Being secure is not enough. You have to be able to prove it.
The German NIS2 implementation act has been in force since 6 December 2025. For IT service providers it creates less of a technical problem than an evidence problem — and it usually arrives through customers rather than through their own scope.
NIS2 implementation act in force, with no general transition period
entities the BSI expects under supervision — up from around 4,500
maximum fine, expressly including missing documentation
entity type for managed service providers in Anlage 1 BSIG
The real problem is the evidence.
Most system houses have long been patching, backing up and monitoring. Where it breaks down is the proof — retrospectively, for a given date, for an auditor.
A customer sends a supplier questionnaire with 40 questions on IT security.
The question is not “do you patch?” but “evidence the patch level as of 31 March”.
Who accessed which system remotely, and when, is almost impossible to reconstruct after the fact.
For every customer enquiry the same analysis is assembled by hand all over again.
Exceptions to patching are justified on technical grounds — but documented nowhere.
What the BSIG actually requires
Condensed to what matters in practice for IT service providers. The statutory text governs.
Registration
Within three months via the BSI portal, access through Mein Unternehmenskonto. Among other things, public IP address ranges must be reported. Changes within two weeks.
Incident reporting
24 hours for the early warning, 72 hours for the report with an assessment, one month for the final report. For MSPs the threshold definition of DVO (EU) 2024/2690 applies directly.
Risk management
Ten areas of measures, from risk analysis through supply chain and vulnerability management to multi-factor authentication. And expressly: the implementation must be documented.
Whether you are in scope yourself can be checked free of charge and anonymously. The BSI provides a scope assessment for this — not legally binding, but a sound first indication. To the BSI assessment
Eight requirements that arise in day-to-day operation anyway
Every line names its source so you can check the statement.
A complete, current inventory of all systems
DVO (EU) 2024/2690, Anhang 12.4
Hardware, software, services and accounts are recorded continuously. The inventory history shows by comparison what changed on which device and when — including the end of operating system support.
Vulnerability and patch management, with a reason where a patch is not applied
§ 30 Abs. 2 Nr. 5 BSIG, DVO Anhang 6.6
Patch level per endpoint with a timestamp, documented approvals naming the decision-maker, exclusions with a stored justification. As a PDF report for a given date.
Logging, in particular of privileged access
DVO Anhang 3.2
Every remote session appears in the device log with person, time and action. Changes to permissions and settings appear in the change log across 26 object types.
Backup and documented recovery testing
§ 30 Abs. 2 Nr. 3 BSIG, DVO Anhang 4.2
Cross-vendor monitoring of backup runs with a status report and notification of failed jobs. The recovery test itself is yours to carry out — octoja evidences the state, not the exercise.
Multi-factor authentication and access control
§ 30 Abs. 2 Nr. 10 BSIG, DVO Anhang 11.2–11.7
Two-factor per account, single sign-on, 17 separate device action rights and an access overview that resolves who may reach which device, and why.
Incident detection for the 24-hour early warning
§ 32 BSIG, DVO Anhang 3.2.4
Alerting with service hours per channel — by phone to the on-call engineer at night. Every alert carries a timestamp, which is what makes the reporting deadline evidenceable.
Protection against malware, detection of unapproved software
DVO Anhang 6.9
Protection status of common antivirus and EDR products, plus a software inventory across the entire estate.
Configuration and change management
DVO Anhang 6.3 und 6.4
Configuration packages as a baseline, checks for deviation in directory permissions, files and registry values.
What octoja expressly does not do
An RMM is not a management system. Anyone promising you NIS2 compliance out of a piece of software is selling you a problem.
What system houses ask us about this
Is my system house itself subject to NIS2?
Managed service providers are expressly named in Anlage 1 of the BSIG under sector 6, “digital infrastructure”, as entity type 6.1.10. Whether you fall under it is decided by the size threshold: an important entity from 50 employees, or from 10 million euros in turnover and balance sheet total. Many system houses sit below that — and are still pulled into the duties through their customers' supply chain.
Does octoja make my company NIS2-compliant?
No, and any vendor claiming so is promising too much. NIS2 requires a management system with risk analysis, training and organisational measures. octoja delivers the technical evidence out of day-to-day operation — patch level, inventory, access logs, backup state — that is, precisely the part that would otherwise be assembled laboriously by hand.
What happens if the documentation is missing?
§ 30 Abs. 1 Satz 3 BSIG expressly obliges you to document the measures. § 65 BSIG makes breaches subject to a fine — up to 10 million euros for essential and 7 million euros for important entities. So it is not enough to be secure; you have to be able to prove it.
How do I know whether I am in scope?
The BSI provides a free and anonymous scope assessment. It is not legally binding, but it gives a sound first indication.
This page is an orientation, not legal advice. What governs is the BSIG as amended by the NIS2 implementation act, together with Implementing Regulation (EU) 2024/2690.
See the evidence against your own estate
During trial access you roll the agent out to a few real devices and produce the patch compliance report with your own data.