Research
Openness is your principle. And your biggest attack surface.
Research institutions are important entities under the law. Day-to-day operations run on exchange, guest access, and international collaboration — exactly the qualities that make security demanding.
Does this apply to you?
Annex 2 · Sector 7
Sector: Research
Research institutions.
Entity of essential importance
at least 250 employees — or annual turnover above €50 million and an annual balance sheet total above €43 million
Applies to entity types under Annex 1 · Section 28(1), (2) BSIG
Important entity
at least 50 employees — or annual turnover and balance sheet total above €10 million
Applies to entity types under Annexes 1 and 2 · Section 28(1), (2) BSIG
Important for you: The statutory description of this entity type is remarkably brief — whether your institution falls under it, and whether state-level rules apply alongside it, is a case-by-case question for legal review.
Covered regardless of size: operators of critical facilities, qualified trust service providers, top-level domain registries, and DNS service providers (Section 28(1) Nos. 1, 2 BSIG); trust service providers always count as an important entity (Section 28(2) No. 1 BSIG). Employee count and financial figures are alternative thresholds (either one triggers coverage); for the financial figures, both values must be exceeded. Whether your specific company is covered is a case-by-case question — that's what lawyers are for.
What's typically in the register in this sector
These obligations decide it for you.
Section 30(2) No. 9 BSIG
Access that comes and goes
Personnel security, access control, and ICT management for visiting researchers, doctoral candidates, and project partners — otherwise accounts outlive their projects by years.
Section 30(2) No. 8 BSIG
Protect research data cryptographically
Concepts and processes for cryptographic methods: unpublished results are your institution's capital.
Section 30(2) No. 7 BSIG
Awareness without heavy-handedness
Basic training and awareness that fit academic culture — short, factual, without a tone of prohibition.
Example (fictional): The institute and the guest account
An institute sets up cluster access for a visiting researcher from abroad, limited to six months. The time limit is never enforced technically — the account stays active.
Two years later, that same account is used to run compute jobs for unrelated purposes. The damage is limited, but the lesson is uncomfortable: it wasn't the firewall that failed, it was a list nobody maintained.
A freely invented example for illustration — no real customer, no legal advice
Here's how Compliverse takes this off your plate.
- 1
A recurring access review with reminders — instead of a list nobody keeps up.
- 2
Policy templates for access and cryptography, adapted to your institution's culture and rolled out with signed acknowledgment.
- 3
Evidence that also satisfies funding bodies and collaboration partners.
NIS2 in Research: frequently asked questions
Is my Research company in scope for NIS2?
Your sector is covered by Germany's BSI Act: Annex 2 · Sector 7, sector Research. That does not put you in scope automatically — a size threshold has to be met as well (Section 28(1), (2) BSIG). And no official notice arrives: you assess the classification yourself and register if it applies (Section 33 BSIG). Your sector also has an exception — it is set out on this page under “Are you in scope?”. Judging your individual case is a lawyer's job.
From what size does NIS2 apply to us?
You count as an essential entity from at least 250 employees — or annual turnover above €50 million and an annual balance sheet total above €43 million; as an important entity from at least 50 employees — or annual turnover and balance sheet total above €10 million (Section 28(1), (2) BSIG). Headcount and financial figures are alternatives to each other — but where the financial figures are used, both have to be exceeded. Some entity types are in scope regardless of size, among them operators of critical facilities and qualified trust service providers.
Which authority is responsible for us in Germany?
Registration and supervision sit with the Bundesamt für Sicherheit in der Informationstechnik (BSI) — Germany's Federal Office for Information Security (Section 33 BSIG). Security incidents, however, do not go there: they go to the joint reporting office of the BSI and the Federal Office of Civil Protection and Disaster Assistance (BBK) — early warning within 24 hours, report within 72 hours, follow-up report a month later (Section 32 BSIG). This is the most common misreading of the act — the supervisory authority and the reporting office are not the same body.
What happens if we do not implement NIS2?
The obligations do not go away: registration stays due (Section 33 BSIG), so do the risk-management measures (Section 30(2) BSIG), and reporting deadlines start running with the first significant incident (Section 32 BSIG). On top of that, Section 38 BSIG puts management personally on the hook: they have to approve the measures, oversee their implementation, and undergo training themselves. “I didn't know” does not carry here.
Find out in thirty seconds what applies to you.
Four questions, an honest first estimate — then you'll know which module to start with and what it costs.
What becomes important next
More industries
Legal status checked on 01/09/2026 · Every statement with a source · No legal advice