15.10.2024
Blog
Regulatory
Cyber Security

NIS2 Directive: No implementation legislation in sight yet – what organisations should do now

The EU’s NIS2 Directive, which aims to strengthen cyber security in Europe, was originally due to be transposed into German law by October 2024. However, the German NIS2 Implementation Act is now set to be delayed until at least spring 2025. This delay raises many questions for operators of critical infrastructure and key facilities. What obligations do they now face? What should companies and federal government bodies do to prepare themselves despite the legal uncertainties?

Robert Stricker
Vice President Security Consulting

No direct obligations under the NIS2 Directive

First and foremost, it is important to understand that, unlike regulations, European directives such as the NIS2 Directive do not apply directly in the Member States. They must first be transposed into national law. This means that operators of critical infrastructure and facilities of particular importance have no direct obligations under the NIS2 Directive until the NIS2 Transposition Act has been enacted in Germany. 

Consequently, public authorities may not impose measures or fines on companies whilst the national law is not yet in force. This is particularly important, as it is also unlawful to issue onerous administrative acts on the basis of the NIS2 Directive during this transitional period. 

Delayed implementation: what are the risks?

Nevertheless, there is a certain risk for KRITIS operators. This is because, once the transposition deadline for the NIS2 Directive has passed – i.e. from October 2024 onwards – national courts must interpret existing law in a manner consistent with the Directive. This means that the requirements of the NIS2 Directive may be taken into account when interpreting German laws. 

This could prove particularly relevant in disputes. For example, insurance companies could refuse to pay out if the affected organisations have failed to comply with the security requirements of the NIS2 Directive from October 2024 onwards. Customers affected by cyber-attacks could also rely on the Directive in claims for damages. 

Although the legal situation is becoming more complicated due to the delayed implementation, there is currently no direct obligation to comply with the NIS2 requirements. However, organisations should not see this as a licence to do nothing. 

Why organisations should still take action

Even if the NIS2 Implementation Act does not come into force for the time being, it is not a question of ‘if’ but ‘when’ the law will come into effect. The threat posed by cyberattacks is constantly increasing, and cybersecurity should already be a top priority for every organisation. The important thing is to get started. Implementing cybersecurity for an organisation is like taking up sport: the main thing is to get started; every step is better than doing nothing. 

Furthermore, it is likely that there will be only short, if any, transition periods once the Act has been passed. Anyone who waits until the Act comes into force to take action will therefore find it difficult to meet the new requirements in time. 

Recommendations for operators

Companies should start integrating the currently known requirements of the NIS2 Directive into their cybersecurity strategies right away. Although the legislation has not yet been passed, the business-related provisions are largely clear and are not expected to change significantly. 

Below are some measures that companies and affected federal government bodies should already be implementing: 

  1. Scoping assessment: Organisations that are unsure whether they are affected by the draft NIS 2 Implementation and Cybersecurity Strengthening Act can check this using a web tool on the website of the Federal Office for Information Security (BSI).
  2. Strategic planning and accountability: Senior management must address cybersecurity at an early stage and take responsibility. Personal liability, which is associated with the NIS 2 Implementation Act, will be a key element.
  3. Technical and organisational measures: Organisations should put in place both technical and organisational safeguards. Technical measures primarily concern the IT department, whilst organisational measures must be implemented across all departments. But be warned: Particularly in the KRITIS sector, the regulations also affect the field of operational technology (OT). This too must be secured in accordance with the guidelines. This includes, for example, securing supply chains – which must be coordinated with the procurement department – or staff security, which must be discussed with the HR department.
  4. Optimising risk management: Robust risk management is essential and time-consuming. It is advisable for companies to start identifying risks now and to take appropriate measures to manage them.
  5. Continuous review of security measures: NIS2 requires not only the implementation of measures but also their regular review. Companies should therefore introduce mechanisms at an early stage to validate the effectiveness of their security measures. 

Conclusion: Act now to be prepared for NIS 2

Whilst the delay to the NIS2 Implementation Act gives companies and public authorities a little more time, this should not be left unused. Further information on this can be found in the article ‘Ten steps to NIS2 compliance’. The cyber security threat is very real. Organisations should start adapting their security measures to the requirements of the NIS 2 Directive today. 

Until the Act comes into force, operators have the opportunity to proactively prepare for the upcoming requirements. Those who take action now will not only be better protected but will also be in a position to meet the legal requirements as soon as the NIS 2 Implementation Act comes into force.

All posts from the “Cyber Security 2024” blog series:

  1. It will affect us all eventually – mandatory IT security requirements in 2024
  2. Improving resilience: How to make your IT a rock in the storm
  3. Intelligent attack detection with a Security Information and Event Management (SIEM) system
  4. Responding more quickly to attacks with SecOps – Part 1
  5. Responding more quickly to attacks with SecOps – Part 2
  6. Responding more quickly to attacks with SecOps – Part 3
  7. NIS2 Directive: No implementation legislation in sight yet – what organisations should do now

Robert Stricker
Vice President Security Consulting

Robert Stricker ist Vice President Security Consulting bei Materna.