Since December 6, 2025, the NIS2 Implementation Act has been in force—with no transition period and no grace period. For approximately 30,000 organizations in Germany, this means that cybersecurity is now a management responsibility with personal liability for executive leadership. Anyone who treats NIS2 as merely an IT issue fundamentally underestimates what is at stake, as Section 38 of the amended German Federal Office for Information Security Act (BSIG) holds managing directors directly accountable.
