Cybersecurity in healthcare is no longer a future issue, but applicable law with personal liability for executive management. The registration deadline has already expired.
The NIS2 Implementation Act (NIS2UmsuCG) entered into force on 6 December 2025 without a transitional period. Since then, around 29,500 companies in 18 sectors, including hospitals, larger medical care centres (MVZs) and many health IT providers, have been subject to supervision by the Federal Office for Information Security (BSI). The deadline for registration on the BSI portal already ended on 6 March 2026. According to current surveys, however, almost half of the affected companies still underestimate whether they are affected.
Who is affected — and why this is often underestimated
NIS2 generally applies from 50 employees or annual turnover of more than €10 million in one of the regulated sectors. For healthcare, this means that not only hospitals as traditional operators of critical infrastructure are affected, but also medium-sized networks of medical care centres, care facilities of a certain size, practice software providers and other health IT service providers. Many of these organisations do not classify themselves as “critical” because they use the old IT Security Act as their reference point, which was considerably narrower in scope.
Those who are not registered are already in default. The obligation to register subsequently continues; the lack of registration is an independent offence subject to a fine.
What remains unclear in concrete terms
- How strictly and how quickly the BSI will actually supervise around 29,500 affected organisations — a risk-based approach that initially addresses larger and more critical organisations is realistic.
- To what extent an existing ISO 27001 ISMS already covers NIS2 requirements — in practice, usually 70 to 80 per cent, while registration, the tiered reporting procedure and executive-management obligations must be evidenced separately.
- How the interaction with the KRITIS Umbrella Act, which has applied since March 2026 and additionally imposes requirements on physical resilience, is to be assessed in individual cases.
- How far supply-chain responsibility extends when software or service partners themselves fall below the NIS2 thresholds but are contractually included in the security requirements.
Managing-director liability as a new reality
Unlike earlier rules, the NIS2 Implementation Act provides for personal liability of executive management for breaches of cybersecurity obligations. Fines of up to €10 million or 2 per cent of worldwide annual turnover are possible. Executive management is also required to attend risk-management training and actively approve security measures. Those who delegate the issue solely to the IT department therefore continue to bear the risk personally — a circumstance of which many people responsible in healthcare are not yet aware.
Conclusion: action is more urgent than final certainty
Those who wait for complete legal certainty before starting NIS2 implementation are waiting for something that will not arise in the foreseeable future. Assessment of whether they are affected, registration and a robust foundation of risk management can nevertheless be implemented today — and materially reduce both the regulatory risk and the personal liability risk of executive management.
PEC supports healthcare organisations with structured assessment and implementation. Find out more on our page about NIS2 consulting and cyber resilience for hospitals or in the NIS2 Quick Check for hospitals and medical care centres.