Free assessment tool · NIS2UmsuCG / BSIG 2025

NIS2 applicability check:
A first assessment in 2 minutes

Germany transposed NIS2 on 6 December 2025 - with no transition period. Around 29,500 organisations are in scope, and far fewer have registered so far. This check walks you through the assessment order of section 28 BSIG.

The outcome is a non-binding initial assessment: operator of a critical installation, essential entity, important entity, or out of scope. What it explicitly is not is a binding classification or legal advice.

Non-binding, no sign-up, no cookies Full Annex 1 and Annex 2 sector lists KRITIS thresholds included

Does your company have an establishment in Germany, or does it provide services in Germany or the EU?

The BSIG applies to entities established or active in Germany. Providers without an establishment that nevertheless serve the EU may have to designate a representative in the EU - we can clarify that in a call.

Does your company operate an installation in any of these KRITIS sectors?

This means installations as defined in the BSI-KritisV - a power plant, a waterworks, a hospital or a data centre, for example. Operators of critical installations are always in scope regardless of company size, which is why this question comes first.

Do any of these activities apply to you?

These entity types are in scope regardless of headcount and turnover - even a company with five employees falls under NIS2 here. Multiple selections possible.

Which of these entity types describes what your company actually does?

What counts is your real activity - not the industry code in the commercial register and not your own marketing self-image. Multiple selections possible. Click a sector to expand it.

No entity type found. Adjust your search or browse the sectors.

How large is your company?

The last adopted annual financial statements are decisive. Employees count as annual work units (full-time equivalents).

EUR m
EUR m
Is your company part of a group, or does it have partner enterprises?

Under the SME definition, the figures of linked and partner enterprises must generally be included - which is how the small German subsidiary of a large group often ends up in scope after all. Section 28 (4) sentence 2 BSIG contains a NIS2-specific exception where the entity is independent in the design and operation of its IT systems.

How the figures are combined
  • Important entity: from 50 employees OR more than EUR 10m turnover AND more than EUR 10m balance sheet total.
  • Essential entity (Annex 1 only): from 250 employees OR more than EUR 50m turnover AND more than EUR 43m balance sheet total.
  • The two financial figures are joined by AND: EUR 60m turnover with a EUR 20m balance sheet total does not reach the large-enterprise threshold.

Get the result by email plus a free initial consultation

We will email you the result together with its reasoning. In the free initial call we then clarify what we can contribute technically - which penetration test provides the evidence in your case. The legal classification and the notification to the BSI remain with you.

Please enter your name.
Please enter a valid email address.
Please enter your company.
That phone number does not look valid.
Please confirm the privacy policy.

Your enquiry has arrived

The result is on its way to your inbox. We will get back to you within one business day - for urgent questions call us directly on +49 9281 5918506.

Want to test a different setup? You can run the check as often as you like.
Non-binding initial assessment: This check is an automated initial assessment. It is not legally binding and does not constitute legal advice. It replaces neither the statutory self-identification duty nor a legal review of your specific case. The classification follows the assessment order of section 28 BSIG and the thresholds of the BSI-KritisV as known to us. Borderline cases - in particular the group-of-companies calculation and the negligible-activity rule of section 28 (3) BSIG - require interpretation and cannot be decided automatically. Public administration (federal, state, municipal) is deliberately not covered, exactly as in the official BSI applicability assessment. Responsibility for correct self-identification always remains with the entity itself.
The basics

What NIS2 means in Germany

NIS2 is EU Directive 2022/2555 on cybersecurity. Germany transposes it through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), an omnibus act affecting 22 laws and regulations that, at its core, completely recasts the BSI Act. Promulgated on 5 December 2025, it has applied since 6 December 2025 - with no transition period. The number of entities supervised by the BSI rises from around 4,500 to roughly 29,500.

Two things determine your classification: which annex of the BSIG your activity is assigned to (Annex 1 or Annex 2), and which size class your company falls into. Operators of critical installations and a handful of special types - qualified trust service providers, TLD registries, DNS and telecommunications providers - are in scope regardless of size. This check applies exactly that order.

Deadlines and status

Where things stand today

6 December 2025

The NIS2UmsuCG enters into force. All substantive obligations apply from that day; there is no transition period.

6 January 2026

The BSI opens its registration portal. Registration runs in two stages, via Mein Unternehmenskonto (an ELSTER organisation certificate) and then the BSI portal.

6 March 2026

Statutory registration deadline under section 33 BSIG. By that date around 17,700 entities had registered - far fewer than the expected 29,500.

31 July 2026

End of the BSI enforcement moratorium. It was never a deadline extension: the administrative offence had existed continuously since 7 March 2026. Since August 2026 the BSI has been inspecting sector by sector, prioritising energy, health and digital infrastructure.

The four outcomes

These classifications are possible

KRITIS

Operator of a critical installation under the BSI-KritisV. Automatically counts as an essential entity, plus attack detection under section 31 and three-yearly evidence under section 39 BSIG.

Essential entity

Annex 1 sectors from large-enterprise size, plus - regardless of size - qualified trust service providers, TLD registries, DNS and larger telecommunications providers. Proactive supervision, fines up to EUR 10m or 2 % of worldwide turnover.

Important entity

Medium-sized enterprises in Annex 1 plus every Annex 2 entity, however large it is. Same obligations, but reactive supervision and fines up to EUR 7m or 1.4 % of worldwide turnover.

Out of scope

No annex sector, no special type, or below the size thresholds. Note: self-identification remains mandatory, and as a supplier to customers in scope, requirements can still reach you contractually.

Frequent questions

NIS2 applicability: the questions that matter

No. The check is an automated initial assessment modelled on the official BSI applicability assessment and is explicitly not legal advice. The duty of self-identification stays with the entity: there is no notice from the BSI telling you that you are in scope.
Register late, and promptly. The statutory deadline expired on 6 March 2026 and the BSI enforcement moratorium on 31 July 2026. An authority cannot extend a statutory deadline, so the infringement has persisted since 7 March 2026 and carries up to EUR 500,000. Late registration at least ends the ongoing infringement.
There are two typical reasons. First, the group calculation: under the SME definition the figures of linked and partner enterprises must generally be included, so the small subsidiary of a large group does cross the thresholds. Second, the size-independent special types - operators of critical installations, trust service providers, TLD registries, DNS and telecommunications providers fall under NIS2 regardless of size.
In terms of obligations, essentially none: risk management under section 30 and the reporting duties under section 32 BSIG are identical for both tiers. The difference lies in supervision - essential entities face proactive supervision with audits even without a trigger, important entities only trigger-based inspection - and in the maximum fines: up to EUR 10m or 2 % of worldwide turnover versus up to EUR 7m or 1.4 %.
No. Annex 2 entities remain important entities regardless of size. They only become essential entities if they additionally operate a critical installation or fall under a size-independent special type. This is a point where self-assessments regularly turn out stricter than the law requires.
Because section 30 BSIG requires effective risk management based on the state of the art, and that effectiveness has to be demonstrated. A penetration test is the recognised instrument for this: it produces a risk picture from real attack paths rather than a self-assessment, serves KRITIS operators as evidence within the meaning of section 39 BSIG, and exposes the entry points before they turn into a reportable incident under section 32 BSIG.
For the size class, yes - partner and linked enterprises must generally be included under EU Recommendation 2003/361/EC, wherever they are based. Section 28 (4) sentence 2 BSIG, however, contains a NIS2-specific exception: where the entity is independent of those enterprises in the design and operation of its IT systems, their data is disregarded. Anyone relying on that should be able to document it.
No, deliberately not - exactly as in the official BSI applicability assessment. Federal administration entities are governed separately by section 29 BSIG: they are treated like essential entities, but without management liability, the supervisory regime or fines. The federal BSIG generally does not cover state and municipal administration, where state law applies.

From the result to the evidence

You now know which tier you are on. The next step is the technical evidence: we assess your attack surface and document the findings mapped directly onto the Article 21 (2) NIS2 requirement catalogue.

Request a free initial consultation
No obligation, no sales pressure. And a straight answer on what your case technically calls for - and what does not belong in our hands.
What we do - and what we do not

Access Granted is a penetration testing provider. We deliver the technical part: penetration tests, attack simulations and reports you can use as evidence for the technical requirements. We explicitly do NOT handle registration with the BSI, the legal classification of your entity, legal advice or certification. This check is therefore meant as a first orientation step, not as proof of compliance.