NIS2 and Access Control: Requirements and Checklist for Affected Companies

NIS2 and Access Control

 
     NIS2 and Access Control
Here’s what it’s all about:

  • Whether a company is affected depends on the type of organization, the sector
    , and the statutory size thresholds—not solely on the number of employees
    or revenue.
  • Suppliers may also be indirectly affected if customers impose NIS2 requirements on their supply chain.
  • Access control alone does not make a company NIS2-compliant, but it is an important component of a comprehensive risk management strategy.

 

NIS2 affects numerous medium-sized and large companies in critical and particularly relevant sectors, including energy, healthcare, transportation, digital infrastructure, and parts of the manufacturing industry. In Germany, the requirements have been in effect since December 6, 2025, under the new BSI Act. The required risk management measures also include access control, personnel security, and the protection of critical systems. Digital access control can make a significant contribution in this regard. Here: Access control by ZMI.

🚨 NIS2 has been mandatory in Germany since December 2025

The European NIS2 Directive significantly expands the scope of regulated entities. In Germany, it was implemented through the new BSI Act. This law took effect on December 6, 2025, and distinguishes, in particular, between critical infrastructure entities and important infrastructure entities.

Companies must verify for themselves whether they meet the legal requirements. A specific request from the authorities is generally not required. Instead, affected organizations must register through the BSI portal and report significant security incidents via the designated reporting channels.

For small and medium-sized enterprises, NIS2 is relevant not only because of the direct regulatory requirements. Even companies that do not themselves fall into any statutory category may be indirectly affected through customer contracts, audits, and security requirements within the supply chain.

🧐 Impact Check: Which companies are subject to NIS2?

The extent of the impact cannot be determined solely by the number of employees. The key factor is the combination of:

🤝 the specific type of facility

🤝 the corresponding sector

🤝 Company size

🤝 Possible special provisions

Step 1: Does the company fall under a recognized type of institution?

The BSI Act contains two appendices listing the sectors, industries, and types of facilities covered. It is not sufficient for a company to operate generally in a sector such as “manufacturing” or “energy.” What matters is whether its specific activities correspond to a type of facility defined by law.

Category: Other Critical Issues

Typical examples: Companies whose primary business is waste management

Category: Highly Critical

Typical examples: Operators of wastewater treatment facilities

Category: Highly Critical

Typical examples: Financial institutions

Category: Other Critical Issues

Typical examples: Manufacturers and importers of certain chemical substances and mixtures

Category: Other Critical Issues

Typical examples: online marketplaces , search engines, social networks

Category: Highly Critical

Typical examples: data centers , cloud services, DNS services, telecommunications networks

Category: Highly Critical

Typical examples: electricity suppliers , grid operators, energy producers, district heating providers

Category: Highly Critical

Typical examples: trading venues , central counterparties

Category: Other Critical Issues

Typical examples: designated research institutions

Category: Highly Critical

Typical examples: hospitals , laboratories, certain pharmaceutical and medical device companies

Category: Other Critical Issues

Typical examples: certain manufacturers, processors, and wholesalers

Category: High-Risk

Typical examples: in particular , federal government agencies

Category: Other Critical Issues

Typical examples: Postal service providers and courier services

Category: Highly Critical or, in some cases, Other Critical

Typical examples: air transport , rail transport, shipping, road transport, postal and courier services

Category: Highly Critical

Typical examples: Water utilities

Category: Other Critical Issues

Typical examples: selected manufacturers, such as those in the mechanical engineering, automotive, or electronics industries

Category: Highly Critical

Typical examples: Operators of ground-based infrastructure for space-based services

👉 The table is intended only as a general guide. A reliable classification always requires a review of the specific type of facility as defined in Annexes 1 and 2 of the BSI Act.

Step 2: Are the size thresholds exceeded?

A registered organization as defined in Appendix 1 is generally considered a particularly important entity if it:

✅ employs at least 250 employees, or

✅ Achieved annual revenue of more than 50 million euros and, at the same time, total assets of more than 43 million euros

An organization listed in Appendix 1 or 2 is generally considered a key institution if it:

✅ employs at least 50 employees, or

✅ Achieved annual revenue of more than 10 million euros and, at the same time, total annual assets of more than 10 million euros

The often oversimplified statement “NIS2 applies to companies with ten million euros or more in revenue” is therefore inaccurate. When determining the financial threshold, both revenue and total assets must generally be taken into account.

👉 Different rules may apply in some cases to telecommunications providers, trust service providers, DNS services, and top-level domain registries. Certain types of organizations fall within the scope of these rules regardless of the usual thresholds, or even when the company is smaller.

Step 3: Is there an indirect impact via the supply chain?

A supplier does not automatically become a critical or highly critical infrastructure entity simply because its customer is subject to NIS2.

However, affected companies must explicitly take into account the security of their supply chain and security-related aspects of their collaboration with direct suppliers and service providers. For this reason, NIS2 requirements are increasingly being incorporated into contracts, supplier audits, and information security questionnaires.

🚨 For medium-sized suppliers, this can result in a de facto obligation: Those who cannot demonstrate adequate security measures risk losing orders or having important contracts not renewed.

🤔 What does NIS2 require in terms of physical security and access control?

NIS2 is not merely a set of rules governing firewalls or cybersecurity. The BSI Act requires a cross-threat approach to protect the availability, integrity, and confidentiality of the IT systems, components, and processes in use.

The explicitly mentioned risk management measures include policies for personnel security, access control, and the management of ICT systems. Access control should not be understood exclusively in physical terms. It also encompasses logical access to applications, systems, and data. However, physical access controls become relevant as soon as unauthorized access to premises could jeopardize the protected IT systems.

Traceable access logs

In safety-critical areas, the following should be traceable:

🔵 Which person entered an area

🔵 When entry occurred

🔵 Which account was used

🔵 whether an access attempt was denied

These logs support both the prevention and the subsequent reconstruction of a security incident. The retention period and access to the logs must be justified and limited in accordance with data protection laws.

Role-Based Access Rights

Blanket access permissions based on the principle that “all employees have access everywhere” are hardly compatible with a risk-based security approach. Access rights should be determined by job function, area of responsibility, work location, and actual need. Examples include:

🔵 IT administrators are granted access to the server room

🔵 Production employees may only enter designated production areas

🔵 External technicians are granted temporary access permissions

🔵 Employees who have left the company are immediately blocked

🔵 Protection of particularly critical areas

A higher level of protection is particularly advisable in the following areas:

🔵 Server and equipment rooms

🔵 Network Splitter

🔵 Control Rooms

🔵 Production Control Systems

🔵 Rooms with security and backup systems

🔵 Archives containing security-related documents

A mechanical key can restrict access, but it usually does not provide reliable evidence of who actually entered a room and when. Whether a digital system is necessary depends on the specific risk. For critical areas, it generally offers better control and audit trail capabilities.

Rapid Response to Security Incidents

If there is suspicion of compromised access cards, lost transponders, or unauthorized access, it must be possible to revoke access privileges at short notice. Digital systems allow for centralized revocation without having to replace entire locking systems.

However, access control alone does not make a company NIS2-compliant. It is one component of a comprehensive risk management strategy that includes, among other things, incident response, backup management, supply chain security, training, cryptography, and multi-factor authentication.

🆘 Reporting Requirements for Security Incidents

A significant security incident must generally be reported in several stages:

💥 Within 24 hours: initial report

💥 Within 72 hours: detailed incident report

💥 No later than one month after the incident is reported: a closure report or a progress report if the incident is still ongoing

The 24- and 72-hour time limits begin when the significant security incident is discovered.

Unauthorized access is not automatically reportable. However, it can trigger a significant security incident if, for example, it results in the tampering of production control systems, the shutdown of systems, the theft of data, or the disruption of essential services.

👉 In this case, analyzable access data helps reconstruct the sequence of events, identify the affected areas, and present the impact to the BSI in a transparent manner.

👔 Sanctions and Management Responsibility

Violations of risk management, documentation, or reporting requirements can result in substantial fines.

For particularly important organizations, the German BSI Act provides for fines of up to 10 million euros for certain violations. For companies with total global revenue exceeding 500 million euros, a fine of up to 2 percent of global annual revenue may be imposed instead.

For major organizations, fines for such violations can be as high as seven million euros. For companies with global annual revenue exceeding 500 million euros, fines can amount to up to 1.4 percent of annual revenue.

Management must implement the required risk management measures and monitor their implementation. In the event of culpable breaches of duty, management may be liable to its own organization in accordance with the applicable corporate law provisions. In addition, management is required to undergo regular training.

The BSI is generally the central supervisory authority for important and particularly important facilities in Germany.

✍️ Practical Implementation with Access Control Software

An access control system should do more than just open and close doors. The following functions are particularly important for a risk-based security strategy:

✅ Custom and role-based permissions

✅ Time-limited access rights

✅ Centralized blocking of lost identification cards

✅ Traceable logging

✅ Quick analysis of security incidents

✅ Documented changes to permissions

✅ Separation of particularly critical security areas

Combining access control and time tracking can also offer organizational benefits. Master data and permissions do not need to be maintained in separate systems. An employee’s hire, department transfer, or resignation can be processed in a consistent manner. Learn more.

👉 Access and working-time data must continue to be processed for specific purposes. Technical integration does not automatically justify every type of analysis. Role-based access controls and data deletion policies, as well as the involvement of data protection officers and, where applicable, the works council, remain necessary.

✅ Checklist: Is your company affected by NIS2?

1️⃣ Determine whether the specific activity corresponds to a type of facility listed in Annex 1 or 2 of the BSI Act

2️⃣ Determine the number of employees, annual revenue, and total assets based on the statutory criteria

3️⃣ Review special regulations for telecommunications, DNS, trust services, or critical infrastructure

4️⃣ Record the direct and indirect requirements of key customers and clients

5️⃣ Designate a person responsible for NIS2 and information security

6️⃣ Fully document risk management measures

7️⃣ Identify Critical Areas and Physical Access Risks

8️⃣ Assign access rights based on roles and review them regularly

9️⃣ Establish a reporting process for significant security incidents with 24- and 72-hour deadlines

🔟 Check registration requirements and reporting options on the BSI portal

🤓 Conclusion: Access Control as Part of a Comprehensive Security Strategy

NIS2 requires affected companies to implement a documented, risk-based security management system. In addition to traditional IT security, this also addresses the question of who has physical access to critical systems and areas.

Digital access control can manage access permissions in a traceable manner, make it possible to reconstruct security incidents, and simplify the process of providing evidence to customers, auditors, and regulatory authorities. However, it does not replace either the impact assessment or a comprehensive information security strategy.

Even small and medium-sized businesses that are not directly subject to regulation should assess what requirements their key customers will place on suppliers in the future. Particularly in the energy, healthcare, transportation, public administration, and industrial production sectors, information security is increasingly becoming a prerequisite for long-term business relationships.

💡FAQ: NIS2 and Access Control

When does NIS2 become mandatory in Germany?

The German NIS2 Implementation Act and the new BSI Act contained therein entered into force on December 6, 2025. The statutory registration, risk assessment, and reporting requirements are therefore already in effect.

Not automatically. However, they may be contractually obligated to implement security measures because regulated customers must secure their supply chain. This results in an indirect, economically significant impact.

That depends on the security requirements. NIS2 does not mandate a specific electronic locking system across the board. However, for server rooms or production control systems, a digital access control system may be required or at least appropriate because it allows for individual access rights, access restrictions, and traceable logs.

The categories differ primarily based on the type of institution and the size of the company. Institutions deemed particularly important are subject to more intensive oversight and, in some cases, higher fines. However, the basic obligations regarding risk management and incident reporting apply to both categories.

Yes, affected organizations must actively register through the BSI portal. Companies should not wait to be contacted individually by the BSI.

ISO 27001 provides a structured information security management system (ISMS) and can support many of the organizational foundations for NIS2. However, certification does not automatically replace the statutory impact assessment or the fulfillment of all obligations under the BSI Act.

Picture of Jonathan Martin

Jonathan Martin

Jonathan Martin is a managing partner at ZMI GmbH. For many years, he has been working in the fields of time tracking, HR software, access control, and the digitization of HR processes. In his articles, he provides practical insights into current developments, legal requirements, and digital solutions for businesses.

Note on the content
The information on this website has been compiled with care and to the best of our knowledge. They serve exclusively to provide general, non-binding information – including on legal topics. They are no substitute for individual legal advice. We assume no liability for the accuracy, completeness or timeliness of the content.