Bundestag decides on NIS2 – what companies have to do now

Tamara Heene
Tamara Heene
4 min read
Bundestag decides on NIS2 – what companies have to do now

The Bundestag has thatNIS2 Implementation Actfinally decided on November 13, 2025. After more than a year of delay, the German implementation of the EU Cyber Directive is now legally binding. For tens of thousands of companies – especially SMEs – this is a turning point. The reach of regulation is increasing sharply,and significantly more companies are now considered “important” or “particularly important” institutions.

Your immediate priorities

  • Obligation to test:Every companyhave to check now, whether it falls under the new NIS2 rules. The responsibility lies solely with you.
  • Extended scope of application:Tens of thousands of companies that previously had no contact with safety regulation are now affected.
  • Strict requirements:Affected entities are now subject to stricter obligations regarding cyber governance, risk management, documentation and reporting channels.
  • Risk of delay:Inaction leads to regulatory risks and can result in fines.

The crucial next step: clarify your concerns

The central and inevitable step is clear: the formal classification of your company. Without this check, it is not possible to determine whether and which of the new, strict obligations you have to fulfill.

Companies covered by NIS2 must act promptly:

These measures are not a recommendation, but alegal requirement.

Conclusion for decision-makers: From knowledge to action

NIS2 is now law. Waiting is no longer an option. Now only one thing counts:

  1. Carry out mandatory inspection.
  2. Identify gaps.
  3. Prioritize measures.

The first step is the most important foundation for your compliance and cyber resilience.

How ADVISORI supports you

We will help you answer the crucial question quickly and confidently: “Are we covered by NIS2?”ADVISORI offers a structured NIS2 quick check, clear roadmaps for implementation and C-level workshopsto enable managers to act immediately. We accompany you efficiently and practically. Talk to us! Further information:NIS Consulting: Your compass for cybersecurity according to NIS and NIS2

📖 Also read:NIS2 for suppliers: How you can turn the NIS2 requirement into an unfair competitive advantage

📖 Also read:NIS2 for suppliers: How you can turn the NIS2 requirement into an unfair competitive advantage

Hat ihnen der Beitrag gefallen? Teilen Sie es mit:

NIS2 affects 29,000 German organisations. Are you one of them?

We clarify scope, registration duties and the security-measure plan under the German NIS2 transposition act in a 30-minute session.

30 Minuten • Unverbindlich • Sofort verfügbar

Further reading

Continue exploring with related insights from our experts.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance