The NIS2 Directive is reshaping cybersecurity compliance across the EU, and German healthcare providers are no exception. With stringent new requirements for data security, incident reporting, and risk management, even mid-sized medical practices must prepare for significant changes. This article breaks down the role of key oversight bodies like the BSI and KBV, explains how practices are categorized under NIS2, and outlines the new compliance obligations—including steep penalties for non-compliance.