NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Weiterführende Seiten

  • Blog
  • FAQ
  • Glossar
  • Use Cases
  • Branchen
  • Preisgestaltung

Offizielle Quellen

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Ihr Navigator durch die NIS2-Compliance

Rechtliches

  • Datenschutzerklärung
  • Allgemeine Geschäftsbedingungen
  • Cookie-Richtlinie
  • Impressum

Ressourcen

  • Blog
  • Use Cases
  • Branchen
  • Preise
  • FAQ
  • Glossar

Kontakt

Kontakt

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. Alle Rechte vorbehalten.

Entwickelt in DeutschlandAllianz für Cyber-Sicherheit — Teilnehmer

NIS2 Affectedness Check

Check in under a minute whether your company falls under NIS2 — free, anonymous, no registration.

Your details

Three inputs are enough. Fully anonymous, no registration.

Initial assessment

Select all three inputs — the result appears instantly.

Frequently asked questions on NIS2 scope

Which companies are affected by NIS2?
Companies from 18 sectors (Annex I and II BSIG) with at least 50 employees or more than €10M annual turnover. In Germany, that is roughly 29,000 companies. KRITIS operators and certain special cases (e.g. DNS providers, TLD registries, qualified trust service providers) fall under NIS2 regardless of size.
What is the difference between essential and important entities?
The substantive obligations are identical. Essential entities (Annex I sectors from 250 employees or €50M turnover, plus KRITIS operators) are subject to proactive BSI supervision and fines up to €10M or 2% of annual turnover. Important entities are audited reactively, with fines up to €7M or 1.4%.
Is this result legally binding?
No. The check provides initial orientation based on sector, size class and KRITIS status. It does not replace legal advice and simplifies detailed criteria such as the balance-sheet total. The official BSI affectedness check is authoritative.
Is my input stored?
No. The check runs entirely in your browser; no inputs are transmitted to a server and no identifying data is requested.
What do I have to do if my company is in scope?
Four sets of obligations: registration with the BSI (§33 BSIG — the deadline has passed, register without delay), implementation of the 10 minimum risk-management measures (§30 BSIG), three-stage reporting of significant incidents (§32 BSIG), and management approval, oversight and training duties (§38 BSIG).
My company is too small — am I done?
Not necessarily. In-scope companies must address supply-chain security (§30(2) no. 4 BSIG) and pass requirements to service providers and suppliers via contracts. If you work for NIS2-regulated customers, expect security questionnaires and contract clauses.

Deep dive: scope in detail

Thresholds, all 18 sectors, special cases and the difference between the entity categories — with a downloadable decision tree.

Read the article "Am I affected by NIS2?"→

This affectedness check provides initial orientation and does not constitute legal advice. The classification simplifies individual §28 BSIG criteria (incl. balance-sheet total and size-independent special cases). The official BSI affectedness check (betroffenheitspruefung-nis-2.bsi.de) or a case-by-case legal assessment is authoritative.