactive supervision and fines up to EUR 7m or 1.4 % of worldwide turnover.
No annex sector, no special type, or below the size thresholds. Note: self-identification remains mandatory, and as a supplier to customers in scope, requirements can still reach you contractually.
You now know which tier you are on. The next step is the technical evidence: we assess your attack surface and document the findings mapped directly onto the Article 21 (2) NIS2 requirement catalogue.
Request a free initial consultationAccess Granted is a penetration testing provider. We deliver the technical part: penetration tests, attack simulations and reports you can use as evidence for the technical requirements. We explicitly do NOT handle registration with the BSI, the legal classification of your entity, legal advice or certification. This check is therefore meant as a first orientation step, not as proof of compliance.