started · updated
German firms face implementation hurdles under EU NIS2 directive
The EU’s NIS2 cybersecurity directive has generated intense focus on technical measures such as security operations centres and incident response, yet many German companies report limited transparency and fragmented compliance efforts. LEGANTA® argues that the real risk lies in contracts – cloud, outsourcing and software agreements – which determine responsibility, audit rights and liability, and proposes a “Form follows Contract” approach to bridge the gap between regulation and business reality.
A survey by the Eco‑Verband der Internetwirtschaft of 38 member companies highlights practical implementation challenges. Respondents cite documentation duties, 24‑/72‑hour reporting rules, and risk analysis as the biggest obstacles. About 15 % rate the additional workload as very high, another 38 % as high or medium, and none claim no extra effort. Only 18 % say they have fully met NIS2 requirements, 36 % are on schedule, while roughly 18 % report delays. Ulrich Plate, head of Eco’s KRITIS competence group, stresses the need for practical guidance to turn regulatory demands into effective risk‑management processes.
Entities
Bundesamt für Sicherheit in der Informationstechnik (BSI) · Eco – Verband der Internetwirtschaft · NIS2 (EU cybersecurity directive) · Ulrich Plate