Contact Deutsch

ISiCO GmbH
Skip navigation
  • Privacy

    Get a head start with our optimal data protection consultancy

    Secure your competitive advantage with our business-focused data protection expertise.

    • Data Protection Consulting
      • Data Protection Impact Assessment (DPIA)
      • Threat Modelling
      • Data Breaches
      • Records of Processing Activities (ROPA)
      • Communication & Procedures with Authorities
      • Employee Data Protection
      • Data Protection Management System
      • Erasure and Archiving Policies
    • External Data Protection Officer
    • Data Protection Audits
    • EU Representative
    • Whistleblower Protection Act
  • IT Security

    Reliable protection for your company

    Make use of our expertise and customised IT security solutions to protect your digital assets.

    • External Information Security Officer (ISO)
    • ISMS
    • ISO 27001 Certification
    • Ransomware Protection
    • Risk Management
    • IT Compliance
    • NIS2
    • DORA
    • TISAX Certification
    • IT Forensics
  • AI Consulting

    Gain a competitive edge with the best AI advice

    Secure your competitive advantage with our business-focused AI expertise.

    • ISO 42001 Certification
    • External AI Officer
  • Data Strategy

    Make the most of your data

    We will show you how to unlock the full potential of your company's data.

    • Develop data strategy
  • Solutions

    We create solutions for all challenges

    Whether you need advice on data protection management, its implementation, or employee training, we can provide the solution you need as part of a corporate network.

    • DPO Coaching
    • Privacy Solution Software caralegal
    • E-Learning from lawpilots
  • Company

    Customised, efficient and business-oriented

    ISiCO is one of the top addresses in Germany for management consultancy in data protection, information security, AI and data strategies.

    • About ISiCO
    • Team
    • News
    • Contact
  • Make an appointment

29.07.2025

NIS2 implementation is coming: German government aims for entry into force by early 2026

The process of implementing the EU NIS2 Directive into German law is gathering pace. A concrete plan for its implementation is finally on the table. However, many companies still seem to underestimate its significance. Read on to find out what needs to be done now.

Arrange a non-binding initial consultation
Your ISiCO-Expert:
Dr. Jan Scharfenberg
Director Information Security

Specific timeframe for NIS2 implementation in Germany

According to media reports, plans to implement the EU's NIS2 Directive into German law in the form of the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) are taking shape.

Claudia Plattner, President of the Federal Office for Information Security (BSI), told the German Press Agency:

"I am hopeful that we will be able to enact it at the beginning of 2026."

This finally provides a realistic target date for the NIS2 Implementation Act to take effect nationally. Preparations are already underway at the Federal Ministry of the Interior, and the first associations and federal states have been consulted.

The EU Commission is also exerting pressure; on 28 November 2024, it initiated infringement proceedings against Germany due to the delay in implementing the directive.

This was followed on 7 May 2025 by an official reasoned opinion. Germany was asked to respond within two months; otherwise, it will face financial sanctions or referral to the European Court of Justice.

More companies will be affected than ever before

The implementation of NIS2 will dramatically increase the number of organisations affected, from around 4,500 to around 29,000. According to Plattner, many companies are still unaware of their future responsibilities. She therefore urges them to address the issue at an early stage.

What should companies do now?

The requirements of the NIS2 Directive are complex, but can be met through early planning. The following steps will help you get started:

1. Clarify whether you are affected

Whether your company falls under the NIS2 Directive depends on various factors, such as industry, company size, and turnover. In many cases, this can be determined by answering a few questions, for example using our online check.

2. Define responsibilities

Who is responsible for NIS2 in your company? Initial responsibilities could lie with management, IT management or the compliance team, for example. Clarity at an early stage saves a lot of time later on.

3. Create an orientation

Get an overview of the typical requirements that NIS2 will impose on you. These include, among other things:

  • Risk analyses and risk management
  • Appropriate technical and organisational security measures
  • Reporting obligations in the event of security incidents.

Do you require assistance with NIS2 implementation?

If you require assistance with any of these steps, we would be pleased to discuss your requirements with you personally. Now is the right time to prepare – before NIS2 becomes law.

Non-binding initial consultation about the implementation of NIS2

  • Detailed analysis: A thorough examination of all IT security processes to clearly identify risks and vulnerabilities.
  • Effective action plan: A concrete, prioritised plan outlining the steps required to meet NIS2 requirements.
  • Sustainable IT security: A long-term strategy that closes current security gaps and protects your organisation against future threats.

Arrange a non-binding initial consultation

Back to the news overview

Berlin
Köln
München

Ready for the next step?

+49 30 21300285-0
info@isico.de

Directly to get to know us

 

Outstanding work

ISiCO is also an active member of the German Association for Data Protection and Data Security (GDD) and the German Association for Information Technology, Telecommunications and New Media (Bitkom).

Top-Links
Skip navigation
  • External Data Protection Officer
  • Data Protection Management System
  • Data Breaches
  • ISMS
Find out more
Skip navigation
  • About ISiCO
  • Team
  • Contact

Language

DE EN

© ISiCO GmbH | Contact | Imprint | Privacy | Privacy Settings