NIS2 Evidence in Germany: What the BSI Expects — and How a Penetration Test Delivers It
Key points
The binder is full. The effectiveness is untested.
- NIS2 has applied in Germany since 6 December 2025 — with no transition period. The BSI expects around 29,500 entities to be in scope.
- § 30 BSIG requires more than policies: no. 6 demands procedures to assess how effective your measures are. Whether they hold against a real attacker is something no document proves.
- Compliance must be documented (§ 30(1)). Failing to do so is an administrative offence in its own right.
- The penetration test is the most common way to evidence effectiveness — and also provides evidence for risk analysis, vulnerability handling and access control.
Where NIS2 stands today
Germany’s NIS2 Implementation Act entered into force on 6 December 2025 and replaced the BSI Act. According to the BSI, the number of supervised entities rises from around 4,500 to around 29,500. By the end of June 2026, the BSI reported 17,729 registered entities — considerably fewer than expected.
Entities in the sectors of Annexes 1 and 2 of the BSIG are in scope. Important entities generally have at least 50 employees, or more than €10m annual turnover and balance sheet. Essential entities have at least 250 employees, or more than €50m turnover and more than €43m balance sheet; operators of critical facilities are among them as well (§ 28 BSIG).
The ten minimum measures of § 30(2) BSIG
The measures should reflect the state of the art and follow an all-hazards approach. They include at least:
Policies on risk analysis and information system security
Incident handling
Business continuity: backup management, disaster recovery, crisis management
Supply chain security
Security in acquisition, development and maintenance — including vulnerability handling and disclosure
Policies and procedures to assess the effectiveness of risk-management measures
Basic cyber hygiene training and awareness
Cryptography
Human resources security, access control and asset management
Multi-factor authentication, secured communications and emergency communications
Most NIS2 projects stop at nos. 1 to 5 and 7 to 10: policies, procedures, a management system. That is necessary. But no. 6 asks about effectiveness— does what you documented actually hold against a real attacker? Only a test answers that.
What evidence a penetration test provides
A well-documented test supports several measures at once — not only no. 6.
| Measure under § 30(2) | What the test evidences |
|---|---|
| No. 1 — Risk analysis | Which risks are actually exploitable, not just listed in the matrix? The test delivers a real attack path and a CVSS-prioritised list of findings. |
| No. 5 — Vulnerability handling | Findings with a remediation deadline, re-test result and date — evidence that vulnerabilities are not just found but closed. |
| No. 6 — Effectiveness assessment | The core: a dated test by an independent tester shows whether the documented measures hold against an attacker. Repeated yearly, it becomes a track record. |
| Nos. 9 and 10 — Access and MFA | Checks whether access control and MFA apply where the policy says they do — including forgotten accounts, test systems and service accounts. |
| No. 2 — Incident handling | An assumed-breach scenario shows whether an intruder gets noticed — and whether reporting within 24 hours is realistic. |
What makes a test report usable as evidence
- Date, scope and method (e.g. OWASP, PTES, BSI guidance) — clearly recorded
- Findings with severity, reproduction and a concrete recommendation, not raw tool output
- A management summary that management can read and sign off
- A re-test showing which findings were fixed — with a date
- An honest statement of what was not tested
The reporting obligation: 24 hours, 72 hours, one month
within 24 hours at the latest
Early notification
Whether unlawful or malicious acts are suspected and whether there could be a cross-border impact.
within 72 hours at the latest
Notification
Confirmation or update, an initial assessment of severity and impact, indicators of compromise.
within one month at the latest
Final report
Description, root cause, mitigation measures, cross-border impact — counted from the 72-hour notification.
Reports go to the joint reporting office of the BSI and the BBK (§ 32 BSIG). An intermediate report is due at the BSI’s request; if the incident is still ongoing after one month, a progress report replaces the final report. As with any reporting obligation: you can only report what you notice. Whether you would is what a test from the perspective of an attacker already inside your network shows.
Management and fines
§ 38 BSIG holds management accountable: it must implement the risk-management measures and supervise their implementation, is liable to the entity for culpably caused damage under company law, and must attend training regularly. A test report with a management summary is also a tool for exactly this supervision.
Breaches of §§ 30 and 32 can be fined up to €10m for essential and up to €7m for important entities. The often-quoted 2% and 1.4% of worldwide turnover only apply to entities with more than €500m total turnover (§ 65 BSIG). Failing to register can be fined up to €500,000.
Seven steps to a robust evidence file
In this order — registration first, technology second.
- 1
Clarify and document whether you are in scope
A sector listed in Annex 1 or 2 of the BSIG, at least 50 employees, or more than €10m turnover and balance sheet? Record the assessment in writing — even if the answer is "not in scope".
- 2
Check your registration
Registration with the BSI is due no later than three months after becoming subject to the law (§ 33 BSIG). The BSI expected outstanding registrations to be completed by the end of July 2026. If you have not registered, do that before anything else.
- 3
Map the ten measures against your status
For each item in § 30(2): what exists, where is it documented, who owns it? The gaps are your action plan.
- 4
Have the effectiveness tested
A penetration test of your most important externally reachable systems and applications — with a report, findings and a re-test. This is the part no document replaces.
- 5
Define the reporting path
Who decides whether a significant incident has occurred? Who reports to the joint BSI/BBK reporting office within 24 hours? Rehearse the process once.
- 6
Involve management
Management must implement the measures, supervise their implementation and attend training regularly (§ 38 BSIG). Schedule the training and keep proof of attendance.
- 7
Keep an evidence file
Policies, test reports, re-test results, training records, incident logs — dated and in one place. The BSI can request evidence; § 30(1) explicitly requires you to document compliance.
Frequently asked questions about NIS2 evidence
Does NIS2 require a penetration test?
Not literally. § 30(2) no. 6 BSIG requires "policies and procedures to assess the effectiveness" of risk-management measures, without prescribing a method. In practice, the penetration test is the most common and best-documented way to do it — a vulnerability scan alone is the weaker position.
How often should the evidence be renewed?
The law does not set an interval. Established practice is one full test per year, plus after significant changes such as a new application, a new interface or a major architecture change.
What are the deadlines for reporting a security incident?
An early notification within 24 hours at the latest, a notification with an initial assessment and indicators of compromise within 72 hours, an intermediate report at the BSI’s request, and a final report no later than one month after the 72-hour notification (§ 32 BSIG). If the incident is still ongoing by then, a progress report replaces it.
How high are the fines?
For breaches of § 30 and § 32, up to €10 million for essential and up to €7 million for important entities. The turnover-based caps of 2% and 1.4% of worldwide turnover apply only to entities with more than €500 million total turnover (§ 65 BSIG).
Does NIS2 affect us even if we are not regulated ourselves?
Often, indirectly. § 30(2) no. 4 requires regulated companies to address the security of their supply chain. In practice they ask their service providers and suppliers for security evidence — in procurement, audits and contracts.
Is management personally liable?
Management must implement the measures and supervise their implementation; it is liable to the entity for culpably caused damage under company law (§ 38 BSIG). It must also attend training regularly. The assessment in your specific case belongs with your legal counsel.
If you want support
You can take the steps above with your ISMS consultant. We are happy to handle the technical part — with a German security lead who signs off every report.
NIS2 readiness check
Two days, €2,900: assessment against the technically testable requirements of § 30(2), prioritised gap list and management summary.
See our NIS2 servicesPenetration test
From €3,500, with an audit-ready report and re-test — the effectiveness evidence under no. 6. See the price for your scope upfront in the pentest calculator.
See penetration testingAttack surface monitoring
From €249 per month: ongoing evidence between two tests — anything newly reachable is reported and recorded with a date.
See monitoringWhere our role ends
We don’t assess whether and in which category your company is in scope, don’t register you with the BSI and don’t certify against ISO 27001. We also don’t operate a 24/7 SOC. What we deliver is the technical evidence — and help with remediation. This article is a technical assessment, not legal advice.
Sources
- Act on the Federal Office for Information Security (BSIG 2025), in particular §§ 28, 30, 32, 33, 38, 65 (German)
- BSI: NIS2 Implementation Act enters into force (press release, 05.12.2025, German)
- BSI: NIS-2 in figures (German)
- BDO: NIS-2 — BSI expects outstanding registrations by the end of July 2026 (German)
Get the evidence before someone asks for it
In a 30-minute intro call we assess where you stand and tell you honestly whether a readiness check or a penetration test is the right next step.


