Blog

NIS2 Six Months In: What German Businesses Still Get Wrong

NIS2 Six Months In: What German Businesses Still Get Wrong
The rules are being enforced. Most German firms are being audited on documentation, not security. Here is what to fix before the next enforcement wave arrives.

images-4-96add8.webp

Six months since NIS2 became enforceable in Germany, one pattern is clear: the businesses being audited aren't the ones with the biggest security gaps. They're the ones who can't document what they have.


Here's what we're seeing, and what your firm should do about it.


I. What NIS2 Requires


The NIS2 Directive is enforced in Germany via the NIS2 Implementation Act, which mandates strict cybersecurity governance and mandatory incident reporting for approximately 40,000 entities covering 18 sectors across the EU: banking, energy, telecoms, plus manufacturing, food production, postal services, waste management, chemicals, and digital services. The directive applies to medium and large organisations, which means if you have more than 50 employees or €10 million or more in annual revenue and operate in a covered sector, you're in scope.


Technical and organisational cybersecurity measures

Incident reporting: 24 hours (Initial warning), 72 hours (Intermediate assessment), 1 month (Final report)

Board-level accountability for cybersecurity

Supply chain security: Your vendors are your responsibility

Registration with the BSI


Fines up to €10 million or 2% of global annual turnover, plus personal liability for senior management under certain conditions.


II. What We're Seeing at Six Months


The BSI's approach hasn't been dramatic, just a few headline fines. What's happened is quieter: audits, documentation requests, and “compliance conversations” with companies that couldn't show a working regime.


The audits focus on three questions:

Can you show your inventory of critical IT systems?

Can you show documented board-level responsibility?

Can you show your incident-response process and evidence you've tested it?


A well-secured company with poor documentation looks worse in an audit than a poorly secured-company with excellent documentation.


III. Three Things Most German Firms Still Get Wrong

images-ca3722.webp

Gap 1 · No Documented AI Inventory: Most firms use AI in some form: ChatGPT, Copilot, cloud tools embedded in workflows. NIS2 requires you to document what data each tool touches, where it goes, and who's responsible. When BSI asks for the inventory, most firms produce a list of five tools that misses the twenty-five that aren't obvious.


Gap 2 · Supply Chain Security: NIS2 makes you responsible for your vendors' security posture. That means: a documented list of every third-party service, contractual obligations, and ongoing assessment. The most common failure is small: a CRM, an email marketing tool, a payroll SaaS. Any can be your NIS2 gap.


Gap 3 · Board-level Accountability: That means: a named board member accountable for cybersecurity, documented board training, regular reporting. Most mid-market companies have IT teams doing the work but no formal documentation of board oversight. The fix isn't expensive: one hour of a board meeting, formalised and repeated quarterly. Most firms haven't done it.


IV. The Next Enforcement Wave


Based on BSI communications, the next six months will focus on:

▸ AI-specific Documentation: Where data goes, EU AI Act cross-references

▸ Cross-border Data Transfers: Cloud services outside the EU face particular scrutiny

▸ Incident-response Testing: A written plan is no longer enough; evidence of tests is now expected

▸ Supply-chain Audits: Documentation from your vendors, not just about them


V. Five Steps to Take This Quarter


1. Do the AI Inventory: Every tool, where the data goes, who's responsible.

2. Name Your Accountable Board Member: In writing, plus documented cybersecurity training.

3. Audit Your Top Ten Vendors: NIS2 status in writing. Update contracts if needed.

4. Test Your Incident-response Plan: A two-hour tabletop exercise. Document everything.

5. Move Client-sensitive AI Use On-premise: For legal, healthcare, financial or forensic firms, cloud AI is a NIS2 exposure.


You don’t need to be perfect. You need to be documented.


How Sinabis Helps

screenshot-2026-07-07-at-11-10-54-2d5b08.webp

Sinabis Assistant is on-premise AI built for the firms NIS2 is now auditing: legal teams, forensic specialists, healthcare providers, public-sector bodies, and any organisation whose work depends on client data staying inside its own walls. The whole system runs on your own hardware, with no cloud dependency, and no data crossing borders you didn't explicitly authorise.


Every interaction is logged and versioned by design, which means using Sinabis Assistant is compatible with the regulatory environment you already operate in, not a new compliance project on top of it. For BSI audits, for court proceedings, and for the everyday work of firms whose output has to be defensible, that difference matters.


→ Learn more: sinabis.com

Sinabis Analytics GmbH · X64 Forensic GmbH · X64 Systems GmbH