The 10 NIS2 Cybersecurity Risk-Management Measures in Germany (Article 21)

Published: · AIPOS OÜ · nis2europe.eu

Why the risk-management measures matter

If your company falls under NIS2 in Germany, the heart of your compliance obligation is one requirement: implement appropriate cybersecurity risk-management measures. In the German transposition, the BSI Act (BSIG) codifies these obligations in § 30 for essential entities (besonders wichtige Einrichtung) and important entities (wichtige Einrichtung).

The underlying European rule is directive (EU) 2022/2555, art 21(1), which requires essential and important entities to take *appropriate and proportionate technical, operational and organisational measures* to manage the risks to the network and information systems they use. The same principle appears in § 30 Abs. 1 BSIG: measures must be *geeignet, verhältnismäßig und wirksam* (suitable, proportionate and effective).

Proportionality is not a loophole - it is a structured test. Under art 21(1) and § 30 Abs. 1 Satz 2 BSIG, you must weigh:

Crucially, § 30 Abs. 1 Satz 3 BSIG requires you to document compliance. In other words, doing the work is not enough - you must be able to prove it.

The 10 measures: your practical checklist

Both art 21(2) points (a)-(j) and § 30 Abs. 2 BSIG set out the minimum measures. They must be based on an all-hazards approach and reflect the state of the art and relevant European and international standards. Here is the checklist, mapped one-to-one:

#Measure (Article 21(2) / § 30 Abs. 2 BSIG)What it means in practice
1(a) Policies on risk analysis and information system securityA documented risk-analysis and information-security policy framework.
2(b) Incident handlingProcesses to detect, respond to and manage security incidents.
3(c) Business continuityBackup management, disaster recovery and crisis management.
4(d) Supply chain securitySecurity in relationships with your direct suppliers and service providers.
5(e) Security in acquisition, development and maintenanceSecure procurement and development, including vulnerability handling and disclosure.
6(f) Effectiveness assessmentPolicies and procedures to assess how well your risk-management measures actually work.
7(g) Cyber hygiene and trainingBasic cyber-hygiene practices and cybersecurity training.
8(h) CryptographyPolicies and procedures on the use of cryptography and, where appropriate, encryption.
9(i) HR security, access control, asset managementPersonnel security, access-control policies and management of ICT systems, products and processes.
10(j) Multi-factor authentication and secure communicationsMFA or continuous authentication, secured voice/video/text and, where appropriate, secured emergency communications within the entity.

The wording in § 30 Abs. 2 BSIG closely tracks the directive text, so a control set built around these ten points serves both the German law and the EU baseline.

How Germany transposes Article 21 into § 30 BSIG

The German transposition follows the directive structure closely, but adds national detail worth noting:

If you discover a gap, act quickly: art 21(4) requires an entity that finds it does not comply to take all necessary, appropriate and proportionate corrective measures without undue delay.

Management responsibility, oversight and enforcement

The ten measures are a board-level matter, not just an IT task.

Given these stakes, mapping your controls against the ten measures - and documenting them per § 30 Abs. 1 Satz 3 BSIG - is the essential first step. Use our free scoping and gap tool to check your status against § 30 BSIG and Article 21.

Frequently asked questions

How many NIS2 risk-management measures are there?

There are ten minimum measures, listed in directive (EU) 2022/2555, art 21(2) points (a)-(j) and transposed in § 30 Abs. 2 BSIG. They range from risk-analysis policies and incident handling to supply-chain security, cryptography and multi-factor authentication.

Do the same measures apply to essential and important entities in Germany?

Yes. § 30 BSIG applies the same risk-management measures to both essential entities (besonders wichtige Einrichtung) and important entities (wichtige Einrichtung). Under § 30 Abs. 1 BSIG, the measures must be suitable, proportionate and effective, with proportionality assessed against risk exposure, entity size, implementation cost, and the likelihood and severity of incidents.

Who is responsible for implementing the measures - IT or management?

Management. Under art 20(1) and § 38 Abs. 1 BSIG, the management body must implement the § 30 measures and oversee their implementation, and under § 38 Abs. 3 BSIG must attend regular training. Management can be held liable under § 38 Abs. 2 BSIG.

What happens if we do not implement the measures?

Failure to implement a § 30 measure is an administrative offence under § 65 BSIG, with fines up to ten million euros for essential entities and seven million euros for important entities; turnover-based caps of 2 % or 1,4 % apply above 500 million euros in total turnover. The BSI supervises and enforces compliance under §§ 61-62 BSIG. If you find a gap, art 21(4) requires prompt corrective measures.

Check your NIS2 compliance

Run the free gap analysis

Start the free scoping test Run the free surface scan

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home