NIS2

Being secure is not enough. You have to be able to prove it.

The German NIS2 implementation act has been in force since 6 December 2025. For IT service providers it creates less of a technical problem than an evidence problem — and it usually arrives through customers rather than through their own scope.

06.12.2025

NIS2 implementation act in force, with no general transition period

≈ 29,500

entities the BSI expects under supervision — up from around 4,500

€10m

maximum fine, expressly including missing documentation

6.1.10

entity type for managed service providers in Anlage 1 BSIG

The situation

The real problem is the evidence.

Most system houses have long been patching, backing up and monitoring. Where it breaks down is the proof — retrospectively, for a given date, for an auditor.

A customer sends a supplier questionnaire with 40 questions on IT security.

The question is not “do you patch?” but “evidence the patch level as of 31 March”.

Who accessed which system remotely, and when, is almost impossible to reconstruct after the fact.

For every customer enquiry the same analysis is assembled by hand all over again.

Exceptions to patching are justified on technical grounds — but documented nowhere.

The duties

What the BSIG actually requires

Condensed to what matters in practice for IT service providers. The statutory text governs.

§ 33 BSIG

Registration

Within three months via the BSI portal, access through Mein Unternehmenskonto. Among other things, public IP address ranges must be reported. Changes within two weeks.

§ 32 BSIG

Incident reporting

24 hours for the early warning, 72 hours for the report with an assessment, one month for the final report. For MSPs the threshold definition of DVO (EU) 2024/2690 applies directly.

§ 30 BSIG

Risk management

Ten areas of measures, from risk analysis through supply chain and vulnerability management to multi-factor authentication. And expressly: the implementation must be documented.

Whether you are in scope yourself can be checked free of charge and anonymously. The BSI provides a scope assessment for this — not legally binding, but a sound first indication. To the BSI assessment

What octoja contributes

Eight requirements that arise in day-to-day operation anyway

Every line names its source so you can check the statement.

A complete, current inventory of all systems

DVO (EU) 2024/2690, Anhang 12.4

Hardware, software, services and accounts are recorded continuously. The inventory history shows by comparison what changed on which device and when — including the end of operating system support.

Vulnerability and patch management, with a reason where a patch is not applied

§ 30 Abs. 2 Nr. 5 BSIG, DVO Anhang 6.6

Patch level per endpoint with a timestamp, documented approvals naming the decision-maker, exclusions with a stored justification. As a PDF report for a given date.

Logging, in particular of privileged access

DVO Anhang 3.2

Every remote session appears in the device log with person, time and action. Changes to permissions and settings appear in the change log across 26 object types.

Backup and documented recovery testing

§ 30 Abs. 2 Nr. 3 BSIG, DVO Anhang 4.2

Cross-vendor monitoring of backup runs with a status report and notification of failed jobs. The recovery test itself is yours to carry out — octoja evidences the state, not the exercise.

Multi-factor authentication and access control

§ 30 Abs. 2 Nr. 10 BSIG, DVO Anhang 11.2–11.7

Two-factor per account, single sign-on, 17 separate device action rights and an access overview that resolves who may reach which device, and why.

Incident detection for the 24-hour early warning

§ 32 BSIG, DVO Anhang 3.2.4

Alerting with service hours per channel — by phone to the on-call engineer at night. Every alert carries a timestamp, which is what makes the reporting deadline evidenceable.

Protection against malware, detection of unapproved software

DVO Anhang 6.9

Protection status of common antivirus and EDR products, plus a software inventory across the entire estate.

Configuration and change management

DVO Anhang 6.3 und 6.4

Configuration packages as a baseline, checks for deviation in directory permissions, files and registry values.

Scope

What octoja expressly does not do

An RMM is not a management system. Anyone promising you NIS2 compliance out of a piece of software is selling you a problem.

Risk analysis and an information security management system
Training and management liability under § 38 BSIG
Personnel security and background checks
Cryptography concepts and physical security
Registration with the BSI, and the reporting itself
Common questions

What system houses ask us about this

Is my system house itself subject to NIS2?

Managed service providers are expressly named in Anlage 1 of the BSIG under sector 6, “digital infrastructure”, as entity type 6.1.10. Whether you fall under it is decided by the size threshold: an important entity from 50 employees, or from 10 million euros in turnover and balance sheet total. Many system houses sit below that — and are still pulled into the duties through their customers' supply chain.

Does octoja make my company NIS2-compliant?

No, and any vendor claiming so is promising too much. NIS2 requires a management system with risk analysis, training and organisational measures. octoja delivers the technical evidence out of day-to-day operation — patch level, inventory, access logs, backup state — that is, precisely the part that would otherwise be assembled laboriously by hand.

What happens if the documentation is missing?

§ 30 Abs. 1 Satz 3 BSIG expressly obliges you to document the measures. § 65 BSIG makes breaches subject to a fine — up to 10 million euros for essential and 7 million euros for important entities. So it is not enough to be secure; you have to be able to prove it.

How do I know whether I am in scope?

The BSI provides a free and anonymous scope assessment. It is not legally binding, but it gives a sound first indication.

This page is an orientation, not legal advice. What governs is the BSIG as amended by the NIS2 implementation act, together with Implementing Regulation (EU) 2024/2690.

See the evidence against your own estate

During trial access you roll the agent out to a few real devices and produce the patch compliance report with your own data.