NIS2 is an IT law. Two of its ten duties still end at your door.
Ahmad Abu ZerCertified Security Master (IHK)
Germany's revised BSI Act (BSIG) has applied since 6 December 2025. It
implements the European NIS2 Directive, came into force without a transition
period, and its scope has grown considerably: instead of roughly 4,000
companies, advisory practice consistently puts the figure at more than 29,000.
[market indication, not an official figure]
If you operate in one of the regulated sectors and have at least 50 employees or 10 million euros in annual turnover, you should check whether you are covered. That check is a legal question, not a security one — it belongs with a law firm or a specialist information-security consultancy, not with us.
That check is not what this article is about.
What section 30 BSIG actually says
Subsection 1 requires "appropriate, proportionate and effective technical and organisational measures" to prevent "disruptions to the availability, integrity and confidentiality of information systems".
That is unambiguous, and it should not be bent: the subject of the subsection is information systems. Fences, doors, server-room doors and locking systems do not appear in it. Anyone selling NIS2 as a hidden law about physical security is overstretching the wording.
Subsection 2 then lists ten measures that give this duty substance. Eight are uncontroversially IT: risk analysis concepts, incident handling, supply chain security, security in acquisition and development, effectiveness assessment, cryptography, multi-factor authentication, secured communications.
Two are not entirely.
Number 9: "security of personnel, access control"
The wording of section 30(2) no. 9 BSIG reads:
"concepts for the security of personnel, access control and for the management of ICT systems, products and processes"
An IT provider reads "access control" as what it knows: an authorisation concept, roles, permissions, revocation on departure. That is correct and necessary.
But access control does not end at the user account. It has a second half, and that half is made of doors:
- Who enters the server room, and who knows they were in there?
- Where does the key to the technical rooms hang, and who had it last?
- Is an external engineer escorted — and if so, by whom at two in the morning?
- What happens to an employee's access card on the day they are dismissed? The user account is usually disabled reliably. The card for the side gate often is not.
"Security of personnel" in the same sentence does not mean occupational safety here, but the question of who may be granted access to which areas at all — reliability, briefing, and control on entry and exit.
Number 3: keeping operations running, and having practised it
The wording of section 30(2) no. 3 BSIG:
"business continuity, such as backup management and disaster recovery, and crisis management"
Backup and recovery are IT. Crisis management is not. A crisis team that exists on paper and has never convened is a list of names, not an organisation. Whoever notices at night that something is going wrong has to know who to call, who decides, and what must not happen before someone has decided.
That is the same work as an alarm and escalation plan for a site, turned towards a different trigger.
The gap this creates
Experience from day-to-day operations is unambiguous: when a duty has two halves and only one of them has an owner, the other one is left lying.
The IT provider implements access control in the system. Who holds the key to the technical room is outside their brief. Facilities manages keys but has nothing to do with NIS2 and often does not even learn that the duty exists. Between the two lies no vulnerability in a system, but a gap in responsibility.
That — and only that — is our part. We do not advise on information security, we do not implement a management system, and we do not assess whether you fall under the act. We look at whether the physical side of access control and the alarm organisation will hold when it matters.
And if you are critical infrastructure, something else applies as well
NIS2 is not the only new law. The KRITIS Umbrella Act has applied since 17 March 2026 and, unlike the BSIG, is explicitly a law about physical resilience: section 13(3) names site demarcation, access control, detection and exercises, and no. 2(a) uses the German word for site protection verbatim. Anyone covered by both should not merge them into one project — they have different addressees, deadlines and supervisory authorities.
We have written a separate article on that: The KRITIS Umbrella Act: why the law says "site protection" in as many words.
What this means for you
- First establish whether you are covered at all — with a law firm or an information-security consultancy. That is a legal question.
- Then ask who actually implements numbers 9 and 3. If the answer for the physical half is "IT handles that too", it is most likely not implemented.
- Check the handover points, not the systems: keys, access cards, escorting of external staff, the leaver process, the alerting chain at the weekend.
If you are unsure about point 3, we will take a look. If your responsibilities there are cleanly settled, we will tell you that too — and you have one worry less.
This article reflects the position as at 8 August 2026 and does not replace legal advice. Whether and to what extent an entity falls under the BSIG must be assessed case by case.
