NIS2UmsuCG · in force since Dec. 2025

NIS2 compliance through
targeted penetration testing

Germany's NIS2 Implementation Act has been binding law since 6 December 2025, obliging around 29,500 companies to implement demonstrable security measures and to register with the BSI. A penetration test is the recognised instrument to meet the requirements of Art. 21 NIS2, and to find real vulnerabilities before attackers do.

NIS2 compliance evidence included Report suitable for regulators Free initial consultation
What you get
Evidence for regulators
Every finding is mapped to Art. 21 NIS2. The report is directly usable for BSI audits.
All relevant attack vectors
Physical, social engineering, infrastructure, AD: we test what NIS2 requires.
Management summary included
Understandable for both board and management and technical teams.
Prioritised remediation plan
Clear recommendations, prioritised by risk and feasibility.
Our final report is suitable for internal audits, BSI notifications, and board-level reporting.
01
Self-check

What is NIS2?

Sec. 28 BSIG distinguishes two obligation tiers based on sector, headcount and financial figures. The employee/turnover thresholds apply alternatively (either one), while turnover AND balance sheet total must both be exceeded together for the financial threshold.

Is your company subject to NIS2?

§ 28 BSIG
< 50

Not affected

  • Fewer than 50 employees
  • Less than €10m annual turnover AND balance sheet total
  • Exception: certain micro-entities in special categories (e.g. trust service providers, DNS) remain in scope regardless of size
≥ 50

Important entity

  • 50+ employees OR
  • More than €10m annual turnover AND more than €10m balance sheet total
  • Active in one of the 18 NIS2 sectors (Annex I or II)
≥ 250

Particularly important entity

  • 250 or more employees OR over €50m turnover AND over €43m balance sheet total
  • In one of the 11 highly critical sectors (Annex I, e.g. energy, health, finance, digital infrastructure)
  • Regardless of size: qualified trust service providers, TLD registries, certain telecom providers

The EU directive itself uses the terms "essential" and "important" entities. German law (BSIG) translates these as "particularly important" and "important entities". Same two-tier concept, just different labels. Not sure where you stand? We'll clarify it in a free initial consultation.

Prefer to work through it step by step?

Our free NIS2 applicability check walks you through the assessment order of section 28 BSIG - including the complete Annex 1 and Annex 2 sector lists and the KRITIS thresholds. The outcome is a non-binding initial assessment with its reasoning, not legal advice and not a binding classification.

Go to the NIS2 applicability check
Affected sectors

18 sectors under Annex I and II

NIS2 covers 18 sectors of the directive. Germany's BSIG groups them into 14: seven in Annex 1 (sectors of high criticality) and seven in Annex 2. Whether you are in scope depends on the combination of sector, type of entity and size.

Energy
Transport
Banking
Financial market infrastructure
Health
Drinking water
Waste water
Digital infrastructure
ICT service providers (B2B)
Public administration
Space
Postal & courier services
Waste management
Chemicals
Food
Manufacturing
Digital providers
Research
02
NIS2 requirements

The complete Art. 21(2) catalogue

Art. 21(2) NIS2 (transposed nationally as Sec. 30(2) BSIG) defines ten measure areas (a-j) that every affected entity must implement. A penetration test provides measurable, technical evidence for most of them.

Art. 21 Abs. 2 (a)

Risk analysis & security concept

NIS2 requires systematic identification and assessment of risks to network and information systems. Our pentest delivers a realistic, current risk picture based on actual attack vectors instead of paper-only compliance.

Physical, Infra, AD pentest
Art. 21 Abs. 2 (b)

Incident handling

Significant security incidents must be reported to the BSI in stages: an early warning within 24 hours, an initial assessment within 72 hours, and, on request, a final report within one month (Art. 23 NIS2). The pentest uncovers the entry points before they turn into a real, reportable incident.

All pentest modules
Art. 21 Abs. 2 (c)

Business continuity & backup

We test whether critical systems and backups are protected against real attacks, including ransomware scenarios, recovery capability and network segmentation as the basis for crisis management and disaster recovery.

Infrastructure pentest
Art. 21 Abs. 2 (d)

Supply chain security

Art. 21(2)(d) in conjunction with Art. 21(3) requires risk assessment of direct suppliers and service providers. Social engineering and OSINT show concretely how attackers can enter your organisation via third parties, remote-access channels, or a compromised supplier.

Social engineering, OSINT
Art. 21 Abs. 2 (e)

Security in acquisition, development & maintenance

New systems and software must be securely procured, developed and maintained, including vulnerability handling and disclosure. Our web app pentest checks exactly these systems, before and after go-live, for exploitable vulnerabilities.

Web app pentest
Art. 21 Abs. 2 (f)

Effectiveness assessment

NIS2 requires procedures to regularly assess the effectiveness of your own risk-management measures. An independent penetration test is exactly that: an objective, technical effectiveness check, not a self-assessment, but a real attack attempt.

All pentest modules
Art. 21 Abs. 2 (g)

Cyber hygiene & security awareness

Basic hygiene practices and regular staff training are mandatory. Our phishing and vishing simulations provide empirical evidence of how effective your awareness measures really are, with hard numbers instead of guesswork.

Social engineering
Art. 21 Abs. 2 (h)

Cryptography & encryption

Policies on the use of cryptography and encryption for data at rest and in transit are mandatory. We test TLS configurations, deprecated protocols (e.g. IKEv1 on VPNs) and unencrypted backups for real-world attack surface.

Infrastructure, web app pentest
Art. 21 Abs. 2 (i)

HR security, access control & asset management

Segmentation, privilege models, privileged access and a clean asset inventory: we test whether your Active Directory and network form a real attack barrier or are only secure on paper.

Infrastructure, AD pentest
Art. 21 Abs. 2 (j)

Multi-factor authentication

MFA or continuous authentication is mandatory for access to network and information systems (Sec. 30(2) no. 10 BSIG in conjunction with CIR 2024/2690), as is secured voice, video and text communication. We systematically test where single-factor access and weak authentication remain exposed.

AD, web app pentest
03
Legal status
In force since 6 Dec 2025

The NIS2 Implementation Act (NIS2UmsuCG) was passed by the Bundestag on 13 Nov 2025, approved by the Bundesrat on 21 Nov 2025, and entered into force on 6 Dec 2025 upon publication in the Federal Law Gazette, with no further transition period. The regular BSI registration deadline (6 March 2026) and the grace period the BSI subsequently granted (31 July 2026) have both since passed. Companies that have not yet registered should do so immediately to avoid regulatory consequences.

Registration status on 30 Jun 2026: roughly 17,700 companies against an estimated 29,500 affected entities (~60%)
Penetration tests as a recognised audit instrument for Sec. 30 BSIG
Our report documents all NIS2-relevant findings
Mapped to the full Art. 21(2) requirements catalogue (a-j)
Usable for internal audits, BSI evidence and board-level reporting
Incident reporting duty

Reporting deadlines under Art. 23 NIS2

A significant security incident triggers a three-stage reporting process with the BSI. These deadlines apply regardless of whether you have already run a pentest, but knowing your attack surface gets you through all three stages much faster.

  1. 24 hours

    Early warning

    A brief notice on whether the incident is suspected to result from unlawful acts or could have cross-border effects.

  2. 72 hours

    Initial notification

    Assessment of the severity and impact of the incident and, where available, initial indicators of compromise.

  3. 1 month

    Final report

    Detailed description of the incident, root cause analysis, mitigation measures taken, and any cross-border impact.

04

What are the consequences of non-compliance?

Particularly important entities: fines of up to €10m or 2% of global group annual turnover, whichever is higher

Important entities: fines of up to €7m or 1.4% of global group annual turnover

Lesser violations (e.g. of cooperation or registration duties) are sanctioned on a graduated scale starting at €100,000

Personal responsibility of management under Art. 20 NIS2 and section 38 BSIG: it must implement the risk management measures and oversee that implementation. Where it fails to, it is liable to its entity under the rules of its legal form.
BSI enforcement powers up to temporary suspension of certifications or of management's authority to act, for particularly important entities
05
Our approach

How does a NIS2 pentest work?

From scoping to NIS2-compliant final report: structured, documented, and designed for demonstrability.

01

Scoping & NIS2 mapping

We jointly define the test scope and map it to the relevant NIS2 requirement articles. This ensures the report delivers the right compliance evidence from the start.

02

Reconnaissance & attack preparation

Information gathering via publicly available sources (OSINT), network scans and attack planning according to the state of the art.

03

Test execution

Manual exploitation within the agreed scope: physical, digital or both. We communicate critical findings immediately so you can act.

04

Analysis & risk assessment

Every finding is rated by severity, exploitability and business impact, with direct reference to the NIS2 requirements catalogue.

05

NIS2 final report & presentation

Complete documentation of all findings with recommendations, management summary and NIS2 compliance mapping. Suitable for BSI audits and internal evidence.

NIS2-Pentest ReportMuster
Server room: no access control (physical)
Art. 21(2)(a) ✓
AD: Kerberoasting, 4 accounts compromised
Art. 21(2)(i) ✓
Phishing simulation: high click rate during test period (example figure)
Art. 21(2)(g) ✓
No network segmentation in place
Art. 21(2)(i) ✓
VPN: deprecated protocol (IKEv1)
Art. 21(2)(h) ✓
Backup: no encryption
Art. 21(2)(h) ✓
10 findings · remediation plan includedNIS2 mapping Art. 21 para. 2 (a-j)
Illustrative example – no real customer data.
29,500
Affected companies in Germany
€10m
Max. fine for particularly important entities
24 h
Early-warning deadline for incidents
100%
Of our reports NIS2-ready
Frequently asked questions

NIS2 & penetration testing: your questions

NIS2 does not prescribe a specific testing method, but requires demonstrable technical security measures (Art. 21). A penetration test is the instrument recognised by supervisory authorities and BSI to meet and document these requirements. Companies without regular security testing risk being unable to demonstrate that adequate measures were in place in the event of an incident.
NIS2 sets no testing interval. A full penetration test at regular intervals is sensible, plus a test after significant IT changes, after security incidents and after introducing new systems. What is appropriate for you depends on size, sector and risk exposure.
Yes. Our final report includes an explicit NIS2 compliance mapping that assigns each finding to the relevant articles of Art. 21 para. 2 NIS2. This makes the report directly usable for BSI audits, internal evidence, and board-level reporting. Management summary included.
The EU directive distinguishes "essential" and "important" entities. Germany's NIS2UmsuCG transposed these into the BSIG as "particularly important" and "important entities", the same two-tier model, just a different German label than the directive text. You're particularly important once you have 250+ employees or €50m+ turnover in one of the 11 highly critical sectors; you're important already from 50 employees or €10m turnover and balance sheet total in any of the 18 NIS2 sectors overall. The practical difference is mainly in supervision: particularly important entities face proactive oversight, important entities a more reactive, complaint-driven approach. The Art. 21 obligations and Art. 20 management liability apply to both tiers equally.
There is no one-size-fits-all answer. Costs depend on too many factors: How large is your organisation? How many sites, systems and employees are in scope? Which NIS2 requirements do you primarily need to address? Do you need a single test module or a combined assessment? All of this significantly affects the effort involved. What we can say: after a free initial consultation we will understand your scope and you will receive a transparent fixed-price offer, no hidden costs, no surprises.
The technical process is identical. The difference is in the reporting. Our NIS2 pentest includes structured compliance mapping to Art. 21 NIS2, a risk-prioritised remediation plan, and a management summary suitable for regulatory authorities. A standard pentest delivers technical findings without this compliance framework.
Yes. The NIS2 directive applies EU-wide. We conduct remote pentests (infrastructure, web app, AD) regardless of location. For physical assessments and social engineering we travel to your site, including outside Germany. Let us know your location and we will find a solution.
Yes. Art. 20 NIS2 and Sec. 38 NIS2UmsuCG require management bodies to personally approve and oversee risk-management measures. A breach can trigger personal liability, regardless of whether the entity is classified as particularly important or important. Waiving this liability via articles of association or bylaws is legally void. A documented, regular penetration test is one of the few concrete ways management can demonstrate it has fulfilled its oversight duty.