German Bundestag passes NIS2 Implementation Act: What Entities Need to Know
November 14, 2025
German Bundestag passes NIS2 Implementation Act: What Entities Need to KnowNovember 14, 2025 Germany has taken a major step forward in cybersecurity regulation. On 13 November 2025, the Bundestag has passed the Implementation Act for the EU’s NIS2 Directive (EU) 2022/2555 on network and information security. This milestone follows an implementation delay since October 2024, which triggered an infringement procedure by the European Commission and has led to legal uncertainty for affected entities. Broad Scope of ApplicationThe NIS2 Implementation Act will significantly expand the range of entities subject to cybersecurity obligations. While previous German rules primarily targeted critical infrastructure, the new Act will apply to a much wider set of sectors, including health, transport, digital services, and parts of manufacturing. SMEs are generally exempt from the scope of application. Accordingly, an entity must either (i) employ more than 50 employees or (ii) have an annual turnover and balance sheet total exceeding EUR 10 million to fall within scope. As a rule, thresholds of partnered and linked enterprises must also be included to the calculation, unless the entity exercises decisive influence over the nature and operation of the IT systems, components, and processes that the enterprise uses to provide its services. Germany will also introduce a significant deviation by introducing the criterion of negligible business activities. Highlights of the NIS2 Implementation ActFor affected entities, compliance will require a thorough review of structures, processes and governance across the organisation. Key provisions of the NIS2 Implementation Act include:
Enforcement and PenaltiesThe Act will give the BSI extended supervisory powers, including the ability to conduct audits and issue binding instructions. Entities that fail to comply may face severe consequences. This may not only include fines of up to €10 million or 2% of global annual turnover, but also personal liability of the management body. Beyond financial penalties, organisations risk reputational damage and operational disruption if they fail to meet the new standards. Preparing for ComplianceWith the law now passed by the Bundestag, entities should act immediately. The obligations will take effect shortly after publication in the Federal Law Gazette, leaving entities with limited time to prepare and requiring proactive measures to avoid non-compliance. The first step is to determine whether your organisation qualifies as an essential or important entity under the NIS2 Implementation Act. From there, entities should conduct a subsequent gap assessment and review internal processes, risk management measures and supply chain vulnerabilities. The management body should complete NIS2 compliance training to ensure it is capable of fulfilling its oversight responsibilities. The NIS2 Implementation Act is part of a broader regulatory trend towards resilience and accountability. A separate implementation law on the CER Directive is expected to follow, adding another layer of obligations for critical entities. Companies that invest early in compliance will not only avoid penalties but also strengthen their operational resilience in an increasingly volatile threat landscape. Please reach out to your Eversheds Sutherland team to discuss your next steps around NIS2, its implementation and our NIS2 management training offering. Latest Insights
Latest News
Latest Events
client news June 02, 2026 Next stop, public ownership: Eversheds Sutherland advises DfT on GTR transi... firm news June 01, 2026 Eversheds Sutherland strengthens restructuring offering with senior partner... firm news June 01, 2026 Eversheds Sutherland strengthens Commercial Advisory practice with technolo... client news May 28, 2026 Eversheds Sutherland advises Schroders Greencoat on acquisition of Dutch bi... virtual Spanish employment law training June 02, 2026 2pm - 5pm (BST) Virtual virtual UK employment law training June 09, 2026 1pm - 4pm (BST) Virtual virtual Nordic (Denmark, Finland, Norway and Sweden) employment law training June 16, 2026 12.45pm - 4pm (BST) Virtual virtual Introduction to Swiss employment law June 23, 2026 2pm - 5pm (GMT) Virtual |