Live · DACH ops
03:47 · QR-2 · Sektor B · 0 anomalies04:03 · QR-7 · Gate 4 · handover ack04:11 · QR-2 · Sektor B · patrol complete · 4.2 km04:14 · Filderstadt · ops ack · all green04:22 · QR-12 · Stuttgart-W · charge cycle 84%04:30 · QR-3 · Karlsruhe · perimeter sweep · pass 3/404:38 · QR-9 · Wien-N · weather check · IP65 nominal04:45 · QR-2 · Sektor B · thermal hit reviewed · benign04:52 · QR-15 · Zürich-O · escalation queue · empty05:00 · all units · shift turnover · zero incidents03:47 · QR-2 · Sektor B · 0 anomalies04:03 · QR-7 · Gate 4 · handover ack04:11 · QR-2 · Sektor B · patrol complete · 4.2 km04:14 · Filderstadt · ops ack · all green04:22 · QR-12 · Stuttgart-W · charge cycle 84%04:30 · QR-3 · Karlsruhe · perimeter sweep · pass 3/404:38 · QR-9 · Wien-N · weather check · IP65 nominal04:45 · QR-2 · Sektor B · thermal hit reviewed · benign04:52 · QR-15 · Zürich-O · escalation queue · empty05:00 · all units · shift turnover · zero incidents
← All articles
KRITIS · Umbrella Act · NIS-2

Am I Affected by NIS-2? 5-Step Self-Check 2026

Check NIS-2 & KRITIS applicability yourself: thresholds, sector list and decision tree. Clarify in 5 steps whether your company is obligated in 2026 — and what follows.

Dr. Raphael Nagel (LL.M.)
Investor & Author · Founding Partner
Follow on LinkedIn

Am I affected by NIS-2? The 5-step self-check

The short answer: you are likely in scope if your company has at least 50 employees or €10m annual turnover and operates in one of the sectors regulated by NIS-2. In Germany that captures roughly 29,000 companies — far more than the classic KRITIS operators.

This self-check clarifies your applicability in five steps. It is not legal advice, but it gives a solid first assessment based on the NIS2 Implementation Act and the KRITIS-Dachgesetz.

Step 1: Am I in a regulated sector?

NIS-2 distinguishes essential and important entities. Check whether your activity falls into one of these sectors:

Sector group Examples
Energy electricity, gas, oil, district heating, hydrogen
Transport air, rail, water, road
Banking & financial market credit institutions, trading venues
Health hospitals, labs, pharmaceutical makers
Drinking & waste water waterworks, treatment plants
Digital infrastructure data centres, DNS, cloud, telecom
Public administration authorities (partly)
Space ground infrastructure
Post & courier delivery services
Waste management disposal, recycling
Chemicals manufacture, trade, distribution
Food production, processing, wholesale
Manufacturing medical devices, electronics, machinery, automotive
Digital services marketplaces, search engines, social networks
Research research organisations

If you are in none of these, the check usually ends here.

Step 2: Do I exceed the thresholds?

Size class Employees Turnover / balance sheet Consequence
Essential entity ≥ 250 > €50m / > €43m full duties, stricter supervision
Important entity ≥ 50 > €10m full duties, reactive supervision
Below < 50 < €10m usually not in scope*

*Exception: certain operators (qualified trust-service providers, DNS, telecom) are in scope regardless of size.

Step 3: Am I also a KRITIS operator?

Operators exceeding defined KRITIS-Verordnung thresholds (supplying large parts of the population) are additionally KRITIS operators under the KRITIS-Dachgesetz — with BSI registration duty and the express obligation of object protection, surveillance and access control. For scale: the BSI counted 1,211 registered KRITIS operators in Germany as of 31 Dec 2025.

Step 4: What obligations apply if in scope?

Obligation Deadline / cadence
BSI registration within 3 months of becoming in scope
Risk management (Art. 21) ongoing, technical and physical
Incident reporting initial report within 24 hours
Management: approval & training ongoing, personal liability
"State of the art" proof ongoing, documented

Details: NIS-2 and KRITIS requirements.

Step 5: What does inaction cost?

Fines up to €10m or 2% of global annual turnover, plus personal liability of management. The duty cannot be delegated to the IT department — it sits with the board.

Where scope is confirmed, physical perimeter and asset protection is usually the most demanding open point. Robotic continuous monitoring on the RaaS model can be piloted within 48 hours and delivers the "state-of-the-art" proof from live operation.

Frequently asked questions

Am I affected by NIS-2 with fewer than 50 employees? Usually no — unless you are a size-independent regulated operator (DNS, telecom, trust services) or a KRITIS-threshold operator.

What is the difference between NIS-2 and KRITIS? KRITIS captures the most systemically critical operators with registration and an explicit object-protection duty; NIS-2 widens the circle to ~29,000 companies with risk-management and reporting duties. Overlap is the rule.

How fast must I act? Registration within 3 months of becoming in scope; incident reporting within 24 hours. Proof duties are ongoing.


Basis: Dr. Raphael Nagel (LL.M.) / Marcus Köhnlein, "KRITIS – Die verborgene Macht Europas" (2026). Not legal advice.

Translations

Call now+49 160 970 36804Free quote · 24 hCalculate price →