Resources

Blog

Blind in a Crisis: Why NIS2 Now Makes IT Transparency Mandatory

Since December 2025, Germany's NIS2 implementation act makes IT transparency a legal duty for roughly 29,500 companies — with personal liability for management. What this means in practice and how to get started.

Irini GaravelaSeptember 20265 min read

Cyberattacks on German companies have reached a record level. According to the Bitkom study "Wirtschaftsschutz 2025," 87 percent of companies in Germany were affected by data theft, espionage, or sabotage within twelve months, with total economic damage of €289.2 billion. According to IBM, it takes an average of 241 days to identify and contain a security incident.

Since December 6, 2025, a second dimension has been added: Germany's NIS2 implementation act (NIS2UmsuCG) makes IT transparency a legal duty for roughly 29,500 companies — those with 50 or more employees or €10 million or more in annual revenue in one of 18 covered sectors. With no transition period.

The blind spot nobody wants to see

A company that doesn't know which IT systems are running can neither protect nor defend them. That is exactly the situation in practice: legacy systems, decentralized procurement, and the constant switching between spreadsheets, ticketing systems, and the knowledge held by individual employees mean that no one in the organization can reliably answer which applications, services, and interfaces are actually in use.

What NIS2 actually requires

The law does not mandate a standalone "application inventory" as an isolated obligation. But the required measures are practically impossible to fulfill without one:

  • BSI registration: grace period until July 31, 2026.
  • Section 30 NIS2UmsuCG: risk analysis, security concepts, and incident handling — all of which require knowledge of your own IT landscape.
  • Section 32 NIS2UmsuCG: staged reporting — initial notification within 24 hours, detailed report within 72 hours, final report within one month.
  • Section 38 NIS2UmsuCG: personal liability of management for adequate risk management.
  • Section 65 NIS2UmsuCG: fines of up to €10 million or 2 percent of global annual revenue.

If you don't know which systems exist in your company, you cannot run a risk analysis on them, and you cannot report within 24 hours exactly what was affected.

What happens in a crisis without an overview

Without a current application overview, the same chain reaction typically unfolds: reporting deadlines are missed because nobody can quickly identify which systems and data are affected. Containing an attack is delayed because interfaces and data flows aren't documented. And afterward, there's no evidence of the security measures that were in place — with fine risk and personal liability for management under Section 38.

Five steps companies can start on now

  1. Start a complete inventory of all applications — including shadow IT.
  2. Check your NIS2 exposure and complete a missing BSI registration (grace period until July 31, 2026).
  3. Document risk management under Section 30 and link it to your IT inventory.
  4. Test your reporting process realistically: could you meet the 24/72-hour deadlines today?
  5. Replace static spreadsheet inventories with a continuously current platform.

Read the full analysis

The complete analysis — with full source references, the complete NIS2 obligations checklist, and detailed recommendations — is available as a free white paper: Download "Blind in a Crisis?" as a PDF

How knooing helps

knooing is an AI-native IT management platform that automates exactly this kind of transparency — instead of spreadsheets and tribal knowledge. A central, AI-supported registry of all applications, services, contracts, and licenses delivers, in minutes rather than days, the answer to "which systems, data, and contracts are affected?" — the basis for timely reporting, effective containment, and evidence for BSI, customers, and insurers.

Sources

This article provides a general overview and does not constitute individual legal advice.

More articles

You might also like.

Blog

Stopping IT sprawl: strategies against shadow IT and redundant software, and how companies stay in control

8 min read

Read

Blog

EU AI Act: What Companies Need to Know About the Transparency Obligation Now

4 min read

Read

Blog

Was Ihre IT wirklich kostet: IT-Kosten ehrlich auf Geschäftsbereiche zuordnen — ohne Excel-Marathon

8 min read

Read

Make data-driven IT decisions in minutes, starting today.

Schedule a free, no-obligation demo