- Which companies are affected by NIS2?
- Companies from 18 sectors (Annex I and II BSIG) with at least 50 employees or more than €10M annual turnover. In Germany, that is roughly 29,000 companies. KRITIS operators and certain special cases (e.g. DNS providers, TLD registries, qualified trust service providers) fall under NIS2 regardless of size.
- What is the difference between essential and important entities?
- The substantive obligations are identical. Essential entities (Annex I sectors from 250 employees or €50M turnover, plus KRITIS operators) are subject to proactive BSI supervision and fines up to €10M or 2% of annual turnover. Important entities are audited reactively, with fines up to €7M or 1.4%.
- Is this result legally binding?
- No. The check provides initial orientation based on sector, size class and KRITIS status. It does not replace legal advice and simplifies detailed criteria such as the balance-sheet total. The official BSI affectedness check is authoritative.
- Is my input stored?
- No. The check runs entirely in your browser; no inputs are transmitted to a server and no identifying data is requested.
- What do I have to do if my company is in scope?
- Four sets of obligations: registration with the BSI (§33 BSIG — the deadline has passed, register without delay), implementation of the 10 minimum risk-management measures (§30 BSIG), three-stage reporting of significant incidents (§32 BSIG), and management approval, oversight and training duties (§38 BSIG).
- My company is too small — am I done?
- Not necessarily. In-scope companies must address supply-chain security (§30(2) no. 4 BSIG) and pass requirements to service providers and suppliers via contracts. If you work for NIS2-regulated customers, expect security questionnaires and contract clauses.