Skip to content
Book a call
🇩🇪 Deutsch 🇬🇧 English 🇫🇷 Français
Flagships
Perstat Uptime monitoring, incident management and status pages for teams who promise availability. NextPKI Find, renew and manage certificates, whoever issued them. Databurg Audit-proof compliance documentation for companies with reporting duties.
Trust & crypto
sqlclient A native database client for macOS. Local, with no detour via someone else's servers. FoldMail An email client with encryption that is meant seriously, S/MIME and OpenPGP. Claro An app for separated parents: handovers, arrangements and costs in one place.
Bundle of the month
Reliability Bundle

Perstat + NextPKI as a single billed package. NIS2 evidence and certificate lifecycle from one cockpit.

Learn more
Learn
Blog Release notes, compliance news, roadmap. Careers
Trust
Legal & privacy DPA, sub-processor list.
Bundle of the month
Reliability Bundle

Perstat + NextPKI as a single billed package. NIS2 evidence and certificate lifecycle from one cockpit.

Learn more
Products Perstat NextPKI Databurg sqlclient FoldMail Claro
Imprint
Language
🇩🇪 Deutsch 🇬🇧 English 🇫🇷 Français
Book a call
Skip to content
NIS2 & Resilience

NIS2 in Practice: From Reporting Duty to Defensible Evidence

14.04.2026 · 3 min read

Since December 2025, NIS2 is German law. What monitoring, reporting and logging must actually prove when the regulator asks, and where companies stand now.

Since 6 December 2025, NIS2 is law in Germany. The NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) was passed by the Bundestag on 13 November 2025, confirmed by the Bundesrat on 20 November, and entered into force with no transition period. Around 29,500 companies across 18 sectors are in scope. The BSI registration deadline on 6 March 2026 has passed; late registration remains possible and is advisable.

Many organisations treated the rollout as a registration and documentation task. The harder part begins afterwards: being able to prove, when it counts, what actually happened.

The clock runs in hours, not weeks

The reporting duties (Section 32) are staggered and tightly timed. For a significant incident: an early warning within 24 hours, a notification within 72 hours, a final report within one month. These deadlines can only be met if an incident is detected quickly and reconstructed traceably. Whoever notices only while writing the report that the necessary data is missing has effectively already missed the deadline.

What the regulator wants to see

Section 30 requires risk-management measures: monitoring, logging, incident handling, business continuity and supply-chain security. The decisive difference lies between “we run monitoring” and “we can prove what happened, and when”. A supervisory authority does not accept a statement of intent, it wants evidence.

Evidence is defensible when it has three properties:

  • Gapless: detection, escalation and response are continuously timestamped, with no dark phases in the timeline.
  • Unalterable: logs and incident histories are append-only, not quietly correctable after the fact.
  • Reconstructable: from the trail, the incident chronology can be derived in a way that maps onto the 24-hour, 72-hour and one-month deadlines.

This is exactly where many setups fail: monitoring exists, but the data is scattered, overwritable, or cannot be assembled into an audit-proof chronology.

Responsibility cannot be delegated away

Section 38 puts management on the hook to approve the measures and oversee their implementation. That responsibility cannot be handed off to IT. Section 65 sets the frame with fines of up to 10 million euros. This shifts NIS2 from a technical task to a leadership one.

What makes sense now

Three steps pay off immediately: map your own obligations cleanly onto Sections 30 and 32; set up detection so that the 24-hour early warning is realistically achievable; and move logging onto unalterable, sufficiently long-retained trails. A single rehearsed reporting run quickly reveals where the chronology breaks.

In our Perstat module, monitoring, security posture and an append-only audit trail are connected so that NIS2 evidence can be produced on demand. The point itself, though, is independent of any tool, namely to run detection and logging so that what remains at the end is an audit-proof chronology and not a pile of scattered log lines.

NIS2 does not ask whether you run monitoring. It asks whether you can prove it.

Back to the blog

Datargo Datargo

Datargo GmbH, Frankfurt am Main. We build and operate our own software products on our own infrastructure in the European Union.

EU hosting, Frankfurt GDPR-native Made in Germany
Products
  • Perstat
  • NextPKI
  • Databurg
  • sqlclient
  • FoldMail
  • Claro
Company
  • Contact
  • Careers
  • Blog
  • Status page
Legal
  • Imprint
  • Privacy
© 2026 Datargo GmbH. All rights reserved.
Germany · English

Datargo® and Databurg® are registered trademarks of Datargo GmbH. All other product names, logos, and trademarks mentioned are the property of their respective owners.