News

NIS2 in the automotive sector – obligations, liability risks and corporate challenges

04.08.2026

An article published in the legal journal “RAW (Recht | Automobil | Wirtschaft)” by Julian Monschke and Andreas Daum sets out the key requirements for implementing the NIS2 Directive in the automotive sector. The authors outline the requirements of the amended German Act on the Federal Office for Information Security (Gesetz über das Bundesamt für Sicherheit in der Informationstechnik) (the “Act”) and address both OEMs and suppliers.

NIS2 applies as standard in the automotive sector

Both OEMs and a substantial share of suppliers fall within the scope of the Act, given the sector’s broad classification under NACE Rev. 2, Division 29 (Manufacture of motor vehicles, trailers and semi-trailers) and the low thresholds set by the size-cap rule. Cases where the Act does not apply will likely remain the exception. Suppliers not directly covered will still feel the effects indirectly through the supply chain: OEMs are legally required to put in place appropriate security measures across their supply chain, and they will pass these requirements on to their partners contractually.

Cybersecurity as a core management responsibility

The Act establishes cybersecurity as a core responsibility of senior management. The management board or board of directors must implement risk management measures, monitor compliance with them and undergo regular training on cybersecurity matters. Breaching these duties exposes managers to personal liability towards the company itself. Companies therefore need to build clear governance structures and robust reporting lines to meet this responsibility.

The law thinks in individual entities – group realities remain unresolved

The Act is consistently designed around individual legal entities and captures the organisational realities of large, cross-border groups only inadequately. In particular, when a cyber incident hits an entire group, companies must meet parallel reporting deadlines across several Member States at once. There is no provision for registering centrally in just one place. The tight 24-hour window for an initial report demands solid organisational and staffing capacity, and that becomes especially challenging to build within international group structures.

You can read the full article here (German only).

Well
informed

Subscribe to our newsletter now to stay up to date on the latest developments.

Subscribe now