NIS2 is here. We make you more ready to act.
The German NIS2 implementation act has applied since December 2025 — with no transition period. We assess whether you're affected, identify the gaps and support you pragmatically on the way to compliance. Consulting and software from one source.
Are you affected?
Sector and company size are decisive. Two categories determine the extent of your obligations.
Essential entities
Sectors of high criticality — subject to the strictest supervision and proactive checks.
Important entities
Further critical sectors — same core duties, supervision happens on cause.
What NIS2 concretely requires
Four core duties that have applied immediately since the law came into force — with no grace period.
Registration with the BSI (§ 33 BSIG)
Affected entities must apply for an ELSTER organisation certificate (MUK) and register via the BSI portal. Failure to register is a separate finable offence.
Risk management (§ 30 BSIG)
Ten mandatory measure areas: risk analysis, incident handling, backup, supply chain, access control, encryption, MFA, training and more.
Reporting duties 24/72h (§ 32 BSIG)
Significant incidents: early warning within 24 hours, report within 72 hours, final report after one month.
Management is liable
Leadership must approve, monitor and train on the measures. The company faces fines of up to €10M or 2% of turnover — management additionally faces personal liability in case of culpable breach of duty.
From scope to proof
We guide you pragmatically and by priority — technically and organisationally, without drowning you in standards.
Scope & self-check
We classify whether and in which category you fall under NIS2 — and what that means in practice.
Gap analysis
Target-actual comparison against the NIS2 requirements — with a clear, prioritised gap list.
Measure roadmap
A realistic implementation plan: what first, with what effort and what impact.
Implementation support
We help implement measures — from emergency plans and roles to reporting paths and documentation.
ISMS & ISO 27001 mapping
We use an existing ISMS as the basis and specifically address the NIS2-specific gaps.
Management training
We prepare leadership and responsible roles for their duties and liability.
How we work
From the first classification to audit-ready proof — in four steps.
Assess scope
Initial call and self-check: do you fall under NIS2, and in which category?
Gap analysis
Target-actual comparison against the requirements, prioritised gap list.
Implement
Measures, roles, reporting paths and documentation — software-supported on request.
Prove
Audit-ready documentation for the BSI and supervisors — kept continuously current.
The law applies. Waiting is no longer an option.
The NIS2 obligations have been directly binding since 6 December 2025 — with no transition period. Responsibility lies explicitly with management; mere delegation is not enough. Those who start in a structured way now reduce liability risk and effort.
No transition period
Risk management and reporting duties apply from the day the law came into force.
Management on the hook
Approval, monitoring and training are mandatory — with personal liability.
Tangible fines
Up to €10M or 2% of the company's global annual turnover.
Consulting and software from one source
We don't just document NIS2 — we make implementation digitally usable.
A continuous approach
Consulting, measures and software work hand in hand — no break between concept and operation.
Technical substance
We understand the realities of real IT environments — and build our software ourselves.
German vendor
Hosting in Germany, in line with the GDPR, short distances and personal contacts.
Frequently asked questions about NIS2
Do you have more questions? Contact us directly — we respond straightforwardly.
Clarify your NIS2 status — in an initial call
Tell us briefly what it's about. We'll get back to you personally and assess your situation.
NIS2 won't wait. Let's begin.
The law applies — with no transition period. In a free initial call we'll clarify whether you're affected and the most sensible next step.