Live · DACH ops
03:47 · QR-2 · Sektor B · 0 anomalies04:03 · QR-7 · Gate 4 · handover ack04:11 · QR-2 · Sektor B · patrol complete · 4.2 km04:14 · Filderstadt · ops ack · all green04:22 · QR-12 · Stuttgart-W · charge cycle 84%04:30 · QR-3 · Karlsruhe · perimeter sweep · pass 3/404:38 · QR-9 · Wien-N · weather check · IP65 nominal04:45 · QR-2 · Sektor B · thermal hit reviewed · benign04:52 · QR-15 · Zürich-O · escalation queue · empty05:00 · all units · shift turnover · zero incidents03:47 · QR-2 · Sektor B · 0 anomalies04:03 · QR-7 · Gate 4 · handover ack04:11 · QR-2 · Sektor B · patrol complete · 4.2 km04:14 · Filderstadt · ops ack · all green04:22 · QR-12 · Stuttgart-W · charge cycle 84%04:30 · QR-3 · Karlsruhe · perimeter sweep · pass 3/404:38 · QR-9 · Wien-N · weather check · IP65 nominal04:45 · QR-2 · Sektor B · thermal hit reviewed · benign04:52 · QR-15 · Zürich-O · escalation queue · empty05:00 · all units · shift turnover · zero incidents
← All articles
KRITIS · Umbrella Act · NIS-2

NIS-2 Compliance 2026: The Physical Security You're Missing

NIS-2 compliance in 2026: who is affected, what physical security measures Article 21 requires, and how operators prove the requirement with audit-ready documentation.

Dr. Raphael Nagel (LL.M.)
Investor & Author · Founding Partner
Follow on LinkedIn

NIS-2 compliance: the three questions to answer first

Most NIS-2 advice on the market comes from the cyber and IT world. That falls short. Article 21 of the NIS-2 Directive (EU 2022/2555) explicitly requires technical and physical risk-management measures — and the physical protection of sites, perimeters and critical assets is exactly what slips through the cracks in nearly every initial assessment.

Three questions decide the scope of action:

  1. Am I in scope at all?
  2. What physical measures does the law actually require?
  3. Who is liable if nothing happens?

Who is affected by NIS-2?

NIS-2 distinguishes essential and important entities. Simplified threshold: at least 50 employees or €10m annual turnover, operating in one of the regulated sectors. In Germany the NIS2 Implementation Act (NIS2UmsuCG) transposes the directive and widens the circle considerably — an estimated ~29,000 companies, far more than the classic KRITIS operators.

For scale, the BSI reported 1,211 registered KRITIS operators in Germany as of 31 Dec 2025 — NIS-2 multiplies that circle.

The clearer legal ground: KRITIS-Dachgesetz and CER

Important for an honest reading: NIS-2 ties physical measures mainly to protecting IT/OT assets (server rooms, access to technical areas). The more explicit mandate for physical site protection sits in the KRITIS-Dachgesetz and the underlying CER Directive (Critical Entities Resilience, EU 2022/2557, in force 2026). These expressly require object protection, surveillance and access control — precisely the job of an autonomous patrol unit.

Operators proving physical resilience should therefore argue via the KRITIS-Dachgesetz (§ 7 "state of the art", object-protection duty) and use NIS-2 as the supporting layer for continuous monitoring under § 30 BSIG. Details: KRITIS requirements, NIS-2 overview.

What physical measures does NIS-2 require?

Requirement (Art. 21 / § 7 KRITIS-DG) Physical implementation
Risk analysis & security concept documented perimeter and access assessment
Incident handling detection, alarm escalation, gapless incident logging
Business continuity continuous monitoring even under staffing shortage
Security of operations perimeter control, sabotage and access protection
"State of the art" (§ 7 KRITIS-DG) proven, market-available technology at the upper edge of the usual

The lever is "state of the art": not the minimum, not the maximum, but the proven upper edge of the usual — and it must be documented. Autonomous perimeter monitoring with audit-ready logging meets exactly this dual requirement: current technology plus verifiable proof.

Who is liable? Management — personally

NIS-2 makes this explicit: management must approve the risk-management measures, oversee their implementation and be trained. Breaches carry fines up to €10m or 2% of global annual turnover — plus personal liability of the governing body. Physical security is no longer a facility-management question; it is board responsibility, and it cannot be delegated to the IT department.

From assessment to deployment

Good NIS-2 work does not end at the gap analysis; it delivers an actionable measure. For physical perimeter and asset protection that is usually a blend of reduced human presence and robotic continuous monitoring — provided as Robotics-as-a-Service, so the measure is immediately effective and treated as operating expense. Low-friction entry: a 14-day zero-risk pilot, 48-hour delivery — RaaS model.

Frequently asked questions

Is NIS-2 only a cyber topic? No. Article 21 requires technical and physical measures. Perimeter, access and sabotage protection are part of the duty.

Who is affected by NIS-2? Essential and important entities from 50 employees or €10m turnover in a regulated sector — ~29,000 companies in Germany.

What are the penalties? Up to €10m or 2% of global annual turnover, plus personal liability of management.


Basis: Dr. Raphael Nagel (LL.M.) / Marcus Köhnlein, "KRITIS – Die verborgene Macht Europas" (2026), chapter 4.

Translations

Call now+49 160 970 36804Free quote · 24 hCalculate price →