In force since 12/2025NIS2 consulting & implementation

NIS2 is here. We make you more ready to act.

The German NIS2 implementation act has applied since December 2025 — with no transition period. We assess whether you're affected, identify the gaps and support you pragmatically on the way to compliance. Consulting and software from one source.

NIS2 self-check
Free initial consultationConsulting & software from one sourceBased in Düsseldorf
NIS2 self-check
12 of 18 measures met
62%Maturity
Risk management (§30)
Reporting process 24/72h
Backup & emergency plan
Supply-chain security
MFA & access control
BSI registration open
Classification: important entity
Since 06.12.2025
in force — no transition period
~29,500
affected companies in Germany (BSI estimate)
18 sectors
from energy to manufacturing
up to €10M
fine, or 2% of turnover
Are you affected?

Are you affected?

Sector and company size are decisive. Two categories determine the extent of your obligations.

Essential entities

From 250 employees
or
> €50M turnover + > €43M balance sheet total

Sectors of high criticality — subject to the strictest supervision and proactive checks.

Size-independent incl.: DNS, TLD, qualified trust services, telecom providers, critical infrastructure.

Important entities

From 50 employees
or
> €10M turnover + > €10M balance sheet total

Further critical sectors — same core duties, supervision happens on cause.

Many SMEs now fall under the regulation for the first time.
Affected sectors (excerpt)
EnergyTransportBanking & financeHealthWater & wastewaterDigital infrastructureICT servicesPublic administrationPost & courierWaste managementChemicalsFoodManufacturingDigital providersResearch
The obligations

What NIS2 concretely requires

Four core duties that have applied immediately since the law came into force — with no grace period.

Registration with the BSI (§ 33 BSIG)

Affected entities must apply for an ELSTER organisation certificate (MUK) and register via the BSI portal. Failure to register is a separate finable offence.

Risk management (§ 30 BSIG)

Ten mandatory measure areas: risk analysis, incident handling, backup, supply chain, access control, encryption, MFA, training and more.

Reporting duties 24/72h (§ 32 BSIG)

Significant incidents: early warning within 24 hours, report within 72 hours, final report after one month.

Management is liable

Leadership must approve, monitor and train on the measures. The company faces fines of up to €10M or 2% of turnover — management additionally faces personal liability in case of culpable breach of duty.

What we do

From scope to proof

We guide you pragmatically and by priority — technically and organisationally, without drowning you in standards.

Scope & self-check

We classify whether and in which category you fall under NIS2 — and what that means in practice.

Gap analysis

Target-actual comparison against the NIS2 requirements — with a clear, prioritised gap list.

Measure roadmap

A realistic implementation plan: what first, with what effort and what impact.

Implementation support

We help implement measures — from emergency plans and roles to reporting paths and documentation.

ISMS & ISO 27001 mapping

We use an existing ISMS as the basis and specifically address the NIS2-specific gaps.

Management training

We prepare leadership and responsible roles for their duties and liability.

How we work

From the first classification to audit-ready proof — in four steps.

1

Assess scope

Initial call and self-check: do you fall under NIS2, and in which category?

2

Gap analysis

Target-actual comparison against the requirements, prioritised gap list.

3

Implement

Measures, roles, reporting paths and documentation — software-supported on request.

4

Prove

Audit-ready documentation for the BSI and supervisors — kept continuously current.

Why now

The law applies. Waiting is no longer an option.

The NIS2 obligations have been directly binding since 6 December 2025 — with no transition period. Responsibility lies explicitly with management; mere delegation is not enough. Those who start in a structured way now reduce liability risk and effort.

No transition period

Risk management and reporting duties apply from the day the law came into force.

Management on the hook

Approval, monitoring and training are mandatory — with personal liability.

Tangible fines

Up to €10M or 2% of the company's global annual turnover.

Why NICA

Consulting and software from one source

We don't just document NIS2 — we make implementation digitally usable.

A continuous approach

Consulting, measures and software work hand in hand — no break between concept and operation.

Technical substance

We understand the realities of real IT environments — and build our software ourselves.

German vendor

Hosting in Germany, in line with the GDPR, short distances and personal contacts.

FAQ

Frequently asked questions about NIS2

Do you have more questions? Contact us directly — we respond straightforwardly.

The German NIS2 implementation act (NIS2UmsuCG) came into force on 6 December 2025 and has been legally binding since. There is no transition period for implementing the security measures — the obligations apply immediately.
Sector and company size are decisive. Essential entities are generally affected from 250 employees or an annual turnover and balance sheet total of more than €50M and €43M respectively, important entities from 50 employees or more than €10M in annual turnover and balance sheet total. In the scope assessment we classify your case specifically.
Three at the core: registration with the BSI, implementation of risk-management measures (§30 BSIG) and reporting of significant incidents (24-hour early warning, 72-hour report, final report after one month). On top of that comes management accountability.
Yes. Management must approve and monitor the risk-management measures and undergo training. They can be held personally liable for violations. Fines reach up to €10M or 2% of global annual turnover.
An ISMS to ISO 27001 already covers a large part of the NIS2 requirements. We specifically add the remaining points — BSI registration, the tiered reporting process and management duties.
No. We focus on technical and organisational implementation — gap analysis, measures, documentation and software. We clarify detailed legal questions on request together with your lawyers or our partners.
It begins with a no-obligation initial call and a scope assessment. A first gap analysis delivers a clear priority list within a few weeks.
Yes. Consulting and software come from one source: emergency planning, awareness training and policy management can be made digitally usable right away — and produce the proof along the way.
Contact

Clarify your NIS2 status — in an initial call

Tell us briefly what it's about. We'll get back to you personally and assess your situation.

Email
[email protected]
+49 211 17520849
Mon–Fri 9:00 – 16:00
Nica Software GmbH
Reisholzer Bahnstraße 41, Düsseldorf
Request a consultation

NIS2 won't wait. Let's begin.

The law applies — with no transition period. In a free initial call we'll clarify whether you're affected and the most sensible next step.

Free initial consultation • Pragmatic implementation • Consulting & software from one source