Skip to main content
NIS2

NIS2 Reporting Requirements in Government Draft: What Companies Need to Know Now

The NIS2 government draft introduces a four-stage reporting procedure. Learn which deadlines apply, who is affected, and how to prepare.

Srdan Manasijevic

Srdan Manasijevic

CEO

NIS2 Reporting Requirements in Government Draft: What Companies Need to Know Now

NIS2 Notification Obligations – What the Government Draft Means for Companies

Germany’s cybersecurity landscape is on the verge of a major shift. With the publication of the German government draft for implementing the NIS2 Directive, notification obligations will be significantly tightened and extended to a much larger number of companies.What previously mainly applied to operators of critical infrastructures (CRITIS) will in future affect thousands of organisations across many sectors.


Key Takeaways

  • Four-stage notification process: 24h initial notification, 72h detailed report, interim updates on request, final report after one month

  • Far more companies in scope: All organisations with 50+ employees and €10m+ annual turnover in relevant sectors will be required to notify

  • Act now: Review incident response processes and train teams – even though the text is still a government draft


What is the NIS2 Directive?

The NIS2 Directive (Network and Information Security Directive 2) is the revised EU directive on network and information security. It entered into force in January 2023, replacing the original NIS Directive (2016).Compared to NIS1, NIS2:

  • significantly broadens the scope of sectors

  • raises security requirements

  • and introduces stricter and more detailed reporting duties

Its goal is to establish a high common level of cybersecurity across the EU and to strengthen resilience against cyberattacks.


Who is affected by NIS2 notification obligations?

NIS2 distinguishes between two categories of entities:

  • Essential Entities Traditional critical infrastructures such as energy and water utilities, transport, banks, healthcare

  • Important Entities Newly added and strongly expanding the scope, including:

    • digital service providers and cloud operators

    • waste and wastewater management

    • postal and courier services

    • chemical industry

    • food production and distribution

In principle, companies with:

  • more than 50 employees, and

  • more than €10 million annual turnover,

operating in relevant sectors will fall under NIS2 – and thus under the new notification regime.


The Four NIS2 Notification Stages

NIS2 introduces a multi-step reporting process for significant security incidents.

1. Early Warning (24 Hours)

  • Deadline: without undue delay, at the latest 24 hours after becoming aware of the incident

  • Purpose: rapid alert and initial situational awareness

Content includes:

  • indication of unlawful or malicious actions

  • potential cross-border impact on other EU Member States

👉 Companies must be able to submit this initial notification even with incomplete information.


2. Detailed Report (72 Hours)

  • Deadline: at the latest 72 hours after becoming aware

  • Purpose: more detailed initial assessment

The 72-hour report should include:

  • confirmation or update of the initial notification

  • first assessment of severity and impact

  • known Indicators of Compromise (IoCs)

  • initial evaluation of affected systems and data

This enables authorities to coordinate response and warn other potentially affected entities.


3. Interim Updates (On Request)

  • Trigger: upon request from the Federal Office for Information Security (BSI)

  • Purpose: ongoing status updates for complex or long-running incidents

May include:

  • progress in incident handling

  • new findings regarding root cause or impact

  • updated risk assessments


4. Final Report (After 1 Month)

  • Deadline: at the latest one month after the 72-hour notification

It must contain a comprehensive documentation of the incident, including:a) Detailed description of the incident

  • full timeline

  • concrete business impact

  • affected systems, data and individuals

b) Threat type and root cause analysis

  • technical attack vector

  • exploited vulnerabilities

  • likely motivation/origin of the attacker

c) Remediation measures

  • immediate response actions

  • ongoing remediation activities

  • long-term improvements planned

d) Cross-border impact

  • confirmed or suspected impact in other Member States

  • coordination with foreign authorities

💡 If the incident is still ongoing after one month, an interim progress report is submitted first, with the final report following once remediation is complete.


Step by Step to a Certifiable ISMS

With the fuentis ISMS Tool, you can implement modern standards in an automated and efficient way. Ready-to-use modules, guided workflows and expert support make building an ISMS straightforward, whether you are:

  • starting from scratch, or

  • modernising existing structures.

Multi-Compliance ISMS

  • Complete solution guiding you to ISO 27001 certification

  • Supports BSI IT-Grundschutz, TISAX® and NIS2 in parallel

Automated processes

  • Workflows that guide you step by step through certification – even without prior experience

Review questionnaires

  • Simple, customisable questionnaires to assess protection needs quickly and clearly

Personal support

  • Direct access to experienced consultants – from initial analysis to audit support


Specifics for Critical Infrastructure Operators (CRITIS)

Additional Information Requirements

CRITIS operators must provide additional details whenever incidents impact (or could impact) critical infrastructures, such as:

  • Type of critical facility

  • Critical service affected

  • Scale and duration of impact (customers affected, regions, outage duration etc.)


Joint Reporting Point & Coordination

  • A joint reporting platform will be set up by BSI and BBK (Federal Office of Civil Protection and Disaster Assistance)

  • Companies submit reports once and the authorities coordinate internally

Benefits:

  • no need for parallel reporting to multiple bodies

  • automatic forwarding to relevant supervisory authorities

  • potential active support from BSI in handling incidents


Practical Implementation and Reporting Channel

Joint BSI/BBK Reporting Platform

  • The technical platform will be set up jointly

  • Reporting obligations only become enforceable once the platform is operational

The BSI will:

  • define detailed reporting procedures after consulting stakeholders

  • publish requirements and guidance on its website


Support from BSI

Reporting entities may receive:

  • technical support during incident handling

  • forensic assistance

  • coordinated communication with other authorities and experts


What Companies Should Do Now

  1. Review and adapt incident response processes

    • Align with 24h / 72h / 1-month deadlines

    • Define escalation paths

    • Establish criteria for “significant” security incidents

  2. Clarify responsibilities

    • Set up an incident response team

    • Ensure 24/7 availability

    • Define backup roles and decision-making authority

  3. Prepare technical capabilities

    • Enhance logging and monitoring

    • Secure forensic capabilities (in-house or external)

    • Test backup and recovery processes

    • Define crisis communication channels

  4. Create documentation & templates

    • Templates for each notification stage

    • Checklists for incident handling

    • Up-to-date contact lists (internal & external)

  5. Run tests and training

    • Conduct IR exercises

    • Simulate reporting processes

    • Train staff to detect and escalate incidents

    • Raise awareness of NIS2 timelines and obligations


Outlook and Next Steps

  • The German government draft is currently in the parliamentary process; entry into force is expected around 2025.

  • Notification obligations will only apply once the joint reporting platform is technically available.

  • Further details will follow from BSI guidance and EU implementing acts.


Conclusion

The planned NIS2 notification obligations represent a fundamental tightening of cybersecurity requirements in Germany. The four-stage process – from 24-hour early warning to a one-month final report – will challenge many organisations that have never dealt with such strict deadlines before.

Important: This description is based on a government draft and may change during the legislative process. Final legal requirements may differ. Companies should closely monitor further developments and BSI publications.NIS2 Notification Obligations – What the Government Draft Means for Companies

Germany’s cybersecurity landscape is on the verge of a major shift. With the publication of the German government draft for implementing the NIS2 Directive, notification obligations will be significantly tightened and extended to a much larger number of companies.

What previously mainly applied to operators of critical infrastructures (CRITIS) will in future affect thousands of organisations across many sectors.


Key Takeaways

  • Four-stage notification process: 24h initial notification, 72h detailed report, interim updates on request, final report after one month

  • Far more companies in scope: All organisations with 50+ employees and €10m+ annual turnover in relevant sectors will be required to notify

  • Act now: Review incident response processes and train teams – even though the text is still a government draft


What is the NIS2 Directive?

The NIS2 Directive (Network and Information Security Directive 2) is the revised EU directive on network and information security. It entered into force in January 2023, replacing the original NIS Directive (2016).

Compared to NIS1, NIS2:

  • significantly broadens the scope of sectors

  • raises security requirements

  • and introduces stricter and more detailed reporting duties

Its goal is to establish a high common level of cybersecurity across the EU and to strengthen resilience against cyberattacks.


Who is affected by NIS2 notification obligations?

NIS2 distinguishes between two categories of entities:

  • Essential Entities Traditional critical infrastructures such as energy and water utilities, transport, banks, healthcare

  • Important Entities Newly added and strongly expanding the scope, including:

    • digital service providers and cloud operators

    • waste and wastewater management

    • postal and courier services

    • chemical industry

    • food production and distribution

In principle, companies with:

  • more than 50 employees, and

  • more than €10 million annual turnover,

operating in relevant sectors will fall under NIS2 – and thus under the new notification regime.


The Four NIS2 Notification Stages

NIS2 introduces a multi-step reporting process for significant security incidents.

1. Early Warning (24 Hours)

  • Deadline: without undue delay, at the latest 24 hours after becoming aware of the incident

  • Purpose: rapid alert and initial situational awareness

Content includes:

  • indication of unlawful or malicious actions

  • potential cross-border impact on other EU Member States

👉 Companies must be able to submit this initial notification even with incomplete information.


2. Detailed Report (72 Hours)

  • Deadline: at the latest 72 hours after becoming aware

  • Purpose: more detailed initial assessment

The 72-hour report should include:

  • confirmation or update of the initial notification

  • first assessment of severity and impact

  • known Indicators of Compromise (IoCs)

  • initial evaluation of affected systems and data

This enables authorities to coordinate response and warn other potentially affected entities.


3. Interim Updates (On Request)

  • Trigger: upon request from the Federal Office for Information Security (BSI)

  • Purpose: ongoing status updates for complex or long-running incidents

May include:

  • progress in incident handling

  • new findings regarding root cause or impact

  • updated risk assessments


4. Final Report (After 1 Month)

  • Deadline: at the latest one month after the 72-hour notification

It must contain a comprehensive documentation of the incident, including:

a) Detailed description of the incident

  • full timeline

  • concrete business impact

  • affected systems, data and individuals

b) Threat type and root cause analysis

  • technical attack vector

  • exploited vulnerabilities

  • likely motivation/origin of the attacker

c) Remediation measures

  • immediate response actions

  • ongoing remediation activities

  • long-term improvements planned

d) Cross-border impact

  • confirmed or suspected impact in other Member States

  • coordination with foreign authorities

💡 If the incident is still ongoing after one month, an interim progress report is submitted first, with the final report following once remediation is complete.


Step by Step to a Certifiable ISMS

With the fuentis ISMS Tool, you can implement modern standards in an automated and efficient way. Ready-to-use modules, guided workflows and expert support make building an ISMS straightforward, whether you are:

  • starting from scratch, or

  • modernising existing structures.

Multi-Compliance ISMS

  • Complete solution guiding you to ISO 27001 certification

  • Supports BSI IT-Grundschutz, TISAX® and NIS2 in parallel

Automated processes

  • Workflows that guide you step by step through certification – even without prior experience

Review questionnaires

  • Simple, customisable questionnaires to assess protection needs quickly and clearly

Personal support

  • Direct access to experienced consultants – from initial analysis to audit support


Specifics for Critical Infrastructure Operators (CRITIS)

Additional Information Requirements

CRITIS operators must provide additional details whenever incidents impact (or could impact) critical infrastructures, such as:

  • Type of critical facility

  • Critical service affected

  • Scale and duration of impact (customers affected, regions, outage duration etc.)


Joint Reporting Point & Coordination

  • A joint reporting platform will be set up by BSI and BBK (Federal Office of Civil Protection and Disaster Assistance)

  • Companies submit reports once and the authorities coordinate internally

Benefits:

  • no need for parallel reporting to multiple bodies

  • automatic forwarding to relevant supervisory authorities

  • potential active support from BSI in handling incidents


Practical Implementation and Reporting Channel

Joint BSI/BBK Reporting Platform

  • The technical platform will be set up jointly

  • Reporting obligations only become enforceable once the platform is operational

The BSI will:

  • define detailed reporting procedures after consulting stakeholders

  • publish requirements and guidance on its website


Support from BSI

Reporting entities may receive:

  • technical support during incident handling

  • forensic assistance

  • coordinated communication with other authorities and experts


What Companies Should Do Now

  1. Review and adapt incident response processes

    • Align with 24h / 72h / 1-month deadlines

    • Define escalation paths

    • Establish criteria for “significant” security incidents

  2. Clarify responsibilities

    • Set up an incident response team

    • Ensure 24/7 availability

    • Define backup roles and decision-making authority

  3. Prepare technical capabilities

    • Enhance logging and monitoring

    • Secure forensic capabilities (in-house or external)

    • Test backup and recovery processes

    • Define crisis communication channels

  4. Create documentation & templates

    • Templates for each notification stage

    • Checklists for incident handling

    • Up-to-date contact lists (internal & external)

  5. Run tests and training

    • Conduct IR exercises

    • Simulate reporting processes

    • Train staff to detect and escalate incidents

    • Raise awareness of NIS2 timelines and obligations


Outlook and Next Steps

  • The German government draft is currently in the parliamentary process; entry into force is expected around 2025.

  • Notification obligations will only apply once the joint reporting platform is technically available.

  • Further details will follow from BSI guidance and EU implementing acts.


Conclusion

The planned NIS2 notification obligations represent a fundamental tightening of cybersecurity requirements in Germany. The four-stage process – from 24-hour early warning to a one-month final report – will challenge many organisations that have never dealt with such strict deadlines before.

Important: This description is based on a government draft and may change during the legislative process. Final legal requirements may differ. Companies should closely monitor further developments and BSI publications.

Despite this uncertainty, early preparation is strongly recommended:

  • build robust incident response processes,

  • train teams,

  • and clarify responsibilities now.

Organisations that start preparing today will be significantly better positioned once NIS2 notification obligations become binding.


Are you affected by NIS2?

Despite this uncertainty, early preparation is strongly recommended:

  • build robust incident response processes,

  • train teams,

  • and clarify responsibilities now.

Organisations that start preparing today will be significantly better positioned once NIS2 notification obligations become binding.


Are you affected by NIS2?

Srdan Manasijevic

Srdan Manasijevic

CEO

Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI and advanced risk methodologies.

From reading to doing: your ISMS with fuentis

ISO 27001, BSI IT-Grundschutz, TISAX and NIS2 in one platform – the free/Basic plan is €0 for 12 months.