Latest posts Visit blog

The NIS2 directive has arrived in Germany – with no transition periods. Since December 6, 2025, the revised BSI Act has been in force (BSI). For online retailers, this means: New obligations regarding cybersecurity, incident reporting, and supply chain control apply immediately. Around 30,000 entities in Germany fall within the scope according to the estimate in the German government bill (BT-Drs. 20/13184). Companies that fail to meet the requirements face significant fines – and management is liable to its own entity for culpably caused damage (Section 38 BSIG). In this article, you will learn what NIS2 means for your online shop and how to approach implementation.

NIS2 in Germany – Current Status and Deadlines

After extended delays, Germany has transposed the EU NIS2 Directive (Network and Information Security Directive 2) into national law. The NIS2 Implementation Act entered into force on December 6, 2025 as the revised BSI Act (BSI). This means the new cybersecurity obligations apply without transition periods – affected companies must comply immediately.

Registration with the BSI: Three-Month Deadline

Affected entities must register with the BSI no later than three months after they first qualify as an important or essential entity (Section 33(1) BSIG). For companies that were already covered when the act entered into force, this deadline ended on March 6, 2026 – anyone who missed the registration should complete it. Companies that grow into the scope later, for instance by exceeding the thresholds, have three months from that point. Registration is completed via the BSI portal and includes information about company size, sector, and contact details for security incidents.

Unlike many EU regulations, NIS2 has no transition periods (BSI). The obligations to implement security measures, report incidents, and register apply immediately. For online retailers, this means: Act now, do not wait.

The NIS2 directive significantly expands the scope compared to its predecessor NIS1. While NIS1 only covered a few sectors such as energy and transportation, NIS2 includes considerably more industries – including digital infrastructures, cloud services, and online marketplaces. For the e-commerce sector, this represents a paradigm shift: Cybersecurity is no longer a voluntary measure but a legal obligation with concrete sanctions.

Are You Affected? Criteria for Online Retailers

The NIS2 directive captures companies based on size criteria and sector classification. Online marketplaces are classified as "Important Entities" under Annex II of the EU directive (EU NIS2 Directive). Whether your company is affected depends on the following thresholds:

CriterionImportant EntityEssential Entity
EmployeesFrom 50From 250
Annual RevenueFrom 10M EURFrom 50M EUR
Balance SheetFrom 10M EURFrom 43M EUR
Fine FrameworkUp to 7M EURUp to 10M EUR

What matters is how the criteria combine: the headcount alone is enough, while annual revenue and balance sheet total must both exceed the threshold (Section 28 BSIG). The BSI Act lists providers of online marketplaces in Annex 2, the list of important entities; the essential tier is tied to Annex 1 by Section 28(1). Online retailers operating a B2B marketplace or acting as a digital service provider are particularly frequently affected. Companies serving critical supply chains can also be captured regardless of their size.

Smaller retailers may also be affected

Even if your company does not meet the size thresholds: If you act as a supplier for NIS2-obligated companies, you can be indirectly affected. The requirements for supply chain security extend across the entire value chain.

The 10 Minimum Measures Under Article 21

Article 21 of the NIS2 directive defines ten minimum measures that all affected companies must implement (EU NIS2 Directive). For online shops, we have prepared these requirements in a practical format:

  1. Risk analysis and security policies: Systematic assessment of IT risks for your online shop, including threat modeling and vulnerability analysis
  2. Incident handling: Documented processes for detection, analysis, containment, and recovery during security incidents
  3. Business continuity and crisis management: Contingency plans for continued shop operations during cyberattacks, including backup strategies
  4. Supply chain security: Assessment and monitoring of cybersecurity across your service providers, hosting partners, and integration partners
  5. Security in acquisition, development, and maintenance: Secure software development following security-by-design principles
  6. Effectiveness assessment: Regular review and testing of implemented security measures
  7. Cyber hygiene and training: Regular training for all employees on cybersecurity and current threats
  8. Cryptography and encryption: Appropriate encryption for data in transit and at rest – particularly relevant for customer data in e-commerce
  9. Access control and asset management: Multi-factor authentication, access restrictions, and complete inventory of all IT assets
  10. Secure communications: Encrypted communication channels and emergency communication systems

Implementing these measures requires a risk-based approach – meaning measures must be proportional to the identified risks. Professional hosting with integrated security measures already covers several of these requirements.

The requirements for cryptography and encryption as well as access control are particularly relevant for online shops. Customer data, payment information, and order histories must be encrypted both in transit and at rest. Multi-factor authentication for administrative access to the shop backend should be considered a minimum standard. If you are unsure which measures should take priority, you can request an individual initial assessment via our contact page.

Duties and Liability of Management

One of the most significant innovations of the NIS2 implementation in Germany: Management itself carries the duty. It has to implement the risk management measures and monitor their implementation. If it breaches that duty, it is liable to its own entity for culpably caused damage under the applicable rules of company law (Section 38(1) and (2) BSIG).

Oversight Obligation

Management must implement the risk management measures and monitor their implementation (Section 38(1) BSIG).

Training Obligation

Management must attend training regularly in order to assess risks and risk management practices (Section 38(3) BSIG).

Liability Risk

In the event of a breach, management is liable to its own entity for culpably caused damage (Section 38(2) BSIG).

What management cannot delegate

The duty to implement and monitor rests with management itself and cannot be handed to employees or external service providers (Section 38(1) BSIG). Directors and board members must actively engage with their company’s cybersecurity strategy. Professional consulting helps minimize liability risks.

Incident Reporting Obligations

NIS2 introduces a three-tier reporting system for security incidents. Online retailers must report significant security incidents to the BSI within strict deadlines (BSI):

ReportDeadlineContent
Initial Report24 hoursType of incident, initial assessment, affected systems
Follow-up Report72 hoursUpdated assessment, severity, impact
Final Report1 monthDetailed analysis, root cause, measures taken

The 24-hour deadline for the initial report is particularly demanding (BSI). It requires that your company can actually detect security incidents promptly. Without professional monitoring and automated alerting, this is hardly achievable. A documented incident response plan is therefore indispensable.

Preparing for Emergencies

Create an incident response plan now with clear responsibilities and communication channels. Test the plan regularly through exercises. This enables you to meet the 24-hour deadline in an emergency.

Supply Chain Security in E-Commerce

A central aspect of the NIS2 directive is supply chain security (EU NIS2 Directive). For online retailers, this means: You must not only secure your own IT infrastructure but also assess and monitor the cybersecurity of your service providers and partners.

In e-commerce, the digital supply chain typically includes:

  • Hosting providers: Is your server hosting certified to current security standards?
  • Payment providers: Do your payment service providers meet PCI-DSS and NIS2 requirements?
  • ERP integrations: Are your system connections protected against unauthorized access?
  • Logistics partners: How secure are the digital interfaces with your shipping providers?
  • Marketing tools: Do third-party integrations meet security requirements?
  • Shop system providers: Are security updates applied promptly?

Assessing supply chain security requires contractual agreements with your service providers, regular audits, and documented supplier risk management. Professional consulting helps identify the critical vulnerabilities.

In practice, this means: Request evidence of security measures from your hosting providers, payment processors, and logistics partners. Contractually agree that security incidents potentially affecting your data are reported without delay. And regularly verify that your integrations are configured according to current security standards. The effort may initially seem high, but it protects your business from cascading security incidents where a vulnerability at one service provider could compromise your entire shop.

Practical Implementation – Your NIS2 Checklist

NIS2 implementation may seem complex, but it can be broken down into concrete steps. Here is your checklist for the most important measures:

  • Conduct affected assessment: Check whether your company falls under NIS2 based on size and sector criteria
  • Check BSI registration: Register via the BSI portal if you have not done so yet – the deadline is three months after your company falls within the scope
  • Create risk analysis: Systematically identify and assess all IT risks of your online shop
  • Set up incident response plan: Define processes, responsibilities, and communication channels for emergencies
  • Conduct supply chain audit: Assess the security of all service providers and integration partners
  • Implement security measures: Encryption, access control, backup strategy, secure hosting
  • Involve management: Organize cybersecurity training for the leadership level
  • Set up monitoring: Automated detection of security incidents with alerting
  • Train employees: Conduct regular cyber hygiene training for all staff
  • Create documentation: Document all measures, processes, and decisions comprehensively
Our Approach

As an e-commerce agency specializing in secure infrastructure, we support you with NIS2 implementation. From the affected assessment through technical implementation to ongoing monitoring – we guide you through the entire process.

NIS2 implementation is not a one-time project but an ongoing process. Security measures must be regularly reviewed, updated, and adapted to new threats. An experienced partner for consulting and hosting helps to anchor this review firmly in the operation of your shop.

Especially in combination with modern security architectures like Zero Trust and fundamental IT security measures for e-commerce, you achieve comprehensive protection for your online shop. SEO optimization should not be neglected either – security measures such as encryption and stable operation also affect discoverability.

Sources and Studies

This article is based on: BSI (Federal Office for Information Security) – NIS2 Implementation Act and BSI Act, EU NIS2 Directive (Directive (EU) 2022/2555), the BSI Act, in particular Sections 28, 30, 32, 33, 38 and 65. Regulatory requirements may change through further implementing regulations and BSI guidelines. As of: September 2026.

The revised BSI Act has been in force since December 6, 2025 (BSI). There are no transition periods – all obligations have applied directly since then. For companies already covered at entry into force, the BSI registration deadline ended on March 6, 2026; those covered later must register within three months (Section 33(1) BSIG).

Online marketplaces are classified as "Important Entities" under Annex II of the NIS2 directive (EU NIS2 Directive). It covers entities in the sectors listed in Annex 2 that employ at least 50 people or whose annual revenue and balance sheet total each exceed 10 million euros (Section 28(2) BSIG). Smaller companies can also be affected as part of the supply chain.

For important entities – which include providers of online marketplaces – fines reach up to seven million euros, for essential entities up to ten million euros (Section 65(5) BSIG). Only above a total turnover of more than 500 million euros does a rate of 1.4 percent of total turnover replace the fixed amount for important entities (Section 65(7) BSIG). In addition, management is liable to its own entity for culpably caused damage (Section 38(2) BSIG). Early consulting helps minimize risks.

Significant security incidents must be reported to the BSI within 24 hours as an initial report (BSI). Within 72 hours, an updated assessment follows, and after one month, a detailed final report. Professional monitoring facilitates timely detection.

We support you with affected assessments, implement technical security measures, provide secure hosting with monitoring, and guide the NIS2-compliant securing of your e-commerce infrastructure. Our consulting covers the entire implementation process.

The GDPR protects personal data, whereas NIS2 governs the cybersecurity of network and information systems. Both frameworks apply in parallel: An online shop typically has to meet both the GDPR data protection requirements and the NIS2 IT security obligations. Professional consulting helps implement both areas in a coordinated way.

Showcase

This is what your NIS2-compliant online shop could look like:

B2B CommerceDemo

B2B Spare Parts Portal

B2BComplianceERP IntegrationSecurity
PharmacyDemo

Mail-Order Pharmacy

Regulated IndustryGDPRHostingMonitoring
IndustryDemo

Mechanical Engineering Company

E-CommerceNIS2EncryptionIncident Response