NIS2 Notification Obligations – What the Government Draft Means for Companies
Germany’s cybersecurity landscape is on the verge of a major shift. With the publication of the German government draft for implementing the NIS2 Directive, notification obligations will be significantly tightened and extended to a much larger number of companies.What previously mainly applied to operators of critical infrastructures (CRITIS) will in future affect thousands of organisations across many sectors.
Key Takeaways
Four-stage notification process: 24h initial notification, 72h detailed report, interim updates on request, final report after one month
Far more companies in scope: All organisations with 50+ employees and €10m+ annual turnover in relevant sectors will be required to notify
Act now: Review incident response processes and train teams – even though the text is still a government draft
NIS2 Notification – Legal Basis
What is the NIS2 Directive?
The NIS2 Directive (Network and Information Security Directive 2) is the revised EU directive on network and information security. It entered into force in January 2023, replacing the original NIS Directive (2016).Compared to NIS1, NIS2:
significantly broadens the scope of sectors
raises security requirements
and introduces stricter and more detailed reporting duties
Its goal is to establish a high common level of cybersecurity across the EU and to strengthen resilience against cyberattacks.
Who is affected by NIS2 notification obligations?
NIS2 distinguishes between two categories of entities:
Essential Entities Traditional critical infrastructures such as energy and water utilities, transport, banks, healthcare
Important Entities Newly added and strongly expanding the scope, including:
digital service providers and cloud operators
waste and wastewater management
postal and courier services
chemical industry
food production and distribution
In principle, companies with:
more than 50 employees, and
more than €10 million annual turnover,
operating in relevant sectors will fall under NIS2 – and thus under the new notification regime.
The Four NIS2 Notification Stages
NIS2 introduces a multi-step reporting process for significant security incidents.
1. Early Warning (24 Hours)
Deadline: without undue delay, at the latest 24 hours after becoming aware of the incident
Purpose: rapid alert and initial situational awareness
Content includes:
indication of unlawful or malicious actions
potential cross-border impact on other EU Member States
👉 Companies must be able to submit this initial notification even with incomplete information.
2. Detailed Report (72 Hours)
Deadline: at the latest 72 hours after becoming aware
Purpose: more detailed initial assessment
The 72-hour report should include:
confirmation or update of the initial notification
first assessment of severity and impact
known Indicators of Compromise (IoCs)
initial evaluation of affected systems and data
This enables authorities to coordinate response and warn other potentially affected entities.
3. Interim Updates (On Request)
Trigger: upon request from the Federal Office for Information Security (BSI)
Purpose: ongoing status updates for complex or long-running incidents
May include:
progress in incident handling
new findings regarding root cause or impact
updated risk assessments
4. Final Report (After 1 Month)
Deadline: at the latest one month after the 72-hour notification
It must contain a comprehensive documentation of the incident, including:a) Detailed description of the incident
full timeline
concrete business impact
affected systems, data and individuals
b) Threat type and root cause analysis
technical attack vector
exploited vulnerabilities
likely motivation/origin of the attacker
c) Remediation measures
immediate response actions
ongoing remediation activities
long-term improvements planned
d) Cross-border impact
confirmed or suspected impact in other Member States
coordination with foreign authorities
💡 If the incident is still ongoing after one month, an interim progress report is submitted first, with the final report following once remediation is complete.
Step by Step to a Certifiable ISMS
With the fuentis ISMS Tool, you can implement modern standards in an automated and efficient way. Ready-to-use modules, guided workflows and expert support make building an ISMS straightforward, whether you are:
starting from scratch, or
modernising existing structures.
Multi-Compliance ISMS
Complete solution guiding you to ISO 27001 certification
Supports BSI IT-Grundschutz, TISAX® and NIS2 in parallel
Automated processes
Workflows that guide you step by step through certification – even without prior experience
Review questionnaires
Simple, customisable questionnaires to assess protection needs quickly and clearly
Personal support
Direct access to experienced consultants – from initial analysis to audit support
Specifics for Critical Infrastructure Operators (CRITIS)
Additional Information Requirements
CRITIS operators must provide additional details whenever incidents impact (or could impact) critical infrastructures, such as:
Type of critical facility
Critical service affected
Scale and duration of impact (customers affected, regions, outage duration etc.)
Joint Reporting Point & Coordination
A joint reporting platform will be set up by BSI and BBK (Federal Office of Civil Protection and Disaster Assistance)
Companies submit reports once and the authorities coordinate internally
Benefits:
no need for parallel reporting to multiple bodies
automatic forwarding to relevant supervisory authorities
potential active support from BSI in handling incidents
Practical Implementation and Reporting Channel
Joint BSI/BBK Reporting Platform
The technical platform will be set up jointly
Reporting obligations only become enforceable once the platform is operational
The BSI will:
define detailed reporting procedures after consulting stakeholders
publish requirements and guidance on its website
Support from BSI
Reporting entities may receive:
technical support during incident handling
forensic assistance
coordinated communication with other authorities and experts
What Companies Should Do Now
Review and adapt incident response processes
Align with 24h / 72h / 1-month deadlines
Define escalation paths
Establish criteria for “significant” security incidents
Clarify responsibilities
Set up an incident response team
Ensure 24/7 availability
Define backup roles and decision-making authority
Prepare technical capabilities
Enhance logging and monitoring
Secure forensic capabilities (in-house or external)
Test backup and recovery processes
Define crisis communication channels
Create documentation & templates
Templates for each notification stage
Checklists for incident handling
Up-to-date contact lists (internal & external)
Run tests and training
Conduct IR exercises
Simulate reporting processes
Train staff to detect and escalate incidents
Raise awareness of NIS2 timelines and obligations
Outlook and Next Steps
The German government draft is currently in the parliamentary process; entry into force is expected around 2025.
Notification obligations will only apply once the joint reporting platform is technically available.
Further details will follow from BSI guidance and EU implementing acts.
Conclusion
The planned NIS2 notification obligations represent a fundamental tightening of cybersecurity requirements in Germany. The four-stage process – from 24-hour early warning to a one-month final report – will challenge many organisations that have never dealt with such strict deadlines before.
Important: This description is based on a government draft and may change during the legislative process. Final legal requirements may differ. Companies should closely monitor further developments and BSI publications.NIS2 Notification Obligations – What the Government Draft Means for Companies
Germany’s cybersecurity landscape is on the verge of a major shift. With the publication of the German government draft for implementing the NIS2 Directive, notification obligations will be significantly tightened and extended to a much larger number of companies.
What previously mainly applied to operators of critical infrastructures (CRITIS) will in future affect thousands of organisations across many sectors.
Key Takeaways
Four-stage notification process: 24h initial notification, 72h detailed report, interim updates on request, final report after one month
Far more companies in scope: All organisations with 50+ employees and €10m+ annual turnover in relevant sectors will be required to notify
Act now: Review incident response processes and train teams – even though the text is still a government draft
NIS2 Notification – Legal Basis
What is the NIS2 Directive?
The NIS2 Directive (Network and Information Security Directive 2) is the revised EU directive on network and information security. It entered into force in January 2023, replacing the original NIS Directive (2016).
Compared to NIS1, NIS2:
significantly broadens the scope of sectors
raises security requirements
and introduces stricter and more detailed reporting duties
Its goal is to establish a high common level of cybersecurity across the EU and to strengthen resilience against cyberattacks.
Who is affected by NIS2 notification obligations?
NIS2 distinguishes between two categories of entities:
Essential Entities Traditional critical infrastructures such as energy and water utilities, transport, banks, healthcare
Important Entities Newly added and strongly expanding the scope, including:
digital service providers and cloud operators
waste and wastewater management
postal and courier services
chemical industry
food production and distribution
In principle, companies with:
more than 50 employees, and
more than €10 million annual turnover,
operating in relevant sectors will fall under NIS2 – and thus under the new notification regime.
The Four NIS2 Notification Stages
NIS2 introduces a multi-step reporting process for significant security incidents.
1. Early Warning (24 Hours)
Deadline: without undue delay, at the latest 24 hours after becoming aware of the incident
Purpose: rapid alert and initial situational awareness
Content includes:
indication of unlawful or malicious actions
potential cross-border impact on other EU Member States
👉 Companies must be able to submit this initial notification even with incomplete information.
2. Detailed Report (72 Hours)
Deadline: at the latest 72 hours after becoming aware
Purpose: more detailed initial assessment
The 72-hour report should include:
confirmation or update of the initial notification
first assessment of severity and impact
known Indicators of Compromise (IoCs)
initial evaluation of affected systems and data
This enables authorities to coordinate response and warn other potentially affected entities.
3. Interim Updates (On Request)
Trigger: upon request from the Federal Office for Information Security (BSI)
Purpose: ongoing status updates for complex or long-running incidents
May include:
progress in incident handling
new findings regarding root cause or impact
updated risk assessments
4. Final Report (After 1 Month)
Deadline: at the latest one month after the 72-hour notification
It must contain a comprehensive documentation of the incident, including:
a) Detailed description of the incident
full timeline
concrete business impact
affected systems, data and individuals
b) Threat type and root cause analysis
technical attack vector
exploited vulnerabilities
likely motivation/origin of the attacker
c) Remediation measures
immediate response actions
ongoing remediation activities
long-term improvements planned
d) Cross-border impact
confirmed or suspected impact in other Member States
coordination with foreign authorities
💡 If the incident is still ongoing after one month, an interim progress report is submitted first, with the final report following once remediation is complete.
Step by Step to a Certifiable ISMS
With the fuentis ISMS Tool, you can implement modern standards in an automated and efficient way. Ready-to-use modules, guided workflows and expert support make building an ISMS straightforward, whether you are:
starting from scratch, or
modernising existing structures.
Multi-Compliance ISMS
Complete solution guiding you to ISO 27001 certification
Supports BSI IT-Grundschutz, TISAX® and NIS2 in parallel
Automated processes
Workflows that guide you step by step through certification – even without prior experience
Review questionnaires
Simple, customisable questionnaires to assess protection needs quickly and clearly
Personal support
Direct access to experienced consultants – from initial analysis to audit support
Specifics for Critical Infrastructure Operators (CRITIS)
Additional Information Requirements
CRITIS operators must provide additional details whenever incidents impact (or could impact) critical infrastructures, such as:
Type of critical facility
Critical service affected
Scale and duration of impact (customers affected, regions, outage duration etc.)
Joint Reporting Point & Coordination
A joint reporting platform will be set up by BSI and BBK (Federal Office of Civil Protection and Disaster Assistance)
Companies submit reports once and the authorities coordinate internally
Benefits:
no need for parallel reporting to multiple bodies
automatic forwarding to relevant supervisory authorities
potential active support from BSI in handling incidents
Practical Implementation and Reporting Channel
Joint BSI/BBK Reporting Platform
The technical platform will be set up jointly
Reporting obligations only become enforceable once the platform is operational
The BSI will:
define detailed reporting procedures after consulting stakeholders
publish requirements and guidance on its website
Support from BSI
Reporting entities may receive:
technical support during incident handling
forensic assistance
coordinated communication with other authorities and experts
What Companies Should Do Now
Review and adapt incident response processes
Align with 24h / 72h / 1-month deadlines
Define escalation paths
Establish criteria for “significant” security incidents
Clarify responsibilities
Set up an incident response team
Ensure 24/7 availability
Define backup roles and decision-making authority
Prepare technical capabilities
Enhance logging and monitoring
Secure forensic capabilities (in-house or external)
Test backup and recovery processes
Define crisis communication channels
Create documentation & templates
Templates for each notification stage
Checklists for incident handling
Up-to-date contact lists (internal & external)
Run tests and training
Conduct IR exercises
Simulate reporting processes
Train staff to detect and escalate incidents
Raise awareness of NIS2 timelines and obligations
Outlook and Next Steps
The German government draft is currently in the parliamentary process; entry into force is expected around 2025.
Notification obligations will only apply once the joint reporting platform is technically available.
Further details will follow from BSI guidance and EU implementing acts.
Conclusion
The planned NIS2 notification obligations represent a fundamental tightening of cybersecurity requirements in Germany. The four-stage process – from 24-hour early warning to a one-month final report – will challenge many organisations that have never dealt with such strict deadlines before.
Important: This description is based on a government draft and may change during the legislative process. Final legal requirements may differ. Companies should closely monitor further developments and BSI publications.
Despite this uncertainty, early preparation is strongly recommended:
build robust incident response processes,
train teams,
and clarify responsibilities now.
Organisations that start preparing today will be significantly better positioned once NIS2 notification obligations become binding.
Are you affected by NIS2?
Despite this uncertainty, early preparation is strongly recommended:
build robust incident response processes,
train teams,
and clarify responsibilities now.
Organisations that start preparing today will be significantly better positioned once NIS2 notification obligations become binding.
Are you affected by NIS2?

Srdan Manasijevic
CEO
Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI and advanced risk methodologies.


