NIS2 in Practice: Personal Liability, Documentation Requirements, and What Managing Directors Need to Do Now

Art
Managed Security & SOC Services
Published
15.06.2026


Since December 6, 2025, the NIS2 Implementation Act has been in force—with no transition period and no grace period. For approximately 30,000 organizations in Germany, this means that cybersecurity is now a management responsibility with personal liability for executive leadership. Anyone who treats NIS2 as merely an IT issue fundamentally underestimates what is at stake, as Section 38 of the amended German Federal Office for Information Security Act (BSIG) holds managing directors directly accountable.

 

 

What Is NIS2—and Why Has It Been in Force in Germany Since December 2025?

The EU’s NIS2 Directive, implemented into German law through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), marks a historic shift in Germany’s regulatory landscape. For the first time, executive management can be held personally liable for failures in cybersecurity measures.

Section 38 of the revised German Federal Office for Information Security Act (BSIG) makes this explicit: members of executive management are required to oversee the implementation of cybersecurity measures and may be held personally liable in the event of failure. Under Section 61 BSIG, an unreliable member of executive management may, as a measure of last resort, be temporarily removed from their position. This mechanism was deliberately introduced to elevate cybersecurity from an IT responsibility to a board-level management obligation.

Which Organizations Are Subject to NIS2?

Banking, Digital Infrastructure

Criteria Essential Entities Important Entities
Organization Size Large (>250 emp. or >50 M € annual turnover) Medium-Sized (>50 emp. or >10 M € annual turnover)
Sectors Energy, Healthcare, Water, Manufacturing, Chemicals, Food, Postal Services, Research, and Others
Maximum Fine €10M or 2% of Global Annual Turnover €7M or 1.4% of Global Annual Turnover
Supervision Proactive Oversight by the BSI Reactive Oversight Following an Incident

Compared to its predecessor, the scope of NIS2 has been expanded dramatically—from approximately 4,500 organizations to around 29,500–30,000 organizations across 18 sectors.

Important: The BSI registration deadline expired on March 6, 2026. Organizations that failed to register by this date are already exposed to the risk of regulatory penalties.

NIS2 at a Glance – The Most Important Facts and Figures

  • Effective Since: December 6, 2025 (NIS2 Implementation and Cybersecurity Strengthening Act – NIS2UmsuCG, Federal Law Gazette 2025 I No. 301)
  • Affected Organizations (Germany): Approximately 29,500–30,000
  • Sectors: 18, including Energy, Healthcare, Transportation, Water, IT, and Manufacturing
  • Threshold: Organizations with 50 or More Employees or Annual Revenue Exceeding €10 Million in Relevant Sectors
  • Maximum Fine (Essential Entities): Up to €10 Million or 2% of Global Annual Turnover
  • Personal Liability: Section 38 of the Revised BSIG
  • BSI Registration Deadline: Expired on March 6, 2026

 

What Must Organizations Demonstrably Implement Under NIS2? – The 10 Core Control Areas

Section 30 of the revised BSIG defines ten core areas of risk management that organizations must implement and document:

  1. Risk Assessment and Security Strategy
  2. Incident Management (Detection, Reporting, and Response)
  3. Business Continuity and Crisis Management
  4. Supply Chain Security
  5. Security in the Acquisition, Development, and Maintenance of IT Systems
  6. Assessment of the Effectiveness of Cybersecurity Measures
  7. Training and Cybersecurity Hygiene
  8. Cryptography and Encryption ← Particularly Relevant
  9. Access and Identity Management
  10. Multi-Factor Authentication

 

The term “demonstrably” is deliberate and fundamental: organizations that implement these measures without maintaining proper documentation do not comply with NIS2.

Particularly relevant in practice is Control Area 8: Cryptography and Encryption. It directly affects the management of digital certificates and cryptographic keys—an area in which many organizations lack documented and verifiable processes. This is where NIS2 directly converges with the requirements of Certificate Lifecycle Managements.

What Does NIS2 Governance Mean in Practice for Executive Management?

NIS2 compliance does not begin with a technical control. It begins with a governance decision:

  • Who Is Accountable for Cybersecurity at the Executive Level?
  • Which Processes Are Documented and Auditable?
  • How Is Executive Management Regularly Informed About the Organization’s Cybersecurity Posture?
  • How Is the Escalation Process Defined in the Event of a Security Incident?

In practice, a phased approach is recommended. The first step is a structured GAP assessment against the requirements of ISO 27001, the NIST Cybersecurity Framework (NIST CSF), and NIS2. This assessment provides:

  • A documented analysis of the current state
  • A cybersecurity maturity assessment
  • A prioritized action plan—the foundation for demonstrable compliance and accountable action

Organizations that have not yet taken this step should act now. Not because the BSI will necessarily be knocking on the door tomorrow, but because documented evidence of the organization’s cybersecurity posture can make the difference between demonstrating due diligence and facing personal liability in the event of an incident, audit, or legal dispute.

Conclusion – NIS2 as an Opportunity for Sustainable Cybersecurity

NIS2 is demanding. It requires time, resources, and a willingness to treat cybersecurity as a strategic management issue rather than a purely technical concern.

But it also presents an opportunity: organizations that use the maturity requirements imposed by NIS2 to permanently embed cybersecurity at the board and executive-management level will be better protected, face lower liability risks, and earn greater trust from customers, partners, and insurers.

The first step is always the same: establishing an honest and realistic assessment of your current cybersecurity posture. Without it, NIS2 remains an abstract compliance obligation. With it, NIS2 becomes the foundation for long-term organizational resilience.

 

Manage Now supports your organization from the assessment of your existing security landscape through to demonstrable NIS2 compliance and implementation.

Talk to Our Security Experts →