Overview
- The draft bill was sent to federal states and industry associations in early July as part of stakeholder consultations
- It obliges up to 29,000 enterprises to conduct regular risk analyses and report cybersecurity incidents under NIS-2 standards
- Coverage spans key sectors ranging from energy and transport to drinking water, food production, sewage and telecommunications
- A publicly accessible NIS-2 applicability test has been taken more than 200,000 times despite widespread organizational unawareness of the new requirements
- Enactment is scheduled by early 2026 following Germany’s miss of the 17 October 2024 transposition deadline for the EU directive