/ THE SHORT ANSWER
- 01Assess the relevant entity and activities explicitly.
- 02Use the current BSI Portal route for applicable registration.
- 03Connect the scope decision to incident and recovery ownership.
/ dotSuper point of view
dotSuper analysis: scope and operating responsibility should lead the implementation, with tools selected for demonstrated gaps.
Begin with the legal entity and what it does
[1] The word manufacturer alone is not enough to resolve the assessment.
Document the relevant entity, its activities and the evidence used.
A group may have production, distribution and shared IT in different entities.
Do not assume a brand-level answer describes every company.
Identify where services are provided, which entity operates them and which teams hold the supporting financial and organisational information.
Write the open questions before purchasing a compliance platform.
If the unresolved issue is which activities fall within a listed category, a software inventory will not answer it.
The right first action is to obtain the business facts and have the responsible specialists assess them against the current provisions.
Use the current registration route when it applies
It directs NIS-2 registration to the BSI Portal rather than the older MIP route.
[2] Treat that as an operational detail worth getting right.
Determine who has authority to represent the entity and maintain the relevant records.
A portal account created by a temporary project member can become a continuity problem if nobody else understands its ownership or access arrangements.
Avoid turning registration into a completion claim.
A registered organisation still needs to understand its operational responsibilities.
Equally, an unresolved scope question should remain visible rather than being replaced with a confident not applicable label because the team has not yet collected the necessary evidence.
Create a scope record that another colleague can follow
It helps organise evidence for a qualified assessment.
It does not replace the statutory provisions or determine the outcome for a particular business.
Record disagreements and their resolution.
A scope assessment may depend on how a service or organisational relationship is understood.
The supporting explanation matters because another person may need to revisit the conclusion after an acquisition, restructuring or material change in activities.
| Question | Gather | Accountable function |
|---|---|---|
| Which entity? | Legal identity and operating role | Management |
| Which activities? | Actual services and production categories | Operations |
| Which size facts? | Relevant workforce and financial records | Finance |
| Which relationships? | Group and shared-service structure | Finance and legal |
| Which conclusion? | Reasoned assessment with date | Authorised advisers and management |
| Which next action? | Registration or reassessment task | Named implementation owner |
A hypothetical German industrial group
Management receives a supplier questionnaire asking whether the group is NIS-2 compliant.
The sales team wants a single sentence it can reuse.
The project owner instead maps the entities and gathers the relevant activity and size information.
Qualified advisers assess the actual scope.
The customer response then identifies the entity and the specific evidence available, without presenting a group-wide conclusion unsupported by the review.
Meanwhile, IT can progress on known operational gaps such as unclear incident contacts and recovery ownership.
That work does not need an invented legal classification to be useful.
The hypothetical example illustrates how the business can resolve scope carefully while continuing improvements that are already justified by its dependence on reliable systems.
Translate the assessment into operating responsibilities
Include production planning, engineering document access, identity services and supplier connections.
A server list alone may miss how several systems combine to support one important process.
Assign ownership for incident decisions, supplier coordination and recovery priorities.
Ask how management learns that an incident has occurred and who can authorise a disruptive containment action.
These questions expose gaps that a document repository or policy template may not resolve.
There is a tradeoff between central consistency and local knowledge.
A group security team can provide common methods, but a plant may understand equipment dependencies that the central team cannot infer.
Design the operating model so local facts reach the people making incident and recovery decisions quickly and in a usable form.
Choose tools after the missing work is visible
Avoid buying overlapping platforms because each advertises NIS-2 coverage.
Ask which decision will become easier and which existing record remains authoritative.
Maintain the scope record as the business changes.
New activities, acquisitions and altered service arrangements should trigger review.
Keep the source date and responsible owner visible so the organisation knows whether a conclusion still reflects its current structure.
The next useful deliverable is a short entity-level assessment pack with unresolved questions and operational owners.
It should let management explain what has been determined, what remains under review and which concrete work is underway.
That is a stronger foundation for implementation than a broad claim of readiness attached to a newly purchased dashboard.
What this page cannot conclude
- 01No particular entity is classified, and this article does not reproduce every threshold, exception or group-calculation rule.
- 02Registration and reporting obligations require current legal assessment of the actual facts; no universal deadline is asserted.
- 03This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Sources
- 01BSI Act, section 28: covered entitiesFederal Ministry of Justice and Federal Office of Justice · accessed Sep 15, 2026
- 02NIS-2 registration informationFederal Office for Information Security (BSI) · accessed Sep 15, 2026
This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Our editorial standard · Found an error? Send a correction with its source.
/ CITE OR SHARE THIS GUIDE
Make the evidence easy to verify.
When you reference this guide, link to its canonical URL. That gives readers one stable place for the evidence, limitations and future updates.
dotSuper Research Desk. (September 15, 2026). Resolve Your German NIS-2 Scope Before Buying Tools. dotSuper. https://dotsuper.net/feeds/market-intelligence/germany-nis2-manufacturing-scope