AwarenessCybersecurity BlogNIS 2: EU time bomb without a countdown – when it goes off, it hits us all

August 7, 2025

Imagine this: since January 2023, NIS 2 has been in force across the EU. Officially, the directive should have been transposed into national law by October 17, 2024. Now it’s August 2025, and Austria and Germany are still operating without a finalized law. What does that mean? When the explosion comes – and it will – it will hit you out of nowhere. Wait a minute … me?

The NIS-2 Directive was supposed to be implemented into national law by around October 17, 2024. So far, unsuccessfully: in many countries, including Austria and Germany, the implementation is still missing – infringement proceedings are already underway. And things are not expected to progress further until the end of 2025 or even 2026, depending on the political schedule.

Who is affected?

In Austria, around 4,000 companies across 18 sectors (including health, transport, energy, and digital infrastructure) are affected – as soon as they have more than 50 employees or an annual turnover exceeding €10 million. Or if they are part of the supply chain of such organizations!

Fines straight out of a horror movie

Violations can result in severe penalties:

  • For “essential entities” up to €10 million or 2% of global annual turnover, whichever is higher.
  • For “important entities” up to €7 million or 1.4% of turnover.
NIS 2: EU-Zeitbombe ohne Countdown – geht sie hoch, trifft sie uns alle

The supply chain as Achilles’ heel

Article 21 of the directive stipulates that companies must not only manage their own risks but also consider and document the security of their supply chain – including direct service providers and suppliers. So if you have a customer who is subject to NIS-2, you’re affected as well, even if you’re just a small company.

Management is personally liable

Managing directors must take action themselves and establish risk management. This means that while experts can be brought in for support, the responsibility always remains with the company itself – specifically, with its leadership.

The responsible management must personally ensure that:

  • information security is guaranteed within the company and resources are made available,
  • risks are identified, assessed, and managed,
  • managing directors and employees are regularly trained,
  • appropriate technical and organizational measures are implemented (e.g., firewalls, monitoring, emergency plans),
  • and everything is documented – in an auditable manner.

What happens in case of violations? The EU mandates that management can be held personally liable!

Why “just waiting” is a very bad strategy

Most companies are postponing the topic or believe it doesn’t concern them anyway. Do you remember the introduction of the GDPR? Boom – everything had to be ready at once. NIS 2 will be worse, and those who wait risk nasty surprises. Because:

  • When the national law finally comes, it will apply retroactively.
  • Affected companies will suddenly have to deliver risk analyses, reporting processes, contract clauses, and supplier audits.
  • This can lead to reputational damage, operational disruptions, or true audit horror scenarios.

Helpful tips – what to do now

To avoid flying blind through compliance, the following steps are essential:

  • Create a supplier register – including IT freelancers and small service providers.
  • Update contracts – with clauses for risk management, audits, certificates, and security ratings.
  • Define standards – such as ISO 27001, BSI Baseline Protection, KSÖ rating, audit systems.
  • Establish regular review and documentation – prove risk analysis and audits for each supplier.
  • Ensure information security within the company – with responsibilities, selection criteria, procedural descriptions, and monitoring – as required in Article 21.

Sounds like a lot of work? Then it makes sense to get help now – from cybersecurity experts (especially if you are NIS-obligated) – and secure the right tools. For documenting your supply chain and your own baseline work, NisFix is the ideal solution.

The solution: NisFix – compliance without headaches

The cybersecurity experts at secinto, , with over 20 years of experience, are developing a tool that handles the groundwork for you (as an NIS-2-obligated company) and consolidates your supply chain’s NIS 2 compliance in one dashboard:

  • Invite suppliers – and they can start right away.
  • They are guided step by step through the compliance process (both administrative and technical) – with templates, risk assessments, and to-do lists.
  • At the end, one click is enough – you’re audit-ready in this area.

You’re ONLY a supplier to an NIS-2-obligated company? Good news for you too:

  • You can proactively use NisFix and simply share it with your customers.
  • NisFix guides you through the process with templates, technical checks including to-do lists for fixes, and training materials.
  • As a supplier, you receive a digital NisFix certificate that you can use centrally – saving you from repetitive compliance efforts.

Summary

NIS 2 is here – but the countdown is running silently, without an official deadline. Companies must prepare on their own to avoid chaos once the law is passed. Particularly risky: the supply chain. Those who act in time protect themselves from fines, liability, and traumatic audits.

And so you don’t collapse under the NIS 2 shock: CheckFix and soon NisFix will help you navigate the process in a structured and legally compliant way.

Sources

EUR-Lex – Directive (EU) 2022/2555 (NIS-2) – Official full text of the NIS-2 Directive, including Articles 20 (Management) & 21 (Risk Management)
https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX%3A32022L2555
Article 20 NIS-2 – Responsibility of management bodies – liability of management, approval and oversight of security measures, training obligation
https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX%3A32022L2555#d1e5596-1-1
Article 21 NIS-2 – Cybersecurity risk management measures – obligation for risk analysis, incident response, supply chain security, monitoring, etc.
https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX%3A32022L2555#d1e5682-1-1
NISG Austria information portal (onlinesicherheit.gv.at) – NIS-2 affects around 4,000 companies in 18 sectors in Austria
https://www.onlinesicherheit.gv.at/Services/News/NIS-2-Richtlinie-Ueberblick.html
Austrian Chamber of Commerce (WKO) – Explanation of affected sectors and companies, current legal implementation status in Austria
https://www.wko.at/it-sicherheit/nis2-uebersicht

Contact

E-mail: office@checkfix.io

Phone: +43 660 77 24 524

secinto

secinto GmbH

Poststraße 3

8530 Deutschlandsberg

Austria

E-mail: office@checkfix.com

*Studie KPMG zur Cybersecurity in Österreich 2023