Direct Answer
GDPR (DSGVO) applies to every company that processes personal data. NIS2, implemented in Germany through the NIS2UmsuCG, applies only to companies above certain size and sector thresholds. The BSI acts both as the supervisory authority for NIS2 and as the publisher of frameworks like IT-Grundschutz, which are voluntary unless a contract demands them. Reading the three together is what saves time, because one set of controls (managed devices, patching, access control, backups, documentation) covers most of what all three ask for.
Key Takeaways
Start with GDPR's technical and organizational measures, because they are mandatory for you today and form the base layer NIS2 and IT-Grundschutz build on.
Fund the controls that satisfy several frameworks at once first: automated patching, MFA with role-based access, encrypted devices, tested backups.
Run a NIS2 scope check the moment you pass 50 employees or 10 million euros in turnover, and put it on the management agenda rather than the IT backlog.
Pick tooling that produces evidence automatically, so an audit or a customer security review becomes an export rather than a scramble.
Re-run your control checklist at every growth milestone instead of treating compliance as a finished project.
What do GDPR, NIS2, and BSI actually require from your company?
Think of them as layers rather than separate projects. GDPR is the floor for anyone handling personal data. NIS2 adds cybersecurity and reporting duties for specific sectors above specific size thresholds. BSI frameworks sit on top as practical guidance that helps you show your measures are appropriate.
GDPR (DSGVO): applies to every company processing personal data. Supervised by the data protection authority of your federal state. Fines reach up to 20 million euros or 4% of global annual turnover.
NIS2 via the NIS2UmsuCG: applies by sector combined with size. Supervised by the BSI. Requires risk management, registration, incident reporting, and active involvement from management.
BSI frameworks: IT-Grundschutz and the CyberRisikoCheck carry no sanctions of their own, but they give you a recognized yardstick for what good looks like.
The threat picture behind these rules is not abstract for smaller companies. According to the Federal Office for Information Security, around 80% of reported ransomware attacks in Germany targeted small and medium-sized enterprises, and 72% of the ransomware incidents recorded in 2024 involved data leaks (Federal Office for Information Security (BSI)). A leak is also a personal data breach, which is exactly where compliance and security stop being separate conversations.
GDPR (DSGVO): the baseline every company already has to meet
For IT operations, four GDPR obligations do most of the work. Article 32 requires technical and organizational measures appropriate to the risk, which is where encryption, access control, and tested backups live. Articles 33 and 34 set the 72-hour notification to your supervisory authority, plus direct notification of affected people in high-risk cases.
Article 28 requires a data processing agreement with every IT provider and SaaS tool that touches personal data, which also means knowing where your vendors host data. Article 30 requires a record of processing activities, the document auditors tend to ask for first.
One German specific catches growing teams by surprise: you need a data protection officer once at least 20 people regularly process personal data by automated means (§ 38 BDSG). If you want the operational detail, work through a GDPR IT compliance checklist before anyone asks you for evidence.
NIS2 and the NIS2UmsuCG: when it applies and what it means for management
The NIS2UmsuCG has been in force since December 6, 2025. NIS2 scope in Germany comes from two questions asked together: is your sector listed in the annexes of the BSIG, and do you pass the size threshold? The general threshold starts at 50 employees, or annual turnover and balance sheet total above 10 million euros. Some services, such as certain digital infrastructure providers, are covered regardless of size.
If you are in scope, three duties follow. You implement risk management measures according to the state of the art (§ 30 BSIG), you register with the BSI, and you report significant incidents on a fixed clock: early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month.
The part that changes boardroom behavior is § 38 BSIG. Management has to approve and monitor the measures and take part in regular training, and culpable breaches create liability toward the company under corporate law. Many teams first meet these controls through certification work, so it helps to understand how NIS2 and ISO 27001 relate before committing budget to either.
The BSI's role: regulator, advisor, and IT-Grundschutz publisher
The BSI wears two hats. It supervises NIS2 and runs the portal used for registration and incident reports, and it publishes practical security guidance that any company can pick up voluntarily.
IT-Grundschutz is the best known of those publications: a catalog of building blocks describing concrete safeguards for devices, networks, cloud services, and organizational processes. Companies use it voluntarily, to answer contractual demands, or as one way to argue that their measures match the state of the art. For smaller teams, the CyberRisikoCheck based on DIN SPEC 27076 gives a structured starting assessment aimed at companies with fewer than 50 employees.
Where do these frameworks overlap, and where do they differ?
Most of the technical ground is shared. Patching, access control with multi-factor authentication, encrypted devices, backups with tested restores, awareness training, and written documentation appear in all three in slightly different language.
The differences are narrower than people expect, and they are mostly procedural:
Only GDPR: data processing agreements, the record of processing activities, data subject rights, and data protection impact assessments.
Only NIS2: registration with the BSI, the 24-hour early warning, supply chain security duties, and documented management involvement.
Only IT-Grundschutz: the detailed building-block structure, which is guidance rather than a legal obligation.
That overlap is good news. Build the shared layer once and you have answered the bulk of three frameworks, leaving a short list of paperwork specific to each.
Legal obligations versus contractual requirements
Plenty of companies hit compliance pressure long before any law applies to them. A customer in scope for NIS2 passes supply chain requirements down to its suppliers. A tender asks for ISO 27001 or TISAX. A cyber insurer sends a questionnaire about MFA coverage and backup frequency.
These contractual demands are often stricter and faster than the statutory ones, and they arrive with a deadline attached to revenue. Treat them as the same program, not a separate one. The evidence that satisfies an enterprise security review (device inventory, patch status, access logs, offboarding records) is the same evidence a supervisory authority would want, which is why preparing for an IT audit in Germany tends to be mostly an exercise in collecting things you should already have.
Which practical measures cover the most compliance ground at once?
If you have limited time, start with the controls that appear in every framework and every customer questionnaire.
Device management, patching, and endpoint security
Central device management is the single highest-leverage control for a growing company. It lets you enforce full-disk encryption, push operating system and application updates automatically, restrict who can install software, and lock or wipe a device remotely.
Patching matters because attackers keep walking through the same door. Exploits were the initial infection vector in 33% of Mandiant investigations in 2024 (Mandiant Consulting, Google Cloud), and 31% of breaches started with vulnerability exploitation in Verizon's 2026 dataset, where only 26% of critical vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog were fully remediated by organizations in 2025 (Verizon). Automated updates turn that from a memory problem into a configuration setting. The broader set of IT security measures for SMEs builds outward from this base.
Access control, onboarding, and offboarding
Role-based access means a new hire receives exactly the systems their role needs, and nothing else. Multi-factor authentication on email, file storage, and core business tools means a stolen password alone is no longer enough to get in. German companies have room to improve here: just 5% were classified as mature in Identity Intelligence readiness in 2025, and only 16% reached maturity in Machine Trustworthiness (Cisco).
Offboarding is the mirror image and the more common failure. Accounts that stay live after someone leaves are both a security risk and a data protection problem, since personal data on old devices and in old mailboxes still has retention rules attached to it. Same-day revocation, logged, is the standard to aim for.
Backups, incident response, and documentation
Backups answer the availability half of Article 32 and the business continuity expectations in NIS2. Follow the familiar pattern of three copies, two media types, one off-site, and test restores on a schedule rather than during an incident. Only 1 in 3 smaller organizations stopped a ransomware attack before attackers encrypted data, and the average recovery cost reached USD 1.7 million in Sophos' 2026 survey (Sophos).
Your incident response plan needs two reporting paths written into it: the 72-hour GDPR notification to the data protection authority, and, if you are in scope, the NIS2 chain to the BSI starting at 24 hours. Documentation is the common denominator all three frameworks test. Keep a record of what you decided, when, and why, because that record is what auditors read. Investment in security tooling also shows up in breach costs: the global average cost of a data breach was USD 4.4 million in 2025, while organizations making extensive use of AI in security reported USD 1.9 million lower breach costs (IBM and Ponemon Institute). The same logic drives most of the layered advice in a cybersecurity guide for small businesses.
What does a compliance roadmap look like as you grow from 30 to 150 employees?
Compliance scales in steps, and each step is triggered by headcount, sector, or a customer contract.
Around 20 to 30 employees: document your technical and organizational measures, build the record of processing activities, sign data processing agreements with every tool, appoint a data protection officer if the § 38 BDSG threshold applies, and put central device management, automated patching, and MFA in place.
Around 50 employees: check your NIS2 status seriously and register with the BSI if you are in scope. Formalize policies, run access reviews, test restores, and start structured awareness training. Training is still a gap across Europe: only 25% of EU businesses provided compulsory ICT security training in 2024 (Eurostat).
Approaching 150 employees: add audit trails, regular management reporting, rehearsed incident response, and certification such as ISO 27001 where customers or tenders require it.
None of this assumes an internal IT or security team. An IT management platform handles the enforcement and the evidence in one place: security settings applied to every device, patching on a schedule, onboarding and offboarding workflows, and exportable documentation. deeploi works this way for SMEs in Germany, with ISO 27001 certification, EU-only hosting, and support for companies working through NIS2 requirements.
Frequently asked questions
Do I need to comply with NIS2 if my company has fewer than 50 employees?
Usually not directly. The general scope combines a listed sector with a size threshold of 50 employees or more than 10 million euros in turnover and balance sheet total. Some services are covered regardless of size, so check the BSIG annexes rather than relying on headcount alone. Smaller suppliers often still have to meet NIS2-level requirements contractually, because regulated customers pass supply chain obligations down.
Do we need a data protection officer?
In Germany, yes, once at least 20 people in your company regularly process personal data by automated means (§ 38 BDSG). Certain high-risk processing activities trigger the requirement at lower numbers. Many SMEs appoint an external data protection officer, which is usually cheaper and avoids the conflict of interest that arises when the role lands on a founder or HR lead.
Do we need ISO 27001 to be compliant?
No. Neither GDPR nor NIS2 requires a certification. ISO 27001 is, however, a recognized way to demonstrate that your measures are appropriate, and customers often require it in contracts or tenders.
How do I protect company data in line with GDPR without an in-house IT team?
Focus on five enforceable basics: full-disk encryption on every device, MFA on all business accounts, least-privilege access tied to onboarding and offboarding, automated patching, and backups you have actually restored from. Each one is a configuration you can enforce centrally rather than a habit you have to police. Keep a short written record of what is enabled and when you last checked it.
What should I do if a company laptop is lost or stolen?
Lock the device remotely, end active cloud sessions, reset passwords, and decide on a remote wipe once recovery looks unlikely. Then assess whether personal data was exposed: strong full-disk encryption usually lowers the risk, while an unencrypted device with customer data often triggers the 72-hour notification. Document everything either way, and follow a step-by-step lost device response plan.
What is patch management, and why does it matter for compliance?
Patch management is the process of tracking which software versions run on your devices and installing security updates promptly and consistently. GDPR counts it as an appropriate technical measure under Article 32, NIS2 treats it as part of risk management according to the state of the art, and the BSI puts it near the top of its recommendations. Automating it is what makes the control provable instead of aspirational.










