NIS2 (Directive (EU) 2022/2555) is the EU directive on the cybersecurity of network and information systems. In Germany, it was incorporated into the NIS-2 Implementation and Cybersecurity Strengthening Act (BSIG). It addresses essential entities and important entities across 18 sectors, including energy, transport, health, digital infrastructure, public administration, and manufacturing.
The registration obligation with the BSI expired on March 6, 2026. Since May 2026, the BSI has been in the operational audit phase. Personal liability for management under Section 38 BSIG has been in effect since December 6, 2025.
As of May 18, 2026: According to publicly cited BSI data (via heise online, referenced multiple times), the registration rate is approximately 38.5 percent. Out of an estimated 29,500 obligated entities, about 11,500 are registered, while around 18,000 are not. In Q4 2025, the BSI had already issued 47 formal notices regarding missing registrations (securitytoday.de, May 3, 2026).
For SAP users, NIS2 is not just an IT security issue. The requirements of Section 30 BSIG (risk management measures) directly impact the change process: access control, cryptography, vulnerability management, security training, and orderly change processes are explicitly required. Anyone managing changes via Cloud ALM and ChaRM in a hybrid landscape without a verifiable audit trail will face problems under Section 30.
Belgium has set the benchmark: the first CCB deadline was April 18, 2026, with three compliance paths (CyFun compliance, ISO 27001 certification, or direct CCB inspection). Austria follows with the NISG 2026 (effective October 1, 2026). Germany is therefore under pressure to keep pace with its neighbors.
The central anchors in the BSIG for SAP users:
StandardRequirementSAP RelevanceSection 30 BSIGRisk management measures: cryptography, access control, vulnerability management, security training, orderly change processesAudit trail from change request to deployment, SoD in the transport workflow, documented emergency changesSection 32 BSIGReporting obligations for significant security incidentsEarly warning within 24 hours, follow-up report within 72 hours, final report within one monthSection 38 BSIGPersonal management liabilityVerifiable supervisory duty, mandatory training for the management levelSection 61 Para. 9 BSIGUltima ratio: suspension of operating license, prohibition of management activitiesCan be applied in case of repeated non-compliance with BSI ordersSection 65 BSIGFine frameworkUp to 10 million EUR or 2% of global annual turnover for essential entities, whichever is higherFor SAP change practice, this means four concrete requirements: a seamless audit trail, technically enforced segregation of duties, documented emergency change processes, and regular security training for those responsible for changes.
Cloud ALM alone does not cover §30. The structural gaps in SAP Cloud ALM regarding transport sequencing, segregation of duties in the transport workflow, and object audit trails are documented in several independent sources (CoreALM 2026, REALTECH January 2026, blue.works ALM Coffee Party IX March 2025). For NIS2-obligated institutions losing ChaRM in 2027, the question becomes urgent: What does a NIS2-compliant change path look like after SolMan?
Personal liability changes escalation behavior. §38 BSIG places obligations on the management level. This is new in the German IT security landscape. CISOs and CIOs who previously delegated regulatory concerns to an advisory role must now document the involvement of executive management in the decision-making process. A change architecture that structurally undermines this escalation creates personal risk.
The non-auditable path between Cloud ALM and ChaRM. In hybrid landscapes, which are typical for existing SAP customers, a productive change often runs through multiple tools: Cloud ALM captures the requirement, ChaRM (or a third-party system) manages the transport, and an ITSM system (Jira, ServiceNow, TOPdesk) handles the service request. If the audit trail breaks at any interface, §30 BSIG cannot be plausibly fulfilled during a regulatory audit.
Supervision in the preparation phase, not the final phase. Between May 11 and May 18, 2026, no BSI-issued fines from the DACH region were publicly identified by name. Trend Micro (May 2026, press release) and securitytoday.de expect the first wave of systematic regulatory audits for Q3 2026. Anyone interpreting this as a sign to relax is overlooking the logic of announcements: advance warnings are the standardized precursor to major fine proceedings.
An SAP-specific NIS2 roadmap for existing customers:
NIS2 has moved from the preparation phase to the enforcement phase in Germany. While oversight is currently focused on spot checks and advisory letters, the legal framework for fines of up to EUR 10 million and personal management liability has been in effect since December 2025. For SAP users, Section 30 of the BSIG has become an architectural issue: anyone unable to provide a seamless audit trail for the change path in a hybrid landscape cannot plausibly meet the requirements. The choice of a successor to SolMan has thus taken on a new dimension. It is no longer just about functional parity with ChaRM, but about the ability to provide evidence to regulators and management. Those waiting for Q3 2026 as the deadline for the first wave of oversight are failing to make the most of the remaining preparation time.