NIS2 Scope Checker Germany
Are you a besonders wichtige or wichtige Einrichtung under the German BSIG (NIS2UmsuCG, in force since 6 December 2025)? Answer seven questions, get your likely classification, the duties that follow, and matched providers from the directory.
Logic reviewed against the BSIG as amended through 29 July 2026. Last reviewed: September 2026.
1. Establishment
Where is your organization established? The German BSIG governs entities established in Germany; other cases follow other rules.
2. Public sector
Federal entities follow § 29 BSIG. Länder and municipal entities often follow state IT security laws.
3. Activities (select all that apply)
Map your activities to the BSIG entity types. Multiple selections are possible; the strongest match wins.
4. Size
Enter your own figures. If your IT systems, components and processes are operated jointly with or by partner or linked enterprises, enter group-wide figures instead (§ 28(4) BSIG).
5. Fine-tuning
IT operated independently
Your IT systems, components and processes run independently of partner or linked enterprises, so their figures stay out of your size calculation (§ 28(4) sentence 2 BSIG).
Annex activity is negligible
The Annex-1/2 activity is negligible relative to your overall business, so it can be disregarded when mapping entity types (§ 28(3) BSIG).
DORA financial entity or telematics operator
Credit institutions and DORA-scoped financial entities, or gematik Telematikinfrastruktur operators: the sectoral regime replaces most BSIG duties (§ 28(6) BSIG).
Runs entirely in your browser. Nothing you enter is transmitted or stored.
How the classification works
§ 28 of the BSIG sorts affected organizations into two classes. The checker evaluates the same paths the law defines, in the order the law applies them:
- KRITIS: operators of critical facilities designated under the BSI-KritisV thresholds are particularly important entities regardless of size (§ 28(1) sentence 1 no. 1 BSIG).
- Digital backbone: DNS service providers, top-level-domain registries and qualified trust service providers are particularly important regardless of size (§ 28(1) no. 2); non-qualified trust service providers are important regardless of size (§ 28(2) no. 1).
- Telecommunications: providers of public telecom networks and publicly accessible telecom services are particularly important at 50+ employees or EUR 10M+ turnover and balance-sheet total (§ 28(1) no. 3), and important even below that line (§ 28(2) no. 2). Their sectoral duties live in the Telecommunications Act (§ 28(5)).
- Annex 1 sectors (energy, transport, banking/finance, health, water, digital infrastructure, space): particularly important at 250+ employees or EUR 50M+ turnover plus EUR 43M+ balance-sheet total; otherwise important at 50+ employees or EUR 10M plus EUR 10M (§ 28(1) no. 4, § 28(2) no. 3).
- Annex 2 sectors (postal/courier, waste, chemicals, food, manufacturing, online platforms, research): important under the same medium-size line, never besonders wichtig by size alone (§ 28(2) no. 3).
- Adjustments: negligible Annex-listed activities can be disregarded in the sector mapping (§ 28(3)); partner and linked enterprises stay out of the size calculation only while your IT runs independently of them (§ 28(4)); DORA financial entities and telematics operators keep the classification but follow their sectoral regime (§ 28(6)).
Duties if you are affected
- Register with the joint BSI/BBK portal within 3 months of becoming affected, and report changes within 2 weeks (§ 33 BSIG).
- Implement and document appropriate technical and organisational security measures (§ 30 BSIG).
- Report significant incidents: 24-hour early warning, 72-hour notification, final report within one month (§ 32 BSIG).
- Management approves, monitors and oversees the measures, and takes training; personal liability for managers is possible (§ 38 BSIG).
- Proactive supervision with ordered audits for particularly important entities (§ 61), backstop supervision for important entities (§ 62); fines up to EUR 10M / 2 percent versus EUR 7M / 1.4 percent of group turnover above EUR 500M (§ 65 BSIG).
Two sectoral regimes replace parts of that package: telecom activities owe their security and reporting duties to the Telecommunications Act instead (§ 28(5) BSIG), and DORA financial entities or telematics-infrastructure operators follow DORA or the telematics rules (§ 28(6) BSIG). The checker reflects this in your result.
Providers tagged for NIS2 in the directory
As of September 2026, ISMS Directory lists 40 providers with a sourced NIS2 capability tag. Listing is free and data-driven: positions below are alphabetical, not ranked and not paid.
Polish GRC software platform for integrated risk, compliance, audit, and information security management including ISO 27001 programs.
Provider of ISO 27001 documentation, training, and consultancy services to help businesses achieve compliance.
*** Helping Businesses Achieve Compliance & Certification Success *** Bitsecura is a IT governance, risk, and compliance (GRC) firm specialising in helping organisations protect their critical assets, navigate complex regulatory landscapes, and build sustainable cybersecurity frameworks. With over 20 years of industry experience, we offer strategic guidance, bespoke solutions, and operational support that align seamlessly with your business objectives. Our commitment to practical innovation and long-term partnerships ensures that working with Bitsecura not only strengthens your current security posture, but also builds a lasting foundation for future resilience.
Integrated and comprehensive solution to assist Governance, Risk and Compliance
Circl3.tech is a Cyprus-based cybersecurity advisory firm specialising in vCISO services, information security governance, risk management, and regulatory compliance. Founded by Panos Panayiotou — an ISO/IEC 27001 Lead Implementer (Senior) and seasoned CISO with over 25 years of experience across banking and government sectors — Circl3.tech supports public and private sector organisations in designing and implementing cybersecurity frameworks, ISMS control environments, and strategic security programmes aligned with ISO/IEC 27001 and NIS requirements.
Compleye provides a user-friendly compliance platform to help companies achieve ISO 27001, SOC 2, ISO 9001, and GDPR compliance quickly and efficiently.
ContrailRisks is a Berlin-based strategic advisory firm delivering lean, high-impact cybersecurity & risk management solutions. We help businesses identify vulnerabilities, implement tailored strategies, and enhance operations—minimizing risks, reducing costs, and boosting resilience.
FEHA is an AI and Human powered platform supporting businesses to comply with various frameworks and regulations, and prepare for certification, seamlessly.
One Platform. Total Control. FullyInControl is a modular Integrated Management Platform that unifies GRC, ISMS, PIMS, QHSE, ESG, BCM & audit in one workspace. Plug-and-play standards, shared data core and smart workflows give you real-time oversight, faster audits and continuous improvement.
GRASP compliance platform helps organizations build and operate a structured ISMS. The platform enables centralized management of risks, actions, and evidence, ensures transparency and traceability, and supports full compliance with ISO 27001 requirements.
Polish GRC and SAP security consultancy with 15+ years of enterprise access governance, SoD, and risk-compliance implementations.
UK cyber security and compliance group (formerly IT Governance) for ISO 27001 consultancy, training, toolkits, and multi-framework programs.
Frequently asked questions
Do the German NIS2 rules (BSIG) apply to my organization?
The BSIG entity regime (§ 28) applies to organizations established in Germany that map to a listed entity type: designated KRITIS operators, telecom and DNS/trust-service providers, and medium or large companies in the Annex 1 and Annex 2 sectors. Sizes: particularly important (besonders wichtige) entities are 250+ employees or EUR 50M turnover plus EUR 43M balance-sheet total; important (wichtige) entities are 50+ employees or EUR 10M plus EUR 10M. Several entity types are in scope regardless of size.
Bin ich NIS2-pflichtig, wenn die Registrierungsfrist im März 2026 verstrichen ist?
Yes, the duty does not go away. The BSIG entered into force on 6 December 2025, so entities already affected at that point owed their BSI registration by 6 March 2026 (§ 33(1) BSIG). The BSI reported that registrations continued after the deadline, and late registration is still owed. New entities (for example after crossing a size threshold) get 3 months from that point.
What is the difference between besonders wichtige and wichtige Einrichtungen?
Both owe registration (§ 33), risk-management measures (§ 30), incident reporting on the 24h/72h/1-month clocks (§ 32) and management oversight (§ 38). The differences are supervision and fines: particularly important entities face proactive supervision including ordered audits (§ 61) and fines up to EUR 10 million or 2 percent of worldwide group turnover above EUR 500 million; important entities face backstop supervision (§ 62) and up to EUR 7 million or 1.4 percent (§ 65 BSIG). Two sectoral carve-outs apply: telecom activities follow the Telecommunications Act instead (§ 28(5)), and DORA financial entities or telematics operators follow their own regime (§ 28(6)).
Is this checker an official BSI tool?
No. It is a neutral orientation aid built on the classification logic of § 28 BSIG, maintained by ISMS Directory with a dated review stamp. The BSI operates the authoritative self-assessment (betroffenheitspruefung-nis-2.bsi.de) and the registration portal. Our added value: the same page shows directory providers with a sourced NIS2 capability tag, with no paid placement.
