The 10 NIS2 Cybersecurity Risk-Management Measures in Germany (Article 21)
Why the risk-management measures matter
If your company falls under NIS2 in Germany, the heart of your compliance obligation is one requirement: implement appropriate cybersecurity risk-management measures. In the German transposition, the BSI Act (BSIG) codifies these obligations in § 30 for essential entities (besonders wichtige Einrichtung) and important entities (wichtige Einrichtung).
The underlying European rule is directive (EU) 2022/2555, art 21(1), which requires essential and important entities to take *appropriate and proportionate technical, operational and organisational measures* to manage the risks to the network and information systems they use. The same principle appears in § 30 Abs. 1 BSIG: measures must be *geeignet, verhältnismäßig und wirksam* (suitable, proportionate and effective).
Proportionality is not a loophole - it is a structured test. Under art 21(1) and § 30 Abs. 1 Satz 2 BSIG, you must weigh:
- the degree of your exposure to risk,
- the size of your entity,
- the cost of implementation, and
- the likelihood and severity of incidents, including their societal and economic impact.
Crucially, § 30 Abs. 1 Satz 3 BSIG requires you to document compliance. In other words, doing the work is not enough - you must be able to prove it.
The 10 measures: your practical checklist
Both art 21(2) points (a)-(j) and § 30 Abs. 2 BSIG set out the minimum measures. They must be based on an all-hazards approach and reflect the state of the art and relevant European and international standards. Here is the checklist, mapped one-to-one:
| # | Measure (Article 21(2) / § 30 Abs. 2 BSIG) | What it means in practice |
|---|---|---|
| 1 | (a) Policies on risk analysis and information system security | A documented risk-analysis and information-security policy framework. |
| 2 | (b) Incident handling | Processes to detect, respond to and manage security incidents. |
| 3 | (c) Business continuity | Backup management, disaster recovery and crisis management. |
| 4 | (d) Supply chain security | Security in relationships with your direct suppliers and service providers. |
| 5 | (e) Security in acquisition, development and maintenance | Secure procurement and development, including vulnerability handling and disclosure. |
| 6 | (f) Effectiveness assessment | Policies and procedures to assess how well your risk-management measures actually work. |
| 7 | (g) Cyber hygiene and training | Basic cyber-hygiene practices and cybersecurity training. |
| 8 | (h) Cryptography | Policies and procedures on the use of cryptography and, where appropriate, encryption. |
| 9 | (i) HR security, access control, asset management | Personnel security, access-control policies and management of ICT systems, products and processes. |
| 10 | (j) Multi-factor authentication and secure communications | MFA or continuous authentication, secured voice/video/text and, where appropriate, secured emergency communications within the entity. |
The wording in § 30 Abs. 2 BSIG closely tracks the directive text, so a control set built around these ten points serves both the German law and the EU baseline.
How Germany transposes Article 21 into § 30 BSIG
The German transposition follows the directive structure closely, but adds national detail worth noting:
- State of the art and standards. Under § 30 Abs. 2 BSIG, measures *should* meet the state of the art, take relevant European and international standards into account, and rest on an all-hazards approach - mirroring art 21(1).
- Implementing acts take priority. Where the European Commission adopts an implementing act under Artikel 21 Absatz 5 der NIS-2-Richtlinie, those technical and methodological requirements prevail. § 30 Abs. 3 BSIG gives such acts priority for specific entity types (for example DNS service providers, cloud-computing providers, managed service providers and trust service providers), and § 30 Abs. 4 BSIG confirms priority more broadly where the requirements conflict with Abs. 2.
- National refinement by regulation. Where those implementing acts are not exhaustive, § 30 Abs. 5 BSIG allows the Federal Ministry of the Interior to refine and expand the requirements by regulation.
- Certified ICT products. § 30 Abs. 6 BSIG allows certain ICT products, services and processes to be required to hold a European cybersecurity certification (Artikel 49 der Verordnung (EU) 2019/881).
- Sector-specific standards. Under § 30 Abs. 8 BSIG, essential entities and their industry associations may propose sector-specific security standards, which the Federal Office for Information Security (BSI) can confirm as suitable.
If you discover a gap, act quickly: art 21(4) requires an entity that finds it does not comply to take all necessary, appropriate and proportionate corrective measures without undue delay.
Management responsibility, oversight and enforcement
The ten measures are a board-level matter, not just an IT task.
- Approval and oversight. Under art 20(1), management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements. Germany transposes this in § 38 BSIG: management (*Geschäftsleitung*) of essential and important entities must implement the § 30 measures and monitor their implementation (§ 38 Abs. 1), and must attend regular training on risk recognition and risk-management practices (§ 38 Abs. 3).
- Liability. Under § 38 Abs. 2 BSIG, management that breaches these duties is liable to the entity for culpably caused damage under the applicable company-law rules.
- Supervision. The BSI is the competent supervisory authority (§ 59) and the national contact and reporting point (§ 40 Abs. 1 BSIG). It has audit and enforcement powers over essential entities (§ 61 BSIG) and important entities (§ 62 BSIG), including ordering audits, requiring evidence of compliance, and ordering corrective measures.
- Fines. Failure to implement a § 30 measure is an administrative offence under § 65 BSIG. Fines can reach up to ten million euros for essential entities (besonders wichtige Einrichtung) and up to seven million euros for important entities (wichtige Einrichtung) (§ 65 Abs. 5). For entities with total turnover above 500 million euros, turnover-based maximums apply: up to 2 % of worldwide total turnover for essential entities (§ 65 Abs. 6) and up to 1,4 % for important entities (§ 65 Abs. 7).
Given these stakes, mapping your controls against the ten measures - and documenting them per § 30 Abs. 1 Satz 3 BSIG - is the essential first step. Use our free scoping and gap tool to check your status against § 30 BSIG and Article 21.
Frequently asked questions
How many NIS2 risk-management measures are there?
There are ten minimum measures, listed in directive (EU) 2022/2555, art 21(2) points (a)-(j) and transposed in § 30 Abs. 2 BSIG. They range from risk-analysis policies and incident handling to supply-chain security, cryptography and multi-factor authentication.
Do the same measures apply to essential and important entities in Germany?
Yes. § 30 BSIG applies the same risk-management measures to both essential entities (besonders wichtige Einrichtung) and important entities (wichtige Einrichtung). Under § 30 Abs. 1 BSIG, the measures must be suitable, proportionate and effective, with proportionality assessed against risk exposure, entity size, implementation cost, and the likelihood and severity of incidents.
Who is responsible for implementing the measures - IT or management?
Management. Under art 20(1) and § 38 Abs. 1 BSIG, the management body must implement the § 30 measures and oversee their implementation, and under § 38 Abs. 3 BSIG must attend regular training. Management can be held liable under § 38 Abs. 2 BSIG.
What happens if we do not implement the measures?
Failure to implement a § 30 measure is an administrative offence under § 65 BSIG, with fines up to ten million euros for essential entities and seven million euros for important entities; turnover-based caps of 2 % or 1,4 % apply above 500 million euros in total turnover. The BSI supervises and enforces compliance under §§ 61-62 BSIG. If you find a gap, art 21(4) requires prompt corrective measures.
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.