

On December 6, 2025, Germany's NIS2 Implementation Act (NIS2UmsG) entered into force, transposing the EU's NIS2 Directive into national law more than a year after the original deadline. The Act substantially revises the BSI Act (BSIG) and expands the scope of regulated entities from roughly 4,500 to around 29,500, a sevenfold increase that pulls thousands of medium-sized companies into the supervision of the Federal Office for Information Security (BSI) for the first time.
Small businesses with fewer than 50 employees and under €10 million in turnover generally remain exempt. Midsize startups and SMBs above those thresholds operating in in-scope sectors, including digital services, manufacturing, health, transport, and data processing, are very likely covered and should act now.
The revised BSI Act classifies regulated organizations into two tiers, mirroring the NIS2 Directive:
Classification is based on a combination of sector and size. If your company has more than 50 employees or exceeds €10 million in both annual turnover and balance sheet total, and operates in one of the sectors named in Annexes 1 or 2 of the BSI Act, you are likely in scope. Companies must self-assess and document their applicability, the BSI does not notify you.
Unlike most EU regulations, the NIS2 Implementation Act came into force with no transition period. Obligations apply immediately. The March 6, 2026 registration deadline has passed, meaning any in-scope company that hasn't yet registered, self-assessed, and started implementing risk management measures is already non-compliant.
Meeting NIS2 from a standing start is demanding, but it doesn't require hiring a team of consultants. Secfix is Europe's end-to-end security compliance platform, built specifically for startups and SMBs navigating frameworks like NIS2, ISO 27001, SOC 2, and TISAX. In fact, companies become compliant up to 90% faster with Secfix.
With Secfix you get:
Enforcement is live, deadlines have passed, and the BSI is now actively supervising tens of thousands of companies that have never dealt with regulatory cybersecurity before. Get ahead of it. Book a free Secfix demo today and see how quickly we can get your company NIS2-compliant.
Entdecken Sie Geschichten, Tipps und Ressourcen, die Sie zu Ihrer nächsten großen Idee inspirieren.

Der Secfix Agent ist ein leichtes Programm, das täglich im Hintergrund auf den Computern Ihrer Mitarbeiter läuft, um die Sicherheit zu überprüfen
Kostenloses SaaS-Webinar jetzt für alle unsere Besucher geöffnet