An initiative by Solutive AG
solutive.ag
Change & Release

NIS2 in Germany: BSI enforcement phase May 2026 and its consequences for SAP Change Management

NIS2 is the EU directive on cybersecurity. Transposed into German law via the BSIG. BSI audit phase active since May 2026; personal liability for management effective since December 2025.
May 18, 2026
min Lesezeit
6

NIS2 in the German implementation

NIS2 (Directive (EU) 2022/2555) is the EU directive on the cybersecurity of network and information systems. In Germany, it was incorporated into the NIS-2 Implementation and Cybersecurity Strengthening Act (BSIG). It addresses essential entities and important entities across 18 sectors, including energy, transport, health, digital infrastructure, public administration, and manufacturing.

The registration obligation with the BSI expired on March 6, 2026. Since May 2026, the BSI has been in the operational audit phase. Personal liability for management under Section 38 BSIG has been in effect since December 6, 2025.

BSI audit phase and personal management liability

As of May 18, 2026: According to publicly cited BSI data (via heise online, referenced multiple times), the registration rate is approximately 38.5 percent. Out of an estimated 29,500 obligated entities, about 11,500 are registered, while around 18,000 are not. In Q4 2025, the BSI had already issued 47 formal notices regarding missing registrations (securitytoday.de, May 3, 2026).

For SAP users, NIS2 is not just an IT security issue. The requirements of Section 30 BSIG (risk management measures) directly impact the change process: access control, cryptography, vulnerability management, security training, and orderly change processes are explicitly required. Anyone managing changes via Cloud ALM and ChaRM in a hybrid landscape without a verifiable audit trail will face problems under Section 30.

Belgium has set the benchmark: the first CCB deadline was April 18, 2026, with three compliance paths (CyFun compliance, ISO 27001 certification, or direct CCB inspection). Austria follows with the NISG 2026 (effective October 1, 2026). Germany is therefore under pressure to keep pace with its neighbors.

BSIG requirements for SAP users

The central anchors in the BSIG for SAP users:

StandardRequirementSAP RelevanceSection 30 BSIGRisk management measures: cryptography, access control, vulnerability management, security training, orderly change processesAudit trail from change request to deployment, SoD in the transport workflow, documented emergency changesSection 32 BSIGReporting obligations for significant security incidentsEarly warning within 24 hours, follow-up report within 72 hours, final report within one monthSection 38 BSIGPersonal management liabilityVerifiable supervisory duty, mandatory training for the management levelSection 61 Para. 9 BSIGUltima ratio: suspension of operating license, prohibition of management activitiesCan be applied in case of repeated non-compliance with BSI ordersSection 65 BSIGFine frameworkUp to 10 million EUR or 2% of global annual turnover for essential entities, whichever is higher

For SAP change practice, this means four concrete requirements: a seamless audit trail, technically enforced segregation of duties, documented emergency change processes, and regular security training for those responsible for changes.

Structural gaps between Cloud ALM, ChaRM, and ITSM

Cloud ALM alone does not cover §30. The structural gaps in SAP Cloud ALM regarding transport sequencing, segregation of duties in the transport workflow, and object audit trails are documented in several independent sources (CoreALM 2026, REALTECH January 2026, blue.works ALM Coffee Party IX March 2025). For NIS2-obligated institutions losing ChaRM in 2027, the question becomes urgent: What does a NIS2-compliant change path look like after SolMan?

Personal liability changes escalation behavior. §38 BSIG places obligations on the management level. This is new in the German IT security landscape. CISOs and CIOs who previously delegated regulatory concerns to an advisory role must now document the involvement of executive management in the decision-making process. A change architecture that structurally undermines this escalation creates personal risk.

The non-auditable path between Cloud ALM and ChaRM. In hybrid landscapes, which are typical for existing SAP customers, a productive change often runs through multiple tools: Cloud ALM captures the requirement, ChaRM (or a third-party system) manages the transport, and an ITSM system (Jira, ServiceNow, TOPdesk) handles the service request. If the audit trail breaks at any interface, §30 BSIG cannot be plausibly fulfilled during a regulatory audit.

Supervision in the preparation phase, not the final phase. Between May 11 and May 18, 2026, no BSI-issued fines from the DACH region were publicly identified by name. Trend Micro (May 2026, press release) and securitytoday.de expect the first wave of systematic regulatory audits for Q3 2026. Anyone interpreting this as a sign to relax is overlooking the logic of announcements: advance warnings are the standardized precursor to major fine proceedings.

NIS2 roadmap for existing SAP customers

An SAP-specific NIS2 roadmap for existing customers:

  1. Clarify registration status. If not registered: catch up immediately, as §65 BSIG is already applicable. If registered: technically operationalize the supplementary obligations from §30 BSIG.
  2. Change path audit. Examine the complete path of a productive SAP change from requirement to deployment. Document every tool handover. Identify gaps in the audit trail.
  3. Technically anchor SoD enforcement. Segregation of duties must not only exist in the role matrix but must be technically enforceable within the transport workflow. CAB approvals must take effect before the import, not be documented retroactively.
  4. Define an emergency change process. Emergency changes require a dedicated, documented path with post-audit and mandatory justification. Without a formal emergency change process, compliance with §30 cannot be demonstrated.
  5. Practice reporting channels. Test §32 BSIG reporting obligations in tabletop exercises. The 24-hour early warning is operationally demanding if the underlying architecture still needs to be identified.
  6. Train management. §38 BSIG requires verifiable training. A one-off awareness session is not enough; regular repetition is the standard of supervisory practice (referencing the Belgian CCB).
  7. Evaluate SolMan successors through a NIS2 lens. When choosing a successor for ChaRM from 2027 onwards, audit trails and SoD enforcement are no longer convenience features, but mandatory regulatory requirements.

Sources

  • BSI Act (BSIG), in particular §§30, 32, 38, 61, 65 (gesetze-im-internet.de)
  • Directive (EU) 2022/2555 (NIS2) (EUR-Lex)
  • securitytoday.de, May 3, 2026: NIS2 Enforcement 2026: BSI audit phase and DACH checklist
  • boerse-express.com, May 2026 (Trend Micro press release): NIS2 and phishing resistance: BSI begins enforcement in May 2026
  • diesec.com, May 2026: NIS2 personal liability for German boards is now live
  • perfomynd.com, March 2026: NIS2 registration deadline in Germany: what low registration numbers mean for employers
  • secjur.com, April 2026: NIS2 penalties: fines of up to 10 million EUR
  • advisori.de, April 2026: NIS2 enforcement 2026: BSI actively auditing, fines imminent
  • Morrison Foerster, December 8, 2025: Germany NIS2 implementation (mofo.com)
  • DLA Piper, February 11, 2026: NIS2 transposed Germany (dlapiper.com)
  • Reed Smith, January 23, 2026: NIS2 Germany immediate effect, broad scope (reedsmith.com)
  • privacyworld.blog, December 2025: Registration portal January 6, 2026
Tool Landscape

NIS2 has moved from the preparation phase to the enforcement phase in Germany. While oversight is currently focused on spot checks and advisory letters, the legal framework for fines of up to EUR 10 million and personal management liability has been in effect since December 2025. For SAP users, Section 30 of the BSIG has become an architectural issue: anyone unable to provide a seamless audit trail for the change path in a hybrid landscape cannot plausibly meet the requirements. The choice of a successor to SolMan has thus taken on a new dimension. It is no longer just about functional parity with ChaRM, but about the ability to provide evidence to regulators and management. Those waiting for Q3 2026 as the deadline for the first wave of oversight are failing to make the most of the remaining preparation time.

Autor:
Christian Steiger