With the NIS2 directive, cybersecurity has shifted from a recommendation to a legal duty. In Germany, an estimated 29,500 entities now fall under the new requirements according to the Federal Office for Information Security (BSI) - and even shops below the size thresholds can be pulled into a duty of proof as suppliers to affected companies. The key point: the required measures - patch and backup management, multi-factor authentication, incident reporting and supply chain security - are not a one-off project but everyday operational maintenance. This guide translates the legal duties into a concrete action plan and shows how an SLA maintenance contract can cover and document these requirements on a lasting basis.
Key takeaways
- NIS2 is Directive (EU) 2022/2555, made binding in Germany through the BSI Act. It covers 18 sectors (Federal Government) and roughly 29,500 entities (BSI) instead of the previous 4,500 critical-infrastructure operators. Pure retail is not among the regulated sectors.
- Shops are directly covered mainly as operators of digital services: important entities from 50 employees or 10 million euros turnover, essential entities from 250 employees or 50 million euros (European Commission). Registration with the BSI is mandatory.
- The catalogue lists at least ten risk management measures (Federal Government): risk analysis, vulnerability and patch management, tested backups, multi-factor authentication, access control, supply chain assessment, effectiveness reviews and documentation.
- Significant incidents are reported in three stages: an early warning within 24 hours, a follow-up report within 72 hours and a final report within one month (BSI). The clock starts when the incident becomes known, not when the analysis is finished.
- Through the supply chain duty, the requirements also reach shops below the size thresholds: regulated companies must assess the security of their providers and suppliers (European Commission) and therefore ask for questionnaires and evidence of ongoing maintenance.
- Fines run up to 10 million euros or 2 percent of worldwide annual turnover, and up to 7 million euros or 1.4 percent for important entities (Federal Government). Management must approve and supervise the measures; a one-off implementation does not suffice.
What NIS2 Is and Why It Affects Shops
NIS2 is the European Union's second directive on network and information security, officially Directive (EU) 2022/2555. Member States had to transpose it into national law by 17 October 2024 (European Commission). In Germany this happens through the NIS2 Implementation and Cybersecurity Strengthening Act, which anchors the requirements in the BSI Act. It covers 18 sectors of high and other criticality (Federal Government), from energy and transport through health and digital infrastructure to manufacturing, chemicals and food. As a result, the circle of regulated entities grows from around 4,500 critical-infrastructure operators to roughly 29,500 - an increase of more than sixfold (BSI).
The reason for this tightening is a real and growing threat landscape. The total damage from analogue and digital attacks on the German economy recently reached 289.2 billion euros per year (Bitkom, Economic Protection 2025); cyber attacks alone accounted for 202.4 billion euros of that, around 70 percent of the total (Bitkom, Economic Protection 2025). Ransomware, where data is encrypted and only released against payment, affected 34 percent of companies (Bitkom, Economic Protection 2025). For an online shop whose revenue depends directly on the availability and integrity of its systems, this is precisely the situation NIS2 responds to.
Directive, law and supervision
Is My Online Shop Directly Affected?
Plain retail is not among the 18 regulated sectors. Shops are directly affected, however, when they also run a service that falls under digital infrastructure or digital services - for instance as the operator of an online marketplace, a search engine or a cloud offering. Whether an entity is covered also depends on its size: as a rule of thumb, medium-sized companies from 50 employees or more than 10 million euros in annual turnover, and large companies from 250 employees or more than 50 million euros in turnover, are in scope (European Commission). The law then distinguishes between essential and important entities.
| Criterion | Essential entities | Important entities |
|---|---|---|
| Size | from 250 employees or over 50m euros turnover (European Commission) | from 50 employees or over 10m euros turnover (European Commission) |
| Typical examples | large operators in highly critical sectors | medium-sized companies in the regulated sectors |
| Supervision by the BSI | more proactive oversight | oversight on specific cause |
| Registration with the BSI | mandatory | mandatory |
| Fine range | up to 10m euros or 2% of worldwide annual turnover (Federal Government) | up to 7m euros or 1.4% of worldwide annual turnover (Federal Government) |
Below the thresholds too: suppliers face a duty of proof
The Ten Mandatory Measures: Law Meets Maintenance
At the heart of NIS2 is a catalogue of at least ten risk management measures that affected entities must implement (Federal Government). It ranges from risk analysis through incident handling, business continuity and supply chain security to cryptography, access control and multi-factor authentication. Read from an operational angle, one thing stands out immediately: almost every one of these requirements describes an activity that belongs in the ongoing maintenance of an online shop anyway.
Patch and vulnerability management
Secure acquisition, development and maintenance means known security gaps are closed promptly. That is classic update and patch management as part of daily operations.
Backup and business continuity
Maintaining operations requires data backups, backup management and verified recovery - a fixed component of any maintenance routine.
Multi-factor authentication
MFA and secured communications protect access to the shop back end, the server and connected services against compromised credentials.
Supply chain security
Supply chain security concerns extensions, themes, libraries and external service providers, all of which must be assessed regularly.
Assessing effectiveness
Procedures for assessing effectiveness require testing after changes and a regular check of whether the measures actually work.
Risk analysis and documentation
Risk analysis, IT security concepts and traceable evidence form the basis - and must be maintained and kept up to date.
The difference lies in continuity
Patch and Backup Management as a Standing Duty
The proximity of law and maintenance is clearest in how vulnerabilities are handled. NIS2 requires security in acquisition, development and maintenance including vulnerability management - in shop terms, that means security updates for the shop system, its extensions and the underlying server environment are applied and tested promptly. An orderly CVE and patch management is therefore not optional but the operational fulfilment of a legal requirement. Without a fixed rhythm, known gaps stay open, and those are exactly the ones most often exploited.
Equally concrete is the duty to maintain operations. It covers data backups, crisis management and the ability to become operational again quickly after an incident. In practice that means regular, tested backups and a well-considered recovery concept - topics we cover in detail in our article on backup strategies for online shops and which are firmly anchored in the backup service. An unverified backup fulfils the requirement only on paper.
Documentation is part of the duty
Multi-Factor Authentication and Access Control
A separate point in the catalogue is multi-factor authentication, complemented by access control, personnel security and asset management. For a shop that means access to the back end, the server and connected services should no longer be protected by a password alone. Compromised credentials are a common entry point for attacks; a second factor reduces that risk considerably. In addition, rights should be granted sparingly, departed accounts deactivated and an overview of the systems in use maintained.
- Enable multi-factor authentication for the shop back end, server and administrative services
- Grant access rights on a least-privilege basis and review them regularly
- Deactivate departed accounts and unused access promptly
- Inventory the systems, extensions and services in use (asset management)
- Encrypt administrative access and communication paths
- Document changes to roles and rights traceably
The Reporting Duty: 24, 72 and One Month
Alongside the technical measures, NIS2 introduces a staged reporting duty. Essential and important entities must report significant security incidents to the BSI - in three steps. The first report, the early warning, must be made within 24 hours (BSI). It is followed by a follow-up report within 72 hours (BSI) and finally a final report within one month (BSI). Importantly, the deadlines run from becoming aware of the incident, not from completing the analysis - speed comes before completeness here.
| Stage | Deadline from awareness | Content of the report |
|---|---|---|
| Early warning | within 24 hours (BSI) | first report on whether a significant incident exists and whether unlawful action is suspected |
| Follow-up report | within 72 hours (BSI) | assessment of the incident with severity, impact and initial findings |
| Final report | within one month (BSI) | full description, cause, impact and the countermeasures taken |
24 hours are hard to keep without preparation
Supply Chain Security: Small Shops in Scope Too
Perhaps the most consequential point for smaller shops is supply chain security. NIS2 obliges affected companies to consider the security of their direct suppliers and service providers and to secure it contractually (European Commission). In practice that means: a regulated company must demand a demonstrable security status from its service providers - including the agency that runs its shop or the supplier connected via an interface.
For shops and service providers below the thresholds, this concretely means: security questionnaires, contractual requirements and evidence of maintenance and updates increasingly become a precondition for being considered as a partner. A documented, continuously maintained security status is therefore no longer just a technical question but a tangible selling point towards regulated customers. Those who are prepared here set themselves apart from competitors who cannot provide the evidence.
The supply chain duty acts like a multiplier: it passes the security requirements from the regulated companies on to their service providers - and turns a demonstrable maintenance status into a door opener.
Fines and the Responsibility of Management
NIS2 backs up its requirements with tangible sanctions. For essential entities, fines of up to 10 million euros or 2 percent of worldwide annual turnover are provided for; for important entities up to 7 million euros or 1.4 percent of worldwide annual turnover (Federal Government). On top of that comes a special responsibility for management: it must approve the risk management measures, oversee their implementation and can be held accountable for failures. Cybersecurity thus becomes explicitly a matter for the top.
Do not forget registration
From Legal Text to an Action Plan in the Maintenance Contract
The decisive insight from all this is that NIS2 does not demand entirely new activities but makes familiar maintenance tasks binding, lasting and demonstrable. An SLA maintenance contract is the tool that performs this translation: it bundles patch management, backups, monitoring, hardening and access control into fixed, recurring services, defines response times and documents every step. Individual paragraphs thus become plannable tasks with clear responsibilities - a principle that runs through all of our maintenance services.
Defined response times
The SLA sets out how quickly security alerts and disruptions are handled - the basis for being able to meet the 24-hour reporting deadline at all.
Planned patch management
Security updates are applied and tested in fixed cycles and after critical releases as security updates.
Backups and recovery
Regular backups with verified recovery fulfil the duty to maintain operations in an emergency.
Ongoing monitoring
Availability, certificates and anomalies are monitored so that incidents are noticed early and can be reported on time.
Demonstrable documentation
Every measure and change is logged - the basis for reports, audits and the evidence along the supply chain.
Hardening and access
Server hardening, multi-factor authentication and access controls are set up and maintained on a fixed rhythm.
- Map all ten mandatory measures from the catalogue onto fixed maintenance services
- Move patch, backup and access management into recurring, tested cycles
- Define a response and reporting process with clear deadlines and responsibilities
- Document the security status and changes continuously and traceably
- Assess extensions, libraries and service providers for security regularly
- Update the action plan after every major change
Seen this way, NIS2 is less a threat than an occasion to put the operation of a shop on a sound footing. The required hardening and safeguarding fit seamlessly into existing building blocks - from server hardening for shops through consistent HTTP security headers and a CSP to maintenance windows without lost revenue and the legally sound retention of backups. A shop that meets and documents these points on an ongoing basis is not only better protected against attacks but also robustly positioned as a partner to regulated companies.
Sources and studies