
You may have heard the term “NIS2” recently—in the news, from your tax advisor, or from one of your business partners. And you have probably wondered: Do I need to worry about it too?
Here’s the honest answer upfront: For most small businesses in the Rhein-Erft district, the answer is “not directly”—but that doesn’t mean you should ignore the topic. Let me explain why in a clear and practical way.
What is NIS2?
NIS2 is an EU cybersecurity directive that has been implemented in Germany through national legislation. Its goal is simple: organizations whose disruption could significantly affect society should better protect their IT systems against cyberattacks.
Around 29,500 organizations in Germany are affected—significantly more than under the previous rules. Those within scope must register with the German Federal Office for Information Security (BSI) and implement specific cybersecurity measures.
Does this apply to my business?
For many businesses, here is the good news: NIS2 primarily applies to medium-sized and large organizations operating in specific sectors. As a general rule of thumb, an “important entity” has at least 50 employees or an annual turnover exceeding €10 million in one of the regulated sectors.
This means that a typical medical practice, a craft business with ten employees, or a small accounting office will generally not be directly subject to NIS2 requirements. So if someone wants to sell you an expensive “NIS2 package” even though you run a small business, ask a few critical questions first.
Would you like to check for yourself? The BSI provides a free, anonymous self-assessment tool (link below). It offers an initial indication but is expressly not a legally binding assessment.
The Catch: The Supply Chain
Now for the part many businesses overlook. Even if your company is not directly subject to NIS2, the topic can still affect you indirectly.
Organizations covered by NIS2 must also consider the cybersecurity of their suppliers and service providers. In practice, this means that larger customers may pass their security requirements on to you. Suddenly, you may be asked questions such as: “Do you have a tested backup strategy? Do you use multi-factor authentication? How do you report a security incident?”
Companies that can answer these questions confidently remain attractive business partners. Those that cannot may lose valuable contracts.
What Does This Mean in Practice?
The requirements may sound complex, but they essentially amount to good IT hygiene—things every business should already have in place:
- Reliable backups that can actually be restored when needed (not just running somewhere in the background).
- Secure access to systems, for example using multi-factor authentication.
- Regular updates and proper vulnerability management.
- A simple incident response plan: Who does what if something happens?
- Security-aware employees who can recognize phishing emails.
None of this is rocket science—but it does require proper implementation and ongoing maintenance.
What You Should Do Now
Whether NIS2 applies directly to you or not, these three steps are worthwhile for every business:
- Assess whether you are affected. Company size, turnover, and sector provide a good indication. In borderline cases, the final assessment is a legal matter and should be clarified with a qualified lawyer or the BSI.
- Review your basic cybersecurity. Do your backups work? Are your accounts protected? What happens if your systems fail? These measures protect your business regardless of legal requirements.
- Be prepared for customer questions. If larger clients ask about your cybersecurity, you want to answer confidently.
Learn More
If you would like to learn more, here are the official sources from the German Federal Office for Information Security (BSI):
- Am I affected? – Official BSI self-assessment: betroffenheitspruefung-nis-2.bsi.de – a short anonymous questionnaire providing an initial indication. Important: the result is guidance only and is not legally binding.
- Information for organizations covered by NIS2: bsi.bund.de – NIS2-regulated organizations
- The original NIS2 Directive (Directive (EU) 2022/2555): You can find the full legal text via the BSI page on the NIS2 Directive.
My Offer
I’m not a fan of fear-based marketing, and I certainly won’t sell you services you don’t need. That’s why I offer an honest initial assessment: Does NIS2 actually apply to your business—and how strong is your current cybersecurity foundation? If your situation falls into a legal grey area, I’ll tell you openly instead of guessing.
If you would like clarity for your business in Bedburg, Bergheim, or the Rhein-Erft district, I would be happy to review your situation personally—free of charge and with no obligation. I will clearly explain what needs immediate attention and what can wait.
Get in Touch
You do not need to prepare anything. Just send me a few lines describing your situation—whether you have a specific NIS2 question, concerns about your backup strategy, or simply want reliable IT. I will personally get back to you, usually within a few hours.
Status: July 2026. This article provides general information and does not constitute legal advice for individual cases.

