Zedmos

NIS2 in Germany

NIS2 evidence, point by point

The German NIS2 implementation (BSIG 2025) has been in force since 6 December 2025, with no transition period. § 30(2) names ten measure areas. Below is what a Zedmos firewall produces evidence for — and what it does not, because those areas are organisational and no product covers them.

6 Dec 2025
In force, no transition period
§ 30(2)
Ten measure areas, state of the art
24 h
First report after an incident (§ 32)
≈ 29,500
German entities in scope

Where a firewall produces the evidence

Nr. 2 — Handling security incidents

The 24-hour clock in § 32 is only meetable if you can see the incident. Live sessions with the reason for each verdict, intrusion detection and prevention, and a CEF/LEEF/syslog-TLS feed into the SIEM you already run.

Nr. 4 — Supply-chain security

A German manufacturer, a CycloneDX SBOM with every release, and a published vulnerability-disclosure path. § 41 BSIG makes manufacturer trustworthiness a criterion; this is the paperwork that answers it.

Nr. 5 — Security in acquisition, development and maintenance

An Annex III Class II product under the EU Cyber Resilience Act, built to Annex I, with a published support period of at least five years and free security updates. The procurement file writes itself.

Nr. 8 — Cryptography and encryption

Selective TLS inspection with a policy that says where, encrypted overlays between sites in the engine, and DNS over TLS and HTTPS handled rather than blinded.

Nr. 9 — Access control

Devices recognised, users and groups from your directory, policy by zone and schedule, quarantine that isolates without cutting off. The records show who reached what, and why it was allowed.

Nr. 10 — Secured communication

Site-to-site overlays with automatic failover and per-application routing across uplinks. The § 30(2) Nr. 10 wording also covers multi-factor authentication; that is a directory and endpoint matter, and we do not claim it for a firewall.

Not covered by any firewall: Nr. 1, 3, 6, 7

Risk analysis, business continuity and backup, effectiveness assessment, cyber-hygiene training. These are organisational duties of the entity. NIS2 binds the operator, not the product; there is no NIS2 product certification, and we do not claim one.