JAN HÖCKDE

NIS2 · DACH

NIS2: from requirements to a manageable operating process.

Germany and Austria implement NIS2 through national law. Switzerland is outside the EU NIS2 framework and follows its own reporting regime. The key question is therefore not only what applies, but how requirements are managed and evidenced in practice. This overview is for orientation and does not constitute legal advice.

LEGAL CONTEXT

Three countries. Three distinct starting points.

Germany

Germany’s NIS2 implementation law entered into force on 6 December 2025.

Austria

Austria’s NISG 2026 enters into force on 1 October 2026.

Switzerland

Switzerland is not an EU or NIS2 jurisdiction. Since 1 April 2025, a separate reporting obligation has applied to cyberattacks on critical infrastructure; qualifying incidents must be reported to the NCSC within 24 hours.

Do not just know what is required. Know what to do next.

ReportAct structures frameworks, controls, evidence, vendor and risk registers, and incident workflows. This creates an operational path from requirement to defensible evidence. I am the commercial point of contact; subject-matter logic and delivery remain with ReportAct.

Explore the ReportAct platform →jan@reportact.comSee the NIS2 workflow in ReportAct ↗