The EU's NIS-2 Directive is intended to strengthen cyber resilience across the Union and ensure a high common level of cybersecurity in the Member States. The second EU Directive on Network and Information Security, known as NIS-2, focuses in particular on protecting critical infrastructure. NIS-2 entered into force at the end of 2022 and was to be transposed into national law by the fourth quarter of 2024. The following sections provide an overview of the development and current status of NIS-2. They also explain the main differences between the first NIS Directive and NIS-2, which companies, entities and sectors are affected, and which requirements must be met.
Information for our customers in the context of NIS-2: affected companies can use the LamaPoll survey tool as a NIS-2-compliant supplier and service provider for surveys and questionnaires. More detailed information: using LamaPoll in compliance with NIS-2.
Table of Contents
- NIS-1, NIS-2 and KRITIS: overview and current status
- History of critical infrastructure in the EU, with a focus on IT
- Brief overview: IT Security Act, NIS-1, IT Security Act 2.0 and NIS-2
- The key differences between NIS-1 and NIS-2
- Scope of NIS-2: who is affected?
- Are SMEs also affected by NIS-2?
- LamaPoll as a NIS-2-compliant part of the supply chain
- NIS-2: the key minimum risk-management requirements
NIS-1, NIS-2 and KRITIS: overview and current status
NIS-2 is an EU directive ((EU) 2022/2555) aimed at strengthening and harmonising cybersecurity across the EU. It replaces the previous NIS-1 Directive, extends it in almost every respect and also goes beyond the German KRITIS regulations.
The Directive was published on 27 December 2022 and entered into force 20 days later. EU Member States were required to transpose it into national law by 17 October 2024. Germany completed national implementation with the entry into force of the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) on 6 December 2025.
Current status of NIS-2: The Act implementing the NIS-2 Directive was adopted by the German Bundestag on 13 November 2025 (draft legislation dated 12 November 2025 - 21/2782). After the Federal Ministry of the Interior (BMI) presented a fourth ministerial draft at the end of June 2024, the Federal Cabinet agreed on an official draft bill in July 2024. With its adoption, the "NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG)" successfully completed the legislative process.
Until 2024, corresponding regulations in Germany applied almost exclusively to critical infrastructure. NIS-2 addresses and imposes obligations on a much broader group. The Directive directly affects both a large number of companies, through specific requirements for risk management, reporting obligations and management-body liability, and the Member States, through requirements such as central points of contact, cross-border cooperation, expanded national powers and rules on fines. To strengthen cooperation at EU level in particular, standards and common requirements are defined.
What does NIS mean? NIS stands for "Network and Information Security". The NIS directives define measures to achieve a high common level of security for network and information systems across the European Union.
What are critical infrastructures, essential services and important services and entities?
In the context of NIS, NIS-2, KRITIS and the German IT Security Act, terms such as "critical infrastructure", "essential services/entities" and "important services/entities" are used repeatedly. What do they mean, and why are they regulated at EU level?
a) Situation in Germany: KRITIS up to 2024
"Critical infrastructures (KRITIS) are organisations or facilities of major importance to the functioning of society, whose failure or impairment would result in sustained supply shortages, serious disruption to public safety or other severe consequences."
(Definition used by the German federal ministries)
The German Federal Office for Information Security (BSI) provides a more detailed definition. Under the BSI Act (BSIG), critical infrastructures are facilities, installations or parts thereof that belong to the following sectors:
- energy,
- information technology and telecommunications,
- transport and traffic,
- health,
- water,
- food,
- finance and insurance, and
- municipal waste disposal (since the IT Security Act 2.0 adopted in May 2021 and the associated amendments to the BSI Act).
They must also be of major importance to the functioning of society because their failure or impairment would cause significant supply shortages or risks to public safety.
In addition, the Federal Office of Civil Protection and Disaster Assistance (BBK) also considers the two sectors government/public administration and media/culture to be critical infrastructure.
Operators of critical infrastructure (§ 1 no. 2 BSI-KritisV) are required under the BSI Act (BSIG) and the BSI Critical Infrastructure Ordinance to:
- designate a contact point for the critical infrastructure they operate,
- report IT disruptions or significant impairments,
- implement IT security in line with the "state of the art", and
- provide evidence of this to the BSI every two years.
b) EU-level rules: essential and important entities under NIS-2
The NIS-2 Directive goes beyond KRITIS and extends the sectors concerned to include public administration (central and regional government), ICT service management (B2B), including managed service providers and managed security service providers, and research institutions. The remaining sectors are partly covered by KRITIS and partly by other German legislation such as the Digital Services Act (formerly the Telemedia Act). Companies are also classified as essential or important entities depending on their size and sector.
Important: NIS-2 has a much broader scope than KRITIS:
- particularly important ("essential") entities
- important entities
- operators of critical installations (KRITIS)
This is subject, of course, to special cases and exceptions.
NIS-1 distinguished between operators of essential services and digital service providers. This distinction no longer applies. Under NIS-2, the new classification distinguishes between particularly important sectors (sectors of high criticality) and important sectors.
History of critical infrastructure in the EU, with a focus on IT
The US established the President's Commission on Critical Infrastructure Protection (PCCIP) as early as 1996. It progressively laid the foundations and definitions for critical infrastructure and soon placed a strong focus on IT.
- 2008: Critical infrastructure is defined at European level in Directive 2008/114/EC; Germany defines it in its Spatial Planning Act.
- 2010: the first Digital Agenda for Europe 2010-2020.
- 2015: The UN resolution "Transforming our world: the 2030 Agenda for Sustainable Development" agrees, among other things, Sustainable Development Goal 9, which calls for resilient and reliable infrastructure.
- 2015: Germany's IT Security Act takes effect.
- 2016: EU Directive on security of network and information systems (NIS). Among other things, the NIS Directive requires Member States to develop national cybersecurity strategies and introduce security measures for operators of critical digital services.
- 2018: Germany transposes the NIS Directive into national law.
- 2019: The BSI publishes a draft of the IT Security Act 2.0.
- 2020: First evaluation of the NIS Directive in Germany and identification of areas for improvement.
- 2022: Proposal to revise the NIS Directive and introduce NIS-2 at EU level.
- 2024: October 2024: NIS is repealed and NIS-2 must be transposed into national law.
- 2024: Germany: draft Act implementing the NIS-2 Directive and regulating key aspects of information security management in the federal administration (NIS-2 Implementation and Cybersecurity Strengthening Act).
- 2025: Germany: on 13 November, the Bundestag adopts the draft Act "implementing the NIS-2 Directive and regulating key aspects of information security management in the federal administration" in the version amended by the Committee on Internal Affairs (21/2782).
A cybersecurity fact: the beginning of the internet is commonly associated with 29 October 1969 and the launch of ARPANET. Only two years later, "Creeper", the first computer worm, was discovered. It was followed in 1972 by "Reaper", effectively the first antivirus program.
Brief overview: IT Security Act, NIS-1, IT Security Act 2.0 and NIS-2
NIS Directive 2016
Across Europe, the long-awaited EU Directive on security of network and information systems (NIS) established the basis for national legislation concerning operators of critical infrastructure. It defined the scope, including operators of essential services (OESs), and extended it to digital service providers (DSPs). The NIS Directive also set out both obligations for OESs and DSPs, such as taking appropriate security measures and considering potential risks, and the consequences of non-compliance.
IT Security Act 2015
Germany was, for once, well prepared. The IT Security Act, which had already been in force since 2015, assigned the Federal Office for Information Security (BSI) a central role in protecting critical infrastructure. Security requirements were added to the BSI Act, while the associated Critical Infrastructure Ordinance (BSI-KritisV) defined the relevant sectors. Apart from the terminology, with the NIS Directive referring to "essential services" and the IT Security Act to "critical infrastructure", the two sets of rules are broadly similar.
Act implementing the NIS Directive 2018
The Act implementing the NIS Directive was promulgated in 2017 and implemented in 2018. It transposed the NIS Directive into German law and expanded the existing rules with new requirements, particularly regarding closer cooperation between EU Member States and reporting obligations for KRITIS operators and digital service providers. The BSI's tasks and powers were expanded.
IT Security Act 2.0, 2019
In 2019, the BSI published the draft IT Security Act 2.0, which strengthened the BSI's powers, expanded investigative activities and placed greater emphasis on consumer protection. Despite criticism, including concerns about extending the BSI's powers without prior involvement of associations and other stakeholders, the Act entered into force at the end of May 2021.
NIS-2 Directive 2023
The evaluation of the NIS Directive identified two major problems, particularly in light of growing dependencies and the spread of digital technologies: cyber resilience was too low and inconsistent across EU countries, and there was a lack of both common understanding and cooperative cross-border collaboration. This led to the adoption of the new NIS-2 Directive in 2022. It imposes stricter requirements, harmonises sanctions and broadens the scope.
The key differences between NIS-1 and NIS-2
NIS-1, or the NIS Directive, was the first European cybersecurity directive. The need for NIS (Network and Information Security) arose from increasing dependence on digital networks and systems combined with a growing threat landscape. These factors also explain the continuing revision and improvement of the rules, which led to NIS-2 in 2022.
a) NIS-1 vs NIS-2: the affected and newly covered sectors
NIS-1 applies to "essential services", meaning specific sectors referred to in Germany as KRITIS (critical infrastructure). In Germany, NIS-1 covers around 2,000 companies. NIS-2, by contrast, defines eleven "essential" and seven "important" sectors.
The difference between NIS and NIS-2 in detail:
The NIS Directive (EU) 2016/1148 identifies seven critical sectors:
- energy (electricity, oil and gas),
- transport (air, rail, shipping and road transport),
- banking and, separately,
- financial market infrastructure,
- healthcare,
- drinking water (supply and distribution), and
- digital infrastructure, specifically IXPs, DNS providers and TLD registries.
The NIS-2 Directive (EU) 2022/2555 provides more detail and additionally divides sectors into sectors of high criticality and "other critical sectors".
Sectors of high criticality under NIS-2
- Energy: as under NIS-1, but additionally district heating and cooling and hydrogen
- Transport
- Banking
- Financial market infrastructures
- Healthcare
The former NIS-1 category "drinking water supply and distribution" is split under NIS-2 into: - Drinking water
- NEW under NIS-2: wastewater
- Digital infrastructure: as under NIS-1, but extended to include cloud computing service providers, data centre service providers, content delivery network providers, trust service providers, providers of public electronic communications networks and providers of publicly available electronic communications services
- NEW under NIS-2: ICT service management (business-to-business)
- NEW under NIS-2: public administration
- NEW under NIS-2: space
Banks, insurers and other financial entities are also subject to the EU regulation DORA, which takes precedence over NIS-2 as the more specific law: DORA: meaning, requirements and differences from NIS-2
Also new under NIS-2: other critical sectors
- postal and courier services
- waste management
- manufacture, production and distribution of chemicals
- production, processing and distribution of food
- manufacturing, including medical devices, computer and electronic products, electrical equipment, machinery, motor vehicles and other transport equipment
- digital service providers, including online marketplaces, search engines and social networks
- research organisations

Figure: differences between NIS and NIS-2 with regard to covered sectors.
The 18 sectors are similar to those covered by the German KRITIS classification or by the German Digital Services Act, formerly the Telemedia Act. The main exceptions are public administration, research and ICT service management. These are covered by the new German Act implementing EU NIS-2 and strengthening cybersecurity, the NIS2UmsuCG.
b) NIS-1 vs NIS-2: classification into "particularly critical" and "other critical" sectors
NIS-2 no longer distinguishes between operators of essential services and digital service providers. The new classification distinguishes between particularly important sectors (sectors of high criticality) and important sectors (other critical sectors):

Figure: new under NIS-2 - classification into critical and particularly critical sectors.
c) NIS-1 vs NIS-2: scope
NIS-1 distinguishes between "operators of essential services", broadly corresponding to KRITIS, and "digital service providers". NIS-2 redefines the affected groups and distinguishes between "essential entities" and "important entities", with operators of critical infrastructure forming part of the essential entities.
d) NIS-1 vs NIS-2: cooperation at EU level
NIS-2 calls for greater consistency across the EU and, above all, stronger information exchange and cooperation. Member States' cybersecurity authorities are expected to work closely together, while the role of the European Union Agency for Cybersecurity (ENISA) is strengthened.
Each country must designate points of contact, such as a Computer Security Incident Response Team (CSIRT) and a competent national network and information systems authority.
e) NIS-1 vs NIS-2: common standards and requirements
To achieve its wider objectives, particularly cooperation, the new NIS Directive calls for EU-wide standards and common requirements. Before NIS-2, national implementation differed between countries. For example:
- Germany has KRITIS regulations.
- Austria has no single specific law explicitly dedicated to protecting critical infrastructure. Instead, several laws, such as the Security Police Act and the Criminal Code, define aspects of critical infrastructure protection. The responsible authorities are supported in implementation by the Austrian Programme for Critical Infrastructure Protection (APCIP). Austria also has bilateral agreements with Slovakia and the Czech Republic.
- Switzerland defines nine critical sectors covering 27 industries.
- Monaco has no definition of critical sectors, as is also the case in 93 other countries worldwide.
A common definition at EU level would represent a major step forward under NIS-2 because the issue has political implications. One central issue is that, under international agreements, attacks on critical infrastructure are prohibited under international law. A voluntary additional principle is that malicious cyber activities against critical infrastructure should also be avoided in peacetime. National priorities also differ. For example, maritime communications, including submarine cables, are particularly relevant in France but less so in Germany.
f) NIS-1 vs NIS-2: reporting obligations
Reporting obligations for companies are expanded, and information about incidents is intended to be shared across the EU.
g) NIS-1 vs NIS-2: fines and sanctions
Unlike the first NIS Directive, NIS-2 requires Member States to provide for fines at national level. This also affects Germany, where existing KRITIS fines are in some cases increased substantially and the range of offences is expanded.
Scope of NIS-2: who is affected?
According to the German Federal Ministry of the Interior's draft NIS-2 Implementation and Cybersecurity Strengthening Act, the following companies are affected as "particularly important" or "important" entities:
a) A company is considered a "particularly important" or "essential" entity if it meets one of the following conditions:
- it provides goods or services to an entity in one of the sectors of high criticality AND
- employs at least 250 people OR has annual turnover of more than EUR 50 million and an annual balance-sheet total of more than EUR 43 million.
Or:
- it operates critical installations.
Or:
- it provides telecommunications services or publicly available telecommunications networks AND
- employs at least 50 people OR has annual turnover and an annual balance-sheet total of more than EUR 10 million each.
Or:
- it is a trust service provider, top-level domain registry operator or DNS service provider for entities in one of the sectors of high criticality.
b) A company is considered an important entity if it meets the following conditions:
- it provides goods or services to an entity in one of the sectors of high criticality OR in another critical sector AND
- employs at least 50 people OR has annual turnover of more than EUR 10 million.
Or:
- it is a trust service provider.
c) Scope of NIS-2 - graphical overview:

Table: graphic based on the draft by the German Federal Ministry of the Interior: Draft Act implementing the NIS-2 Directive and regulating key aspects of information security management in the federal administration (NIS-2 Implementation and Cybersecurity Strengthening Act), version dated 7 May 2024.
The German Federal Office for Information Security (BSI) provides a questionnaire to help companies assess whether they fall within the scope of NIS-2. After answering the questions, users receive an automated initial assessment. The BSI questionnaire is available here: NIS-2 scope assessment.
Are SMEs also affected by NIS-2?
Small and medium-sized enterprises are generally not directly subject to NIS-2, but they may still be affected indirectly. This is particularly relevant if they act as suppliers or service providers to companies that are directly in scope. SMEs in this position may therefore also face cybersecurity-related requirements.
Because directly affected companies must consider their entire supply chain as part of NIS-2 risk management, cyber-resilience requirements can influence how suppliers are selected and assessed. As a result, supplying and service-providing SMEs may also encounter requirements stemming from the EU Directive and the national rules based on it.
As with the German Supply Chain Due Diligence Act (LkSG), SMEs should expect companies subject to the legislation to request their cooperation and involvement. For smaller and medium-sized businesses, this can include implementing cybersecurity measures or introducing an ISMS.
Apart from certain trust service providers, SMEs are generally not directly subject to NIS-2. However, as partners or suppliers of affected companies, they may fall within the Directive's requirements indirectly as part of the supply chain.
LamaPoll as a NIS-2-compliant part of the supply chain
LamaPoll, or more precisely the company behind the survey tool, Lamano GmbH & Co. KG, provides services to entities in sectors of high criticality and also serves KRITIS operators. However, the second condition, the minimum company size, is not currently met. LamaPoll itself is therefore not an entity within the meaning of NIS-2.
Nevertheless, LamaPoll is well positioned thanks to recognised certifications such as TISAX and ISO 27001, as well as an implemented and externally audited ISMS (information security management system). This enables affected companies to use the LamaPoll survey tool internally in a NIS-2-compliant manner and to use LamaPoll as a NIS-2-compliant service provider. The supply chain remains protected:
- ISMS established and externally audited
- information security risk management covering identification, assessment and treatment
- security incidents clearly defined, including responsibilities, escalation levels and processes
- emergency concept and manual in place, including business continuity management and regularly conducted emergency tests
- cryptography concept subject to regular review and external audit
- training and professional development established as an ongoing process
- reporting procedures established and regularly tested
NIS-2: the key minimum risk-management requirements
If your organisation already falls under KRITIS or holds recognised certifications, particularly ISO 27001, you are already well positioned. The requirements of the NIS-2 Directive are extensive and far-reaching, but they are also closely aligned with standards such as ISO 27001:
- policies for risk analysis and information-system security, as well as incident handling
- BCM: business continuity management, including maintaining operations, emergency management and crisis management
- risk management covering the entire supply chain
- risk-treatment measures, including a framework for assessing their effectiveness
- supply-chain security, including security-related aspects of relationships between entities and their direct suppliers or service providers
- cryptography: policies and procedures governing its use
- personnel: training, access-control arrangements and personnel security
NIS-2 also introduces terms such as "cyber hygiene". According to the Directive, this includes, for example, zero-trust principles, software updates, device configuration, network segmentation, identity and access management, user awareness, employee training, and raising awareness of cyber threats, phishing and social-engineering techniques. (Source: Directive (EU) 2022/2555)
Another specific feature of NIS-2, particularly compared with standards such as ISO 27001, is that it contains concrete requirements such as:
- the use of multi-factor authentication
- security measures for the acquisition, development and maintenance of network and information systems
- secured voice, video and text communications
LamaPoll is one of the few survey tools with recognised ISO 27001 certification and covers the risk-management requirements listed above. Companies subject to NIS-2 or KRITIS can use LamaPoll as a NIS-2-compliant supplier or service provider for surveys and questionnaires.
Together with the Federal Office for Information Security (BSI), we conducted a security survey for the first time. The participating companies had high requirements for data protection, cybersecurity and anonymity. LamaPoll met them very well, both technically and organisationally. A contact person was also available whenever needed. We are extremely satisfied with the cooperation.
Do you have questions for our team?
We will be happy to answer any questions you may have about security at LamaPoll.
Please feel free to contact us.


