Skip to main content Skip to search Skip to main navigation
Menu
Important Standards & legislation Score: 8/10

NIS-2 Directive: New Guide for Data Centre Security Published

Deutsche Rechenzentren GmbH publishes a practical guide for IT managers. NIS-2 significantly tightens cybersecurity requirements.

What happened? - New guide to the NIS-2 Directive

Deutsche Rechenzentren GmbH (DeRZ) has published a comprehensive guide to the NIS-2 Directive. The white paper is aimed specifically at data centre operators, IT managers and managed service providers. The guide is intended to provide orientation in a regulatory environment that, in the publishers' assessment, is still underestimated by many companies.

The document's practical approach focuses specifically on IT infrastructure and covers the tightened cybersecurity requirements that come with the EU NIS-2 Directive.

The details - Tightened requirements under NIS-2

With the NIS-2 Directive, the European Union has fundamentally tightened cybersecurity requirements for critical infrastructure. In Germany, the directive was transposed into binding law through the new BSI Act at the end of last year. The implications are more far-reaching than initially assumed.

Broader scope

Those affected are no longer just classic KRITIS operators. Colocation providers, hosting companies and IT service providers with 50 or more employees or 10 million euros in annual turnover also fall within the scope - often without knowing it. These thresholds make clear that cybersecurity is becoming a broad-based obligation and covers considerably more companies than before.

Physical security in focus

A central aspect of the DeRZ guide is the physical security of data centres - an area that has long been underestimated in IT compliance. NIS-2 makes clear that access control, power supply and fire protection must be equally ranked components of a documented risk management system.

Strict sanctions and reporting obligations

The new legal situation brings strict obligations to report security incidents. Particularly sensitive: personal liability of the management is explicitly provided for. Fines can amount to up to 10 million euros or 2 percent of global annual turnover.

Context - Why this development matters

The publication of the guide shows that the industry has recognised the need to act. NIS-2 marks a paradigm shift in cybersecurity: what previously concerned only large corporations and critical infrastructure is now becoming an obligation for a much wider circle of companies.

This opens up new business areas for the security technology sector. Companies that have so far invested little in physical security measures must fundamentally rethink their infrastructure. This applies in particular to:

  • Modern access control systems for data centres
  • Documented security concepts and risk management
  • Integration of physical and IT security measures
  • Compliant monitoring and reporting procedures

Practical tips for affected companies

According to the announcement, the DeRZ guide explains which requirements apply, how to assess your own status as an affected entity and which steps make sense now. For companies that may be affected, a systematic approach is advisable:

Carry out a status check

Companies should first check whether they fall under the new rules. The thresholds of 50 employees or 10 million euros in annual turnover cover considerably more companies than the previous KRITIS regulations.

A holistic view of security

NIS-2 requires a holistic approach that treats IT security and physical security as equals. This means that traditional security measures such as access control and video surveillance must now become part of the documented cybersecurity concept.

Documentation and processes

Documented risk management becomes mandatory. Companies must be able to demonstrate that they have implemented appropriate technical and organisational measures.

Outlook - What follows from the new legal situation

The publication of the DeRZ guide is an indicator that the implementation of NIS-2 has arrived in practice. With the new BSI Act coming into force at the end of last year, a new era of cybersecurity begins for many companies.

For the security technology sector this means new opportunities, but also the need to prepare for more complex requirements. The integration of IT security and physical security is becoming the standard, which also increases the importance of classic security solutions such as access control systems and surveillance technology.

Companies that act now and adapt their security infrastructure accordingly are not only compliant but also better protected against rising cyber threats. The DeRZ guide provides valuable support in putting the complex requirements of the NIS-2 Directive into practice.