Back to the blog
NIS2 & law

NIS2 hits the mid-market: what to do now

Many companies are covered by a cyber-security directive for the first time — often without knowing it. A clear five-step roadmap out of the uncertainty.

With NIS2, the EU drastically widens the circle of regulated companies. Suddenly it's not only large corporations and classic critical-infrastructure operators who are obliged, but also many mid-sized suppliers, service providers and manufacturers. The uncomfortable truth: most of those affected don't yet know they're meant.

Am I even affected?

What matters is sector, company size and turnover. If you operate in one of the “important” or “essential” sectors and exceed the thresholds, you're obliged — whether or not the word “critical infrastructure” was ever mentioned. As a supplier to an affected company you're drawn in via supply-chain requirements too.

NIS2 is not a pure IT task. The directive explicitly holds management accountable.

The five steps out of uncertainty

  1. Clarify exposure: assess sector, size and supply-chain links in a structured way — not by gut feeling.
  2. Gap analysis: mirror the current state against the requirements (risk management, reporting paths, continuity).
  3. Prioritise measures: start with the gaps that carry the biggest risk and the shortest deadline.
  4. Build continuity provisioning: document reporting processes, emergency plans and responsibilities — and rehearse them.
  5. Secure evidence: document everything in a fully traceable way so you can prove it to authorities and customers.

Waiting is the most expensive option

Experience shows: organisations that start early and structured need less external help and avoid last-minute panic. The first step is unspectacular but decisive — clarity about your own exposure. That's exactly what our free self-check is for.

NICA

Related from our offering

See NIS2 consulting

Turn knowledge into readiness.

Talk to us about NIS2, continuity provisioning or an awareness programme — consulting and software from one source.

Hosted in Germany • In line with the GDPR • a personal contact