Energy sector under NIS2 – why municipal utilities and grid operators can no longer defer the Microsoft 365 question before the autumn 2026 audit
Energy sector under NIS2 – why municipal utilities and grid operators can no longer defer the Microsoft 365 question before the autumn 2026 audit
On 17 October 2026 the first operational proof deadline of the German NIS2 Implementation Act expires for essential entities in the energy sector. In scope: electricity, gas, district-heating and hydrogen suppliers, distribution and transmission grid operators, charging-point operators and balancing-group managers. Unlike under the old IT Security Act 2.0, the 500,000-customer threshold is gone. Small municipal utilities with at least 50 employees or 10 million euros of turnover are in scope for the first time – and face the same proof logic as a large transmission grid operator. As audit preparations run, one question that IT leaders have long preferred to postpone becomes unavoidable: can Microsoft 365 still be operated audit-ready at an energy supplier in 2026?
What NIS2 concretely demands in the energy sector in 2026
NIS2, transposed in the German NIS2UmsuCG, obliges affected entities under Article 21 to a catalogue of technical and organisational measures: risk management, incident handling, business continuity, supply-chain security, secure procurement of network and information systems, effectiveness reviews, cyber hygiene, cryptography, access control, personnel management, multi-factor authentication, asset management and secured communication. The energy sector adds sector-specific requirements from the BSI KRITIS sector standard and industry-specific security standards from BDEW and VKU. The central novelty: proof must be concrete and audit-grade. A pure contract clause with a cloud provider no longer satisfies BSI auditors since spring 2026, as we already laid out in our post on the BSI C3A criteria catalogue.
Why Microsoft 365 becomes a hard problem in the NIS2 audit
The issue is not new but tightens two notches under NIS2. First, NIS2 demands proof that operational, grid and customer data fall under regulated cryptography and access control. Second, the new supply-chain duty kicks in: the entity has to document how access by sub-processors and their legal parents can be technically and legally excluded from processed data. As long as the processing entity is a subsidiary of a US parent group, the US CLOUD Act (18 U.S. Code §2713) and FISA Section 702 apply. The operator can be compelled to hand over data without being allowed to inform the European entity. For a balancing group, a grid control system or a customer portal at a distribution grid operator this is a regulatory contradiction with no clean workaround. The full legal derivation is in our post on the CLOUD Act 2026.
The concrete proof situation in the autumn audit
The BSI and competent state supervisors focus the autumn 2026 cycle on four points:
- Storage locations of all processed grid and market communication data, including backup and log copies.
- Encryption chains – zero-knowledge or at least server-side encryption with keys held in Europe.
- Access control by the operator and its sub-processors, including access paths via parent companies.
- Operational continuity in case of a regulatory or political failure of the cloud provider, in the context of the EU Data Act and its cloud-switching duties from January 2027.
Anyone who cannot answer these four points audit-grade for a US hyperscaler operation risks a negative audit result and, as a consequence, fines up to 10 million euros or two percent of worldwide group turnover – plus personal liability of management.
The sovereign stack for municipal utilities – no longer a special path
The building blocks that answer the four proof points audit-grade are production-ready and live at several municipal operators: Nextcloud with Collabora Online replaces SharePoint and OneDrive for administrative documents. Open-Xchange or Mailcow handle email and calendar. OpenTalk or BigBlueButton cover video and presence. Univention Corporate Server or Keycloak deliver the identity backend. Operation runs in-house, at Dataport, at IONOS SE or at a municipal IT service provider. For distribution grid operators and balancing-group managers a strict separation between administrative network and grid control system is added – something that was already hard to achieve under Microsoft 365. The operationally documented reference path is described in the Schleswig-Holstein blueprint. For picking concrete providers, our categorised alternatives matrix is a quick starting point.
Cost and timeline up to 17 October 2026
For a municipal utility with 200 to 800 administrative workstations the one-time cost of a clean migration typically ranges from 150,000 to 700,000 euros, spread across 90 to 150 days. Ongoing operation of the core suite runs at 6 to 12 euros per user per month – well below the effective Microsoft 365 E3 or E5 price including compliance add-ons, sovereign-cloud surcharges and Azure connectivity fees. Anyone who cannot fully meet the 17 October 2026 deadline can agree a documented transition period with the BSI – subject to a credible plan and a pilot already in operation. Without a pilot the transition period is in practice no longer reachable.
What to do now
Three concrete steps for energy suppliers that want to be audit-ready by autumn: First, the live analysis of Microsoft 365 data flows on /en/microsoft – it makes the concrete proof gap visible in audit terms. Second, the selection of the right sovereign building blocks via the alternatives matrix and, when a compact comparison is needed, via /en/pricing. Third, an initial call via /en/contact to plan the migration and prepare the BSI proof documentation. Treating the switch as an isolated IT project will miss the deadline. Running it as a procurement, operations and evidence project together with data protection, grid operations and management leaves 2026 enough runway to move the sovereign stack cleanly into regular operation. The parallel between the hospital and the energy sector is documented in our post on the hospital NIS2 exit.
The Schleswig-Holstein blueprint – 80 percent LibreOffice migration and what German states, municipalities and SMEs can copy from it in autumn 2026
Schleswig-Holstein has migrated 80 % of its state administration to LibreOffice. What German states, municipalities and SMEs can take from the €15M blueprint now.
Microsoft 365 Copilot in law firms and tax advisory practices – why § 203 StGB and § 43e BRAO reopen the cloud question in autumn 2026
New Copilot data exports in September 2026 force law firms and tax advisors to reassess. What § 203 StGB, § 43e BRAO and § 62a StBerG really demand.