Cybervize
NIS-2 for energy providers

Energy is Annex I. A sector of high criticality.

The sector covers electricity, district heating, oil, gas and hydrogen. How strict the obligations become depends on company size. For KRITIS operators, the German threshold regulation and BSIG obligations also apply. Our vCISO leads the implementation of the information security obligations and works with OdySecure, the security platform by Cybervize.

Book the NIS-2 risk check

NIS-2 classification: energy

Classification
Annex 1 to the German BSIG ("Anlage 1")
Wichtige Einrichtung
from 50 employees, or annual turnover and annual balance sheet total each above €10M
Besonders wichtige Einrichtung
from 250 employees, or annual turnover above €50M and balance sheet total above €43M
Exception
can apply to EnWG-regulated activities (§ 28 Abs. 5 BSIG), see the note below
Reporting deadlines
initial report 24 hours, follow-up 72 hours, final report one month
Obligations
10 minimum measures under § 30 BSIG
On top
German KRITIS regulation from installation thresholds

Standard case under § 28 of the German BSIG. "Wichtige Einrichtung" is the standard tier, "besonders wichtige Einrichtung" the stricter tier; the figures are annual values. Calculating them in annual work units, attributing partner and linked enterprises, special cases and the final classification under German law all require a case-by-case legal review. The reporting deadlines require a significant incident (§ 32 BSIG). The exception: §§ 30, 31, 32, 35, 36, 38, 39, 61 and 62 BSIG do not apply to energy supply networks, energy installations and digital energy services subject to §§ 5c to 5e of the EnWG, the German energy industry act, and only for those activities; where operating an energy installation is a mere ancillary activity, the exception does not apply.

Cybervize building blocks for energy providers

Your vCISO works with OdySecure: ISMS, BCM, Assessment and supplier risk on one data foundation. Especially relevant for energy providers: control systems under IEC 62443 and the IT security catalogue energy.

Self-check available

NIS-2 maturity check: 30 questions, 10 §30 BSIG measures, instant traffic light

Free, no signup, around 5 minutes. Detailed evaluation by email if desired.

Start the check
More about NIS-2 for energy providers

What NIS-2 means in practice for energy providers

The KRITIS regulation also typically applies once asset-related thresholds are exceeded. Four consequences of this classification for a typical energy provider. Sector alone is not enough: KRITIS status and NIS-2 classification depend on size thresholds and concrete supply scope as well. The legally binding evaluation remains a matter for counsel.

01

The stricter tier from 250 employees: proactive supervision

From 250 employees, or at annual turnover above €50M and annual balance sheet total above €43M, an Anlage-1 entity is in the stricter tier: highest sanction level, active BSI supervision, faster intervention rights. Operators of critical installations reach it regardless of size. On findings, the BSI does not just send a notice; it arrives on site.

02

KRITIS regulation as a second layer

Whoever exceeds KRITIS thresholds (e.g. 500,000 supplied persons for electricity) becomes a KRITIS operator as well. Obligations overlap but are not identical. NIS-2 is broader in sector scope, KRITIS is deeper on plant requirements.

03

Reporting duties: § 32 BSIG or § 5d EnWG

For a significant incident, the staggered reporting under § 32 BSIG applies: initial report 24 hours, follow-up 72 hours, final report within one month, plus potential customer notification obligations. For EnWG-regulated activities under the § 28 Abs. 5 BSIG exception, § 5d EnWG applies instead: reports also go to the reporting office under § 32 BSIG, and the BSI takes measures in consultation with the Bundesnetzagentur, the German federal network agency.

04

OT focus: control rooms, SCADA, smart grid

Operational technology is the dominant attack surface in the energy sector. Control rooms, SCADA connections, smart-meter-gateway infrastructure and maintenance access need segmented architecture and continuous monitoring.

What applies in the energy sector, and what sits in the catalogue

Few sectors carry as many parallel rulebooks. Grid operation, metering and the protection of critical assets each follow their own system. In OdySecure they sit in one catalogue instead of separate evidence trails.

  • ISO/IEC 27001The shared language of the management system.123 records, reference
  • BSI IT-GrundschutzModules and methodology of the BSI, where the German approach is used.74 modules, BSI methodology
  • IEC 62443Security of control systems: zones, conduits and security levels per asset.37 records, reference
  • KRITIS umbrella actPhysical resilience of critical assets. Cybersecurity is governed alongside it by the BSIG.16 records, full catalogue
  • IT security catalogue energyRequirements of the federal network agency for grid operators.15 records, full catalogue
  • Metering Point Operation ActSmart meter gateway and metering operation.13 records, full catalogue
  • ISO/IEC 27019Information security specifically for energy supply.12 records, reference
  • CER DirectiveResilience of critical entities, beyond IT.14 records, full catalogue

NIS-2 is added where the thresholds of § 28 BSIG apply. That classification is set out below.

Full catalogue with depth and type of assurance

Five NIS-2 minimum measures with energy examples

Five of the ten minimum measures per §30, translated into energy practice.

01

Risk analysis and information system security

OT and IT risks assessed jointly, covering smart grid connections, control rooms and generation assets. Smart metering and market communication form a risk area of their own.

02

Cryptography and encryption

BSI-compliant crypto concepts for smart-meter gateways, control communication and remote-maintenance tunnels. Key management central and audit-ready.

03

Security in procurement and maintenance

Supplier audits for SCADA vendors and maintenance service providers. Remote-maintenance access documented, patch management for controllers aligned with maintenance windows.

04

Multi-factor authentication and access control

MFA for control-room access, privileged accounts separated, role model for OT distinct from office IT RBAC. Emergency access documented.

05

Business continuity and crisis management

BCM plans for generation outages, grid restoration exercises, black-start capability. Plus crisis communication to regulators and end customers.

Why Cybervize fits the energy sector

Methodology built for audit-ready evidence towards the BSI. Reference: support with the introduction of NIS-2 in the energy sector.

KRITIS
BSIG and KRITIS regulation coverage
OT
SCADA, control-room, smart-grid experience
50
frameworks held as a catalogue
24/72h
BSI reporting paths documented

Frequently asked questions from the energy sector

Most likely yes, if you operate in the energy subgroups (electricity, district heating, oil, gas, hydrogen) and have at least 50 employees, or annual turnover and balance sheet total each above 10 million euros. That makes you an important entity (wichtige Einrichtung). You are an essential entity (besonders wichtige Einrichtung) from 250 employees, or with annual turnover above 50 million euros and a balance sheet total above 43 million euros. NIS-2 is not built on KRITIS thresholds but on company size and sector membership. The legally binding evaluation remains a matter for counsel. We provide the expert classification in the risk check.

NIS-2 is sector-broad (different energy subgroups), KRITIS is plant-oriented (e.g. supply assets above certain thresholds). KRITIS operators are usually also NIS-2-affected. NIS-2-affected entities are not automatically KRITIS. The obligations overlap but differ in detail. In OdySecure, the KRITIS umbrella act and the IT security catalogue energy sit in the same catalogue as the NIS-2 obligations.

Yes, smart-meter gateways are also subject to § 22 of the German metering law (MsbG), read together with the BSI protection profiles and technical guidelines. That is a separate regulatory layer alongside NIS-2 and KRITIS. In the NIS-2 context, smart-meter infrastructure is part of the risk analysis and needs documented crypto concepts.

On a cybersecurity incident, the legal basis of the report depends on the type of entity. Operators of energy supply networks and installations under § 5c EnWG report significant incidents under § 5d EnWG to the reporting office under § 32 BSIG; the BSI takes measures in consultation with the Bundesnetzagentur and forwards relevant findings to it. § 28 (5) BSIG exempts those activities from the BSIG reporting duties. For entities to which this exemption does not apply, the staggered reporting duty under § 32 BSIG applies: 24-hour initial report to the BSI, 72-hour follow-up, one-month final report. Depending on the incident, further reporting duties may arise, for example to the data-protection authority on a data breach; a reporting system should map these paths in a documented way.

NIS-2 makes supply chain security a minimum measure: Article 21(2) explicitly lists supply chain security and security in the acquisition, development and maintenance of network and information systems, including the relevant IT and OT systems; in Germany this is transposed via Section 30 of the BSI Act. For energy suppliers this concretely means: contracts with IT, OT and maintenance providers should contain security requirements, the provider’s duties to inform and report in case of incidents, audit rights, rules for subcontractors, and exit and reintegration provisions. For grid operators, the IT security catalogue of the Federal Network Agency applies on top. It is important to include existing contracts, not just new ones: a model clause alone does not yet evidence a documented, ongoing vendor process.

What holds up is what is documented and current: a register of providers with criticality rating, the associated contracts with their security-relevant clauses, verified provider evidence (such as ISO 27001 certificates), and a defined reporting chain for incidents at the provider. In OdySecure, the TPRM module carries this documentation: vendor assessment, a contract register with security-relevant mandatory fields, and the link between incidents, risks and the respective provider, so the evidence emerges from ongoing operations instead of a binder assembled before the audit date.

For providers with generation and network infrastructure, typically 12 to 16 weeks for audit-ready NIS-2 readiness, depending on OT complexity and KRITIS status. Multi-asset operators need 20 to 26 weeks. The exact cost estimate comes from the risk check.

Classify your NIS-2 and KRITIS position in 30 minutes

Free risk check with indicative NIS-2 classification, KRITIS threshold indicator, top-5 gaps and path recommendation. Ideally with CISO or IT security leadership plus management board present.

Book the NIS-2 risk check

In scope? How you get to a provable security posture

If the classification above fits your organisation, the first step is to establish where you stand. Once it is clear which obligations apply and where the gaps are, the question is who closes them: a vCISO working with OdySecure, or your own team with a platform licence.

Book a vCISO callSee the journey in five stations

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT