nis-2 compliance

Implement NIS-2 pragmatically


The NIS-2 directive expands on the European Union's existing cybersecurity regulations and aims to strengthen the resilience of affected companies against cyber threats. Its scope is significantly broader and its requirements are significantly stricter than those of previous regulations. This is intended to better minimize cybersecurity risks and protect critical infrastructure.

  • Certified experts and specialized lawyers
  • Proactive vulnerability analysis and effective NIS-2 compliance
  • For every size of company – from start-ups to conglomerates
ISO 9001
BvD member
GDD member
Made in Germany
20 years of experience
  • Federal Office for Information Security
  • Compliant with GDPR
  • BvD member
  • GDD member
  • Made in Germany
✓ Interdisciplinary team ✓ certified experts ✓ pragmatic implementation
NIS-2 Concern

Is my company affected by NIS-2?

Consultant

Marvin Süß

Signature Asmus Eggert

Consultant, mip Consult GmbH

The directive divides affected establishments into two main groups:

Essential entities

Among the particularly important institutions are companies from sectors such as energy, transport, banking, healthcare and digital infrastructure that exceed a certain threshold.

Important entities

Important facilities include companies from seven other sectors such as food, manufacturing, and research that exceed a certain threshold size. Additionally, companies can be considered important facilities that operate in the sectors of particularly important facilities that fall below that threshold size.

NIS2 requirements for companies

Reporting

Do not be fooled by the seemingly simple nature of NIS-2 reporting obligations deceive. Report significant incidents within 24 to 72 hours, This is a major challenge. This requires effective internal processes as well as clear governance to ensure reliable and consistent implementation. The non-fulfillment Failure to meet these requirements can lead to serious sanctions for your company.

If your organization is currently unable to report incidents within the deadlines set by NIS2, implementing this capability will be one of the biggest challenges on the path to NIS2 compliance. Key competencies are:

  • Timely detection of incidents
  • Assessment of whether they have reached the NIS2 threshold of a „significant incident“
  • Adequate understanding of the incident to issue an initial warning message
  • Detailed analysis of the incident for an initial assessment within 72 hours
  • Comprehensive investigation and resolution of the incident, implementation of additional measures, and the preparation of a complete final report within 30 days

Regardless of how mature your cybersecurity program currently is, meeting these requirements will be a challenging task. Conducting simulations for the incident reporting process can help identify existing gaps in your organization.

Risk management

NIS2 requires affected organizations to conduct a „risk assessment“ and to be able to assess the „effectiveness of risk management measures.“ Although these terms seem simple, their implications are complex.

Implementing a comprehensive and verifiable risk management framework is a major challenge. Companies must establish policies, appoint risk managers, define a uniform terminology, and ensure consistency in analysis and reporting.

A tried and tested procedure, such as the ISO recommended, is essential. However, the involvement of the entire organization is equally important. While Risk managers and risk teams professionals for measurement and Control Often, risks can only be identified by the respective departments themselves. Therefore, risk management must work closely with all departments to capture the full range of risks, for example in the following areas:

  • Procurement of new IT systems or technologies
  • Personnel and recruitment processes
  • Emergency and business continuity planning

To ensure this, the risk team or the risk manager must train all relevant employees and ensure a uniform application of terminology, assessment methods, and taxonomies.

Supply chain security

Supply chain security has been a central topic in information security in recent years – and for good reason. Many of the security incidents of recent times were caused or exacerbated by attacks on the supply chain.

The NIS1 directive did not contain a direct reference to supply chain security, and beyond basic measures, this area is often not sufficiently considered.

If your company has not previously monitored the security of its supply chain, implementing this part of NIS-2 compliance will be time-consuming and challenging.

Understanding NIS2

To address modern cybersecurity threats, NIS2 introduces several significant changes, including:

Clearer governance and oversight

Regulatory roles are defined for national authorities, and organizations are required to implement structured cybersecurity strategies.

Increased security and risk management obligations

Companies must implement stricter cybersecurity policies and adhere to established standards such as ISO 27001 or NIST CSF.

Strict reporting requirements for incidents

Organizations must report significant cybersecurity incidents within 24 to 72 hours to ensure a quick response and containment.

Stricter enforcement and sanctions

Non-compliance is subject to severe penalties of up to 10 million euros or 2 % % of global annual turnover.

Systematic disclosure of vulnerabilities

Companies are required to proactively identify and report cybersecurity vulnerabilities.

Cross-border information sharing

Cooperation between EU member states is being promoted to raise awareness of cybersecurity threats.

Consultant
Marvin Süß • Consultant

From the impact analysis
until proven otherwise
NIS-2 verification.

Non-binding · 15 minutes · Free

Frequently asked questions

Since when has NIS-2 applied in Germany?

Since December 6, 2025. On that day, the NIS-2 Implementation and Cybersecurity Strengthening Act came into effect and reshaped the BSIG.


Is my company affected by NIS-2?

The BSIG distinguishes two groups. Companies with 250 employees or more with a turnover of more than €50 million and a balance sheet total of more than €43 million are considered particularly important institutions. Companies with 50 employees or more with a turnover of more than €10 million and a balance sheet total are considered important institutions. Operators of critical installations are automatically considered part of the first group. However, size is not the only factor; the sector is also important; the installations 1 and 2 are relevant for the BSIG. Many online checks only provide general results; we conduct legal and reliable checks.


Do we have to register with the BSI?

Yes. Affected institutions must register with the BSI themselves; the authority will not notify you of the issue. The deadline for doing so was March 6, 2026, which is three months after it came into effect. Anyone who missed the deadline will have to complete the registration again. The process is two-stage: first „My Business Account,“ then the BSI reporting portal.

What deadlines apply if a security incident occurs?

Three staggered notifications: an initial notification within 24 hours, a more detailed follow-up notification within 72 hours, and a final notification within one month. These deadlines run regardless of the 72-hour deadline for data breaches under Article 33 GDPR; a single incident can trigger both.


What happens if we do not implement NIS-2?

The BSIG provides for staggered fines: up to €10 million for particularly important establishments or 2% % of the global annual turnover, up to €7 million for important establishments, or 1.4%. % In addition, there is the personal liability of the management for the company itself.


Does NIS-2 apply to us as a supplier as well?

Even organizations that are not directly affected by NIS2 could feel its effects if they are suppliers or partners of regulated companies; these companies will likely have to demonstrate which cybersecurity measures they are taking to maintain business relationships with NIS2-regulated organizations.

Other services

Information security services,
that suits your company.