NIS-2 Compliance 2026: The Physical Security You're Missing
NIS-2 compliance in 2026: who is affected, what physical security measures Article 21 requires, and how operators prove the requirement with audit-ready documentation.
NIS-2 compliance: the three questions to answer first
Most NIS-2 advice on the market comes from the cyber and IT world. That falls short. Article 21 of the NIS-2 Directive (EU 2022/2555) explicitly requires technical and physical risk-management measures — and the physical protection of sites, perimeters and critical assets is exactly what slips through the cracks in nearly every initial assessment.
Three questions decide the scope of action:
- Am I in scope at all?
- What physical measures does the law actually require?
- Who is liable if nothing happens?
Who is affected by NIS-2?
NIS-2 distinguishes essential and important entities. Simplified threshold: at least 50 employees or €10m annual turnover, operating in one of the regulated sectors. In Germany the NIS2 Implementation Act (NIS2UmsuCG) transposes the directive and widens the circle considerably — an estimated ~29,000 companies, far more than the classic KRITIS operators.
For scale, the BSI reported 1,211 registered KRITIS operators in Germany as of 31 Dec 2025 — NIS-2 multiplies that circle.
The clearer legal ground: KRITIS-Dachgesetz and CER
Important for an honest reading: NIS-2 ties physical measures mainly to protecting IT/OT assets (server rooms, access to technical areas). The more explicit mandate for physical site protection sits in the KRITIS-Dachgesetz and the underlying CER Directive (Critical Entities Resilience, EU 2022/2557, in force 2026). These expressly require object protection, surveillance and access control — precisely the job of an autonomous patrol unit.
Operators proving physical resilience should therefore argue via the KRITIS-Dachgesetz (§ 7 "state of the art", object-protection duty) and use NIS-2 as the supporting layer for continuous monitoring under § 30 BSIG. Details: KRITIS requirements, NIS-2 overview.
What physical measures does NIS-2 require?
| Requirement (Art. 21 / § 7 KRITIS-DG) | Physical implementation |
|---|---|
| Risk analysis & security concept | documented perimeter and access assessment |
| Incident handling | detection, alarm escalation, gapless incident logging |
| Business continuity | continuous monitoring even under staffing shortage |
| Security of operations | perimeter control, sabotage and access protection |
| "State of the art" (§ 7 KRITIS-DG) | proven, market-available technology at the upper edge of the usual |
The lever is "state of the art": not the minimum, not the maximum, but the proven upper edge of the usual — and it must be documented. Autonomous perimeter monitoring with audit-ready logging meets exactly this dual requirement: current technology plus verifiable proof.
Who is liable? Management — personally
NIS-2 makes this explicit: management must approve the risk-management measures, oversee their implementation and be trained. Breaches carry fines up to €10m or 2% of global annual turnover — plus personal liability of the governing body. Physical security is no longer a facility-management question; it is board responsibility, and it cannot be delegated to the IT department.
From assessment to deployment
Good NIS-2 work does not end at the gap analysis; it delivers an actionable measure. For physical perimeter and asset protection that is usually a blend of reduced human presence and robotic continuous monitoring — provided as Robotics-as-a-Service, so the measure is immediately effective and treated as operating expense. Low-friction entry: a 14-day zero-risk pilot, 48-hour delivery — RaaS model.
Frequently asked questions
Is NIS-2 only a cyber topic? No. Article 21 requires technical and physical measures. Perimeter, access and sabotage protection are part of the duty.
Who is affected by NIS-2? Essential and important entities from 50 employees or €10m turnover in a regulated sector — ~29,000 companies in Germany.
What are the penalties? Up to €10m or 2% of global annual turnover, plus personal liability of management.
Basis: Dr. Raphael Nagel (LL.M.) / Marcus Köhnlein, "KRITIS – Die verborgene Macht Europas" (2026), chapter 4.
Translations