NIS-2 and the shipping industry – cybersecurity obligations for shipping companies entered into force
Cybersecurity moves up the agenda and into the boardroom. What shipping companies and their management need to know now.
In a nutshell: For some months, numerous shipping companies have been subject to the cybersecurity obligations of the amended Act on the Federal Office for Information Security and on Information Security in Organisations ("BSIG"). We continue to receive questions on this topic. Passenger and cargo transport companies that exceed certain employee or turnover thresholds are classified as "important" or "particularly important entities". Anyone who has not yet acted should do so urgently – there is a risk of substantial fines and personal liability for management.
Background
The European NIS-2 Directive (EU) 2022/2555 of 14 December 2022 ("NIS-2") aims to ensure a high common level of cybersecurity within the Union. The implementation of the Directive is set out in the Act on the Federal Office for Information Security and on Information Security in Organisations (Gesetz über das Bundesamt für Sicherheit in der Informationstechnik und über die Sicherheit in der Informationstechnik von Einrichtungen -"BSIG"). Its key obligations have been amended by the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz) and have been in force in their new version since 6 December 2025. As part of the ‘transport and traffic’ sector, shipping is classified as a ‘high-criticality sector’ (Annex I of the Directive) – covered companies are subject to the supervisory and penalty regime of the BSIG.
Who is affected?
Among others, companies in critical sectors that also exceed certain thresholds are affected. Individual ships are expressly excluded – the addressee is always the company on land.
Both the NIS-2 Directive (Annex I, shipping sub-sector) and the BSIG (Annex 1) refer, within the "Transport and Traffic" to "passenger and freight transport companies in inland, maritime and coastal shipping, as defined in Annex I of the Regulation (EC) No /25/2004 for shipping, excluding the individual ships operated by these companies".
The companies that are captured by this is a matter of interpretation. To date, there are no reliable statements from the Federal Office for Information Security ("BSI") or European Union Agency for Cybersecurity ("ENISA"), nor any court decisions, that would assist with the interpretation.
Open question of interpretation: Who is a ‘transport operator’ under the BSIG?
The reference in the BSIG to Regulation (EC) No 725/2004 raises a question of interpretation that is significant in practice.
Reference is made to passenger and cargo transport companies engaged in inland, maritime and coastal shipping, as defined in Annex I to Regulation (EC) No 725/2004. However, Annex I to Regulation 725/2004 (Rule 1.7 in conjunction with SOLAS Rule IX/1) only defines the term "company" as the company that has assumed responsibility for the operation of the ship – in practice, therefore, the ISM manager who holds the Document of Compliance (DOC). The Annex does not contain a definition of "passenger or cargo transport companies". This reference is assessed differently in the legal literature:
Editorial oversight: Some commentators classify the reference as a legislative drafting error. According to this view, the EU legislator intended to cover only the operators of those ships that fall within the scope of Regulation (EC) No 725/2004 – i.e. in particular passenger ships and cargo ships of 500 GT or more engaged in international voyages. This reading would significantly narrow the scope of application and would largely exclude inland shipping.
Reference to the SOLAS company concept: According to another view, the reference is not an oversight but a terminological reference to the concept of "company" established in international maritime law. Annex I to Regulation 725/2004 serves to implement the SOLAS Convention and adopts its definitions, including the functional concept of a company. On this reading, the Directive – in line with its organisation-based regulatory approach – refers to the companies responsible for the operation of ships, without restricting the scope of application to specific ship categories. This interpretation would mean that inland shipping companies may also be potential addressees, even though they are not subject to the SOLAS regime. The ISM manager responsible for ship operations in practice would then be the primary addressee.
Economic function-based interpretation: Finally, it can be argued that the NIS-2 Directive and the BSIG, by using the distinct term "passenger and cargo transport companies", focus on the economic function and have deliberately not adopted the narrower SOLAS term "company". On this basis, all companies commercially engaged in the carriage of cargo or passengers would be covered. This would include shipowners and vessel owners who have outsourced operational ISM management to an external manager.
It remains to be seen how the BSI interprets the term and whether the courts will follow this interpretation.
In view of the significant risks of penalties, companies should not rely on a narrow interpretation. Any decision should at least be carefully documented.
Threshold values
The legislator distinguishes between large, medium-sized and small enterprises. Small enterprises are those that fall below the thresholds set out below. They are not subject to any obligations under NIS-2 or the BSIG if they do not operate critical infrastructure.
The obligations differ for large and medium-sized enterprises. They are classified as follows:
Medium-sized enterprises are those with at least 50 employees or an annual turnover and balance sheet total of over €10 million each. They are considered “important entities”.
Large enterprises are those with at least 250 employees or an annual turnover exceeding €50 million and an annual balance sheet total exceeding €43 million.
In principle, affiliated and partner companies (with a shareholding of 25% or more) both domestically and abroad are also considered when assessing the thresholds, unless the company operates its information technology systems independently of these affiliated companies.
When considering the thresholds for individual companies, seasonal outliers are disregarded. A company’s status only changes if the thresholds are exceeded or not met in two consecutive years.
What obligations apply?
Affected companies must take appropriate, proportionate and effective technical and organisational measures to prevent disruptions to the availability, integrity and confidentiality of the information technology systems, components and processes they use to provide their services, and to minimise the impact of security incidents as far as possible (Section 30(1) BSIG).
Specifically, covered organisations must:
register with the Federal Office for Information Security (BSI);
introduce a comprehensive cybersecurity risk management system (Section 30 BSIG) covering at least ten areas of measures prescribed by law (including risk analysis, incident response, supply chain security, cryptography and access control);
report significant security incidents to the BSI within strict time limits (Section 32 BSIG); and
ensure that senior management approves the risk management measures, monitors their implementation and participates in cybersecurity training (Section 38 BSIG).
The personal liability of senior management for breaches of these obligations is expressly provided for by law. Furthermore, fines of up to EUR 10 million or 2% of global annual turnover may be imposed for breaches. Reduced fines apply for late registration.
Distinction from operators of critical infrastructure
The NIS-2 obligations should not be confused with the obligations of operators of critical infrastructure (e.g. control centres or port information systems) which also arise from the BSIG. The NIS-2 obligations, on the other hand, apply to the company regardless of whether it operates individual facilities classified as ‘critical’.
Action required
Companies that have not yet taken any measures should immediately check whether they fall within the scope of application of the newly introduced obligations under the BSIG. If necessary, they should register with the BSI and begin implementing the risk management obligations. The obligations under the BSIG apply regardless of whether registration, which should have taken place within three months following the amended BSIG has entered into force, has been completed. In view of the unresolved question of interpretation regarding the scope of application, a careful review is recommended for all companies in the shipping sector. Companies that decide against registration should document why they are not obliged under the BSIG.
If you have any further questions on this matter, please do not hesitate to contact your contact person at EHLERMANN RINDFLEISCH GADOW, Hanno Geissler or Sven Deters.

