The EU's new NIS-2 Directive requires operators of critical infrastructure (KRITIS) and companies in Germany classified as "important" to update their cyber security concepts. Since mid-November 2025, it has been clear that the security standards of the NIS-2 Directive are to be implemented. Find out what NIS-2 is all about and what affected organizations need to pay attention to now.

 

Origin of the directive

On 27.12.2022, the first version of the NIS-2 Directive, which is to be implemented by EU member states and the respective KRITIS organizations from autumn 2025. NIS-2 stands for Network Information Security 2 and is an initiative of the EU Commission to strengthen cyber security.

Its purpose: to make "critical" and "particularly critical" infrastructures more resilient in times of increasing cyber threats. It builds on the first NIS Directive from 2016 and expands the scope to include other sectors such as digital service providers and certain online platforms. Among other things, the directive sets out minimum security requirements for risk management and defines reporting obligations for cybersecurity incidents.

 

What the new NIS-2 directive will change in Germany

NIS 2 defines EU-wide standards and requirements for the security of KRITIS and amends existing guidelines of the German Federal Office for Information Security (BSI). The abbreviation KRITIS stands for critical infrastructures, i.e. organizations and institutions from sectors such as energy supply, water, healthcare, transport and telecommunications. What they all have in common is that they perform fundamental and in some cases vital functions for the community and therefore need to be protected against cyberattacks with particular rigor.

The EU's NIS 2 Directive supplements and expands the protective measures that have already been taken under the previous KRITIS legislation. In addition, however, commercial enterprises are also increasingly affected by the legislation, which, depending on their size and annual turnover, are classified as "important" or "particularly important" facilities be defined. As the threat situation and the methods and technologies used by hackers evolve very quickly.

 

Low awareness of NIS 2 requirements in German companies

According to Bitkom, cyberattacks cost the German economy over 200 billion euros per year. Reason enough for affected organizations to make cyber security a top priority - or so you might think. However, the reality is different: A current survey shows that half of all employees consider a cyberattack on their own company to be unlikely, while only one in four managers is considered to be exemplary in terms of IT security.

What is alarming is the discrepancy between this and the actual likelihood of companies falling victim to a cyberattack: In 2022, the Federal Criminal Police Office registered Over 130,000 cases of cybercrime - which is one of the phenomenon areas with the highest potential for damage in Germany. In particular, the number of crimes committed from abroad that cause damage in Germany is rising sharply. 49 percent of KRITIS infrastructure operators state that they are experiencing a sharp increase in cyberattacks on their company.

 

NIS 2 implementation in German KRITIS companies

In Germany, KRITIS operators must meet both the requirements of KRITIS legislation and the requirements of the NIS 2 Directive. Anyone hearing about this for the first time usually has no precise idea of what this means in concrete terms. In cases of doubt, external cyber security service providers then help with the step-by-step implementation of NIS-2-compliant security concepts. Networks and information systems are first subjected to a comprehensive risk analysis, on the basis of which suitable security measures are then evaluated and implemented.

These include access controls, encryption technologies and an incident response plan (IRP), which enables quick and effective countermeasures to be taken in the event of a cyberattack and limits the potential damage. Raising employee awareness of cyber threats through appropriate training measures is also an integral part of any NIS-2-compliant security concept. ISO27001 provides guidance: ISO27001-certified companies can assume that they meet a large part of the NIS2 requirements.

 

Safety and risk management in accordance with NIS 2

KRITIS operators as well as "important" and "particularly important" institutions are legally obliged by the NIS 2 Directive to implement appropriate, proportionate and effective technical and organizational measures. to take measures. This allows you to protect the IT and processes of the services you provide, avoid disruptions and minimize the impact of security incidents. Important to know: Companies affected by NIS2 must proactively register with the BSI. Failure to do so could result in severe penalties.

It is therefore important for those affected to determine in good time to what extent they are affected by NIS-2 - and what measures are required to meet the new requirements. The numerous security-relevant areas of action include, for example

 

Implement NIS-2 directive via UEM

Ultimately, the NIS-2 directive is about the continuous monitoring and updating of security measures in order to be able to react to dynamic threat situations and the associated requirements. UEM systems play an important role here: they are predestined to support organizations in implementing the requirements of NIS-2.

UEM stands for Unified Endpoint Management. UEM systems manage and control end devices centrally and provide security updates and patches automatically. They also enable security settings to be configured in accordance with company guidelines and compliance standards to be monitored in real time. Unified endpoint systems thus improve the ability to respond to security incidents - and give companies exactly the capabilities they need to meet the requirements of NIS-2.

 

acmp Suite with new NIS-2 security features

The adoption of the NIS-2 Implementation Act in November 2025 will lead to strong pressure on affected companies to implement the requirements. aagon is also keeping an eye on developments in connection with NIS-2 and will be adding new features to the acmp Suite over the course of the year that are aimed at implementing the NIS-2 requirements. These include, for example, multi-factor authentication for the acmp Console, which will be available soon. Via reports and in the Asset and License management our acmp Suite also offers important functions for documentation and thus for risk assessment.

About our interpretation of SOAR (Security Orchestration Automation Response) we also combine various security tools and programs from the acmp environment: Managed Software, Desktop Automation, CAWUM, Vulnerability, Defender and and BitLocker management. This bundling enables companies to use the acmp Suite to react to detected threats in an automated, prioritized and therefore efficient manner. Comprehensive patch management also ensures that deployed software is always provided with the latest security updates.

NIS-2 Directive Summary

In Germany alone, around 30,000 companies need to take action due to the NIS 2 Directive. Decision-makers should therefore quickly check whether they are one of these companies or whether they are indirectly affected as a supplier, as they must register with the BSI independently as "important" or "particularly important" companies. And they should not take much longer to do so: Checking the current security standards and setting up NIS-2-compliant concepts are complex processes - but they can be considerably simplified by using a UEM solution.

 

 

You can find more information on our solution and product pages, in our white papers and guides or in our aagon community:

Legal guide to license management

This legal guide, created with IT law expert Kjell Vogelsang, provides you with clear answers and practical advice on dealing with software licenses.

Guide: IT security

This white paper deals with various aspects of IT security and is directly related to the requirements of the NIS2 directive.

Free trial version

Download & test without obligation!

 

 

Noch Fragen? Wir helfen Ihnen gerne weiter oder vereinbaren Sie direkt einen Termin unter:

 +49 2921 789 200 oder sales@aagon.com