Cinthia Trevisoli

Cinthia Trevisoli

Dec 18, 2023   •  2 min read

NIS2 Guideline - What german companies need to know now

NIS2 guideline: What German companies need to know now

The EU cybersecurity landscape is undergoing a significant change as a result of the NIS2 Directive and its German implementation, the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS-2UmsuCG). This article provides an overview of the specific compliance requirements for German companies and what this means for future management. Additionally, it offers a guideline for navigating these new regulations effectively, ensuring that companies can know their obligations and need to enhance their cybersecurity measures in alignment with the Directive's goals.

What is the NIS-2UmsuCG?

The draft bill from the Federal Ministry of the Interior forms the basis for the German compliance requirements of the NIS2 directive. This is intended to create a coherent level of cybersecurity in the EU and includes expanded requirements and sanctions.

Compliance requirements for German companies

German companies must evaluate themselves based on defined criteria. This criteria concern, among other things, the size of the company and the industry. Executives now have direct responsibility for identifying and addressing cyber risks.

Key measures include:

  • Cyber risk management: Companies must implement and continually develop effective risk management.
  • Security in the supply chain: Security must also be guaranteed with third-party providers.
  • Business Continuity Management: Companies must be prepared to maintain their operational capability even in crisis situations.
  • Encryption and access restrictions: Data must be managed and protected securely.
  • Reporting to the authorities: Incidents and security gaps must be reported in a timely manner.

Tiered fine concept

Failure to comply could result in fines of up to 20 million euros. The amount depends on the degree of fault and type of facility.

Affected sectors

The NIS2 directive covers a wide range of sectors, from energy to space. Each company must check for itself whether it falls under the directive.

Conclusion

The NIS2 Directive is a complex and far-reaching law that redefines cybersecurity practices in Germany and the EU. Companies are well advised to quickly understand and implement the requirements to ensure both security and compliance.

It is crucial that companies take the requirements of the NIS2 Directive seriously and implement appropriate compliance measures. This requires careful review of your own processes and possibly extensive adjustments.

NIS2 Guideline: Leverage CCNet Offering for Tailored IT Inventory

NIS2 Guideline: Leverage CCNet Offering for Tailored IT Inventory

In the climactic conclusion of our enlightening series on the NIS2 directive, we're excited to unveil a powerful solution that can leverage your efforts to align with the directive's stringent standards and fortify your IT infrastructure against potential threats. The CCNet offering elevates your compliance journey by providing a complimentary ...

    CCNet

    CCNet

    Mar 14, 2024   •  2 min read

Overcoming the Hurdles: Effective Strategies for Implementing NIS2

Overcoming the Hurdles: Effective Strategies for Implementing NIS2

The implementation of the NIS2 Directive poses challenges for many companies. This article highlights the most common difficulties and offers practical solutions to overcome them successfully. The Complexity of the Rules The NIS2 Directive is extensive and complicated. Approach: Invest in upskilling your compliance teams and bring in cybersecurity experts ...

    Cinthia Trevisoli

    Cinthia Trevisoli

    Mar 14, 2024   •  1 min read

Verification of NIS2 compliance by German authorities: An overview

Verification of NIS2 compliance by German authorities: An overview

Introduction: With the introduction of the European Union's NIS2 directive, companies are facing new challenges in the area of cybersecurity. In Germany, compliance with this directive is monitored by the responsible authorities. This article provides an overview of how the NIS2 compliance review by German authorities is likely to proceed. ...

    CCNet

    CCNet

    Mar 14, 2024   •  1 min read