Introduction
Germany transposed NIS2 into national law ahead of many of its EU peers, and its federal cybersecurity agency, the BSI, is now the clearest early signal of how NIS2 enforcement actually plays out in practice once a supervisor has a functioning legal mandate. Roughly 47 formal orders have already been issued under Germany's NIS2 implementation - a volume that says more about likely enforcement patterns across the rest of the EU than any single fine has so far.
What a 'Formal Order' Actually Means
A formal supervisory order sits a step before a fine. It typically directs a regulated entity to remediate a specific identified gap - a missing risk management measure, an incomplete incident reporting process, an unaddressed supply-chain security requirement - within a defined window, with a fine as the consequence of non-compliance with the order itself, not the original gap. The high volume of orders relative to confirmed fines suggests German supervisors are, so far, using the enforcement ladder as designed: identify gaps, direct remediation, and reserve fines for entities that fail to close them once directed.
What the Orders Are Actually Targeting
- Incomplete or untested incident response and reporting procedures
- Insufficient supply-chain and third-party risk assessment
- Missing or inadequate risk management measures across the ten categories specified in NIS2's Article 21
- Gaps between documented security policy and demonstrable operational practice
The recurring gap: policy exists, evidence doesn't
The pattern emerging from Germany's early enforcement activity mirrors what has already surfaced in the small number of confirmed fines elsewhere in the EU: organizations are rarely cited for having no policy at all. They are cited for being unable to demonstrate, with evidence, that a documented policy was actually operating as described on the dates that matter. A written incident response plan that has never been tested, or a supply-chain risk assessment that exists as a static document rather than a continuously updated record, both look identical to a well-run programme on paper - until an auditor asks for evidence rather than a description.
What this signals for organizations in less mature enforcement jurisdictions
Germany's supervisory maturity is ahead of much of the EU, which makes its enforcement pattern a useful preview rather than a Germany-specific concern. Organizations operating in jurisdictions where NIS2 supervision is newer or less active should read Germany's order volume as a preview of what their own eventual audits are likely to focus on - not evidence that their jurisdiction is safer.
Germany's enforcement wave is a preview, not an outlier - the gap it keeps finding is between documented policy and provable practice. See how ROOTKey turns compliance policy into continuous, audit-ready evidence.
Recebe insights de ciber-resiliência no teu email
Orientação prática e pronta para auditoria sobre integridade de dados, conformidade e continuidade - à medida que publicamos.





