€10 Million Fine?

Image cover for blog post.

Aug 5, 2026

Profile image of Annika Rogg

Annika Rogg

Millions in fines, personal liability of management, and expanded supervisory powers: with the entry into force of the NIS-2 Implementation Act, cybersecurity is no longer just an IT task for many companies, but a responsibility of management and a legal obligation. Nevertheless, many companies do not know to what extent they already meet the requirements of NIS-2 and where action is still required. Together with HK2 Rechtsanwälte, ENTRYZERO has developed the NIS-2 Status Check. Based on an interdisciplinary assessment, the current implementation status of a company is evaluated in a structured way using the risk management measures under Section 30(2) of the BSIG. The results transparently show which requirements are already met, where action is needed, and which measures should be prioritized.

What is NIS-2?

The NIS-2 Directive (Network and Information Security Directive 2) is an EU directive to strengthen cybersecurity. It sets uniform minimum requirements across Europe that companies and organizations can use to better protect their network and information systems against cyberattacks. The focus is on effective risk management, appropriate technical and organizational security measures, and the responsibility of management for their implementation.

In Germany, the requirements of the directive were transposed into national law by the Act on the Implementation of the NIS-2 Directive and the Regulation of Essential Principles of Information Security Management in the Federal Administration (NIS2UmsuCG). The law anchors the requirements primarily in the BSI Act (BSIG) and significantly expands the circle of affected companies.

The risk management measures described in Section 30(2) of the BSIG include, among others:

  • Risk analysis and IT security concepts
  • Handling cyberattacks and security incidents
  • Emergency management and business continuity
  • Supply chain security
  • Secure development, operation and maintenance of IT systems including vulnerability management
  • Review of the effectiveness of security measures
  • Training and awareness for employees
  • Encryption and data security
  • Access and authorization management
  • Secure authentication and communication procedures

The objective of the NIS-2 Directive and its implementation in German law is to sustainably strengthen digital resilience.

What penalties can arise?

Violations of NIS-2 requirements can have significant consequences for companies. Depending on the classification of the company, fines of up to €10 million or 2% of global annual turnover, or €7 million or 1.4% of global annual turnover may be imposed, whichever amount is higher. In addition, the competent supervisory authorities may, depending on the case, order further measures such as audits, the elimination of identified deficiencies or additional reporting obligations. Particularly relevant: management bears its own responsibility for approving, monitoring and controlling cybersecurity measures. NIS-2 therefore makes cybersecurity no longer just an IT task, but an issue at executive level.

Knowing the current status

Many companies have already implemented cybersecurity measures. But do these measures actually meet the requirements of NIS-2 and where are gaps still present? This is precisely where the NIS-2 Status Check comes in. It evaluates the current level of implementation in a structured way based on the risk management measures of Section 30(2) of the BSIG, makes deviations transparent and shows where concrete action is needed. On this basis, companies receive clear recommendations on which measures should be prioritized next. Together. Structured. Legally compliant.

Bochum 2026 ENTRYZERO x NIS-2 x HK2 Rechtsanwälte

Our service at a glance

The NIS-2 Status Check combines legal and technical expertise in an interdisciplinary assessment approach. Together, HK2 Rechtsanwälte and ENTRYZERO assess a company’s current level of implementation based on the ten risk management measures under Section 30(2) of the BSIG. While HK2 Rechtsanwälte handle the legal assessment, ENTRYZERO evaluates the technical implementation of the risk management measures. This creates a holistic picture that transparently shows deviations from legal requirements and provides concrete recommendations for action from both legal and technical perspectives.

The result is a comprehensible and objective decision-making basis for management and those responsible, enabling necessary measures to be prioritized and the implementation of NIS-2 requirements to be advanced in a targeted manner.

Bochum 2026 ENTRYZERO x NIS-2 x HK2 Rechtsanwälte

Bochum 2026 ENTRYZERO x NIS-2 x HK2 Rechtsanwälte

3-step process

The NIS-2 Status Check is structured as a three-step process (see figure). After commissioning and the provision of access data, the joint implementation begins:

Step 1: Recording the current state: The current level of implementation is documented in the NIS-2 Status Check portal.

Step 2: Analysis and transmission of results: The information provided is reviewed by HK2 Rechtsanwälte and ENTRYZERO, and the results are delivered in the form of a concise executive summary.

Step 3: Presentation of results and recommendations: In the final meeting, the reviewed results and concrete recommendations for action are presented from a technical and legal perspective.

Bochum 2026 ENTRYZERO x NIS-2 x HK2 Rechtsanwälte

Fixed price

The NIS-2 Status Check portal is based on a structured questionnaire covering the ten risk management measures under Section 30(2) of the BSIG. For each topic area, targeted review questions are asked to enable a clear, understandable and comparable assessment of the current level of implementation. Based on this, a consistent and well-founded assessment of maturity is created, providing a solid basis for concrete technical and legal recommendations.

Please send requests to RA Karsten U. Bartels LL.M. bartels@hk2.eu or Dr. Mohamad Sbeiti mohamad.sbeiti@entryzero.ai. Subject: “NIS-2 Status Check”.

All Rights Reserved by ENTRYZERO GmbH

IMPRINT: ENTRYZERO GmbH, Technologiezentrum Ruhr, Konrad-Zuse-Straße 18, 44801 Bochum, Registered Office: Bochum, Registration Court: Local Court Bochum, Registration number: HRB 21709, VAT ID: DE369315057, Managing Directors: Dr. Mohamad Sbeiti, Samet Gökbayrak, Tel.: +49 234 94426026, Email: info@entryzero.ai

PRIVACY POLICY: This website does not collect any personal data. We do not use cookies, trackers, forms or similar technologies. However, by visiting our website you agree that for every site request the following non-personal information is stored on the webserver for statistical, intrusion detection/prevention and troubleshooting purposes: requested address (URL), request date and time, client IP address, user-agent and referer. No information is given to or shared with third parties