Headcount is not the only factor
Sector, specific activity, entity type and group or special rules all influence the assessment.
- Sector and activity
- Size thresholds
- Special and exemption rules
NIS2 & compliance
TM-Connect helps organisations structure their potential NIS2 relevance, clarify responsibilities and prepare the next organisational and technical steps.
Current position
The German NIS2 implementation act entered into force on 6 December 2025. The revised BSI Act distinguishes particularly important and important entities and links classification to factors such as sector, activity, size and special rules.
Sector, specific activity, entity type and group or special rules all influence the assessment.
Risk management, reporting, registration, supply chain, training and documentation need to be considered as one system.
The BSI Act assigns implementation, monitoring and training duties to management. Qualified legal advice remains necessary for individual legal assessment.
Scope orientation
These questions create a structured basis for discussion. They do not produce an automatic legal determination.
Review the sectors and entity types in Annexes 1 and 2 of the BSI Act as well as possible special categories.
The legally defined activity, not just the industry label, is relevant to classification.
Employee numbers, annual turnover and balance-sheet totals are combined differently depending on the entity type.
Group aggregation follows specific rules and may require individual assessment.
Telecommunications, trust services, public administration and DORA-related entities may be treated differently.
Even organisations outside the formal scope may receive security, evidence and incident-communication requirements from customers.
This orientation does not replace individual legal review. A reliable classification requires the current legal text, the specific activity and the organisational structure to be assessed together.
Organisation
NIS2 is not a single IT product. It requires a traceable combination of governance, processes, technology and documentation.
Define decision paths, roles, escalation and reporting lines.
Identify, assess and treat risks to network and information systems systematically.
Plan safeguards proportionate to risk, size, state of the art and implementation effort.
Prepare detection, internal escalation, external reporting, recovery and crisis communication.
Document dependencies, providers and security requirements across the supply chain.
Keep decisions, measures, effectiveness checks and regular training auditable.
Establish security as a reviewable operating process rather than a one-off project.
Approach
Every phase clarifies who is involved, what happens and which result supports the next decision.
The organisation, activities, sites and open classification questions are bounded.
Systems, services, responsibilities, providers and existing security processes are captured.
The documented current state is compared with relevant requirements and risks.
Organisational and technical measures are ordered by impact, urgency, dependency and effort.
Internal teams, specialist providers and suitable security and connectivity solutions are coordinated.
Evidence, effectiveness checks, training, reporting paths and recurring reviews move into operations.
TM-Connect
The service framework connects orientation, project structure and technical infrastructure. Legal advice and compliance guarantees are expressly excluded.
We bring systems, responsibilities, dependencies and open questions into one shared landscape.
We structure work packages, support the selection of suitable solutions and coordinate implementation partners.
Network security, endpoints, sites, resilience and communications are treated as connected infrastructure topics.
We support decisions, implementation and subsequent development steps in a personal and understandable way.
Solution fields
Suitable solutions depend on risk, existing infrastructure, the operating model and the confirmed service scope. No single product creates NIS2 compliance.
Assess access, segmentation, traffic and safeguards in the context of the infrastructure.
Include devices, identities, patching and secure mobile use in the protection model.
Connect distributed sites securely, controllably and with transparent dependencies.
Plan backups, restoration, redundancy and emergency procedures as one process.
Review identities, permissions, configuration, data and recovery systematically.
Select operating and monitoring models only after availability and scope have been confirmed.
Governance
Section 38 of the German BSI Act requires management bodies of particularly important and important entities to implement and monitor risk-management measures; regular training is also required. The individual legal effect needs qualified legal assessment. In practice, management needs reliable reporting, documented decisions and a clear view of material risks and measures.
Sectors
Healthcare organisations need to consider regulatory, technical and operational dependencies together.
Multiple facilities, mobile work and providers require clear ownership and practical reporting and recovery paths.
The first task is often to make responsibilities, suppliers and priority risks visible across sites.
Administration, technical infrastructure and external partners form a delivery chain with different protection needs.
Even outside formal classification, customers or sponsors may expect robust security evidence.
Trust
TM-Connect combines security and compliance orientation with experience in telecommunications and digital infrastructure. Vendor relationships are stated factually while TM-Connect remains clearly identifiable as an independent consulting and implementation company.
These approved statements describe partner relationships. They do not imply exclusivity, certification, a mandate or a compliance guarantee.
Questions & answers
No. Classification depends on entity type, activity, sector, size and special or group rules. Individual review remains necessary.
The German NIS2 implementation act entered into force on 6 December 2025. Decisions should always use the current legal text.
The BSI Act classifies entities through statutory categories and thresholds, which lead to different supervisory and sanction frameworks.
Depending on the category, employee numbers, annual turnover and balance-sheet totals are considered. Some entity types are covered independently or under different thresholds.
Section 30 lists proportionate technical and organisational risk-management measures, including risk analysis, incident handling, continuity, supply-chain security, effectiveness review, training, cryptography and access security.
Section 32 generally provides for an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. Details and the start of the obligation need current review.
In-scope entities have registration duties. The BSI provides its portal for this purpose; deadlines and special routes depend on entity type.
The BSI Act assigns implementation, monitoring and training duties to management. Individual liability and legal effects require legal advice.
No. NIS2 covers governance, processes, people, supply chains, documentation and technology. Individual products can only be elements of a proportionate measures package.
No. TM-Connect supports orientation, project structure, technical assessment and implementation. Legal classification and legal questions require qualified counsel.
A scoped initial discussion covering activity, size, sites, systems, responsibilities and open questions provides a practical basis for further assessment.
Related solutions
Initial consultation
In the initial consultation we clarify your situation, open classification questions and the most useful next work step. The consultation is not legal advice.