NIS2: implement the EU cybersecurity directive before the BSI audits you
NIS2 is binding law in Germany: risk management under Art. 21, reporting within 24 hours, BSI registration and personal accountability of management bodies. We take you from scope assessment through gap analysis to audited implementation, pragmatic, audit-proof and integrated with your existing ISMS.
- ✓Applicability settled reliably: essential or important entity, with BSI-ready documentation
- ✓Gap analysis against all ten Art. 21 minimum measures in two to three weeks
- ✓Reporting processes that pass the 24-hour test: playbooks, templates, exercises
- ✓Management body training with attendance evidence, as required by law
- ✓ISO 27001 and IT-Grundschutz are credited instead of rebuilt
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
- Your strategic goals and objectives
- Desired business outcomes and ROI
- Steps already taken
Or contact us directly:
Certifications, Partners and more...










What is NIS2? Obligations, deadlines and liability at a glance
Our Strengths
- In-depth NIS2 expertise and EU cybersecurity knowledge
- Proven cybersecurity governance methodologies
- Sector-specific critical infrastructure experience
- Integrated risk management and compliance automation
The BSI has been auditing actively since 2026
The BSI registration deadline expired on 6 March 2026 and the enforcement phase is running: the BSI reviews evidence and can impose fines of up to 10 million euros or 2 percent of global turnover. Management bodies are personally accountable for implementing the risk management measures.
ADVISORI in Numbers
11+
Years of Experience
120+
Employees
520+
Projects
We pursue a systematic, risk-minimizing approach to NIS2 compliance that combines technical excellence with strategic governance integration.
Our Approach:
Comprehensive current-state analysis and NIS2 gap assessment
Design of tailored cybersecurity governance frameworks
Phased implementation with continuous testing
Integration into existing risk management structures
Continuous optimization and compliance monitoring
"With our NIS2 compliance framework, we transform cybersecurity governance into a genuine competitive factor. Through systematic implementation and continuous optimization, we not only ensure regulatory conformity but also lay the foundation for sustainable cyber excellence and operational resilience."

Sarah Richter
Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
Our Services
We offer you tailored solutions for your digital transformation
NIS2 scope and applicability assessment
Legally sound clarification within days: does your company fall under NIS2, as an essential or important entity, and which obligations follow in concrete terms.
- Sector and size test under the NIS2UmsuCG including group perspective
- Classification as essential or important with BSI-ready documentation
- Derivation of the concrete obligation catalogue per classification
Gap analysis against Art. 21
Structured baseline against the ten minimum measures: from risk analysis and incident handling to supply chain security, MFA and cryptography.
- Maturity rating per measure based on evidence, not self-assessment
- Reconciliation with your existing ISMS (ISO 27001, BSI IT-Grundschutz)
- Prioritised roadmap by risk, effort and audit relevance
Implementation of security measures
Delivery with your teams: policies, processes and technology, integrated into existing structures instead of building a parallel world.
- Measure implementation along the roadmap with clear ownership
- ISMS integration: existing certifications are credited, not duplicated
- Evidence documentation that withstands BSI audits
BSI registration and reporting processes
Catch up on registration, set up and rehearse reporting channels: a 24-hour early warning only works with prepared playbooks.
- BSI registration including late registration after missed deadlines
- 24h/72h/1M reporting process with playbooks and templates
- Incident response exercises with your teams
Management body training
NIS2 requires demonstrable training of management bodies. We train boards and managing directors compactly, liability-focused and documented.
- Mandatory training under the NIS2UmsuCG with attendance evidence
- Liability scenarios and oversight duties, hands-on
- Board reporting: the right questions to ask your own organisation
Supply chain security and provider governance
Art. 21 demands supply chain security: we build the processes for supplier assessment, contract clauses and continuous monitoring.
- NIS2 requirement catalogue for procurement and supplier contracts
- Assessment of critical providers including cloud
- Connection to outsourcing and third-party risk management
Our Competencies
Choose the area that fits your requirements
Systematic NIS2 readiness assessment for essential and important entities: We conduct a structured gap analysis, evaluate your NIS2 maturity level, and develop a prioritized implementation roadmap for sustainable NIS2 compliance.
The NIS2 Directive covers 18 sectors across two categories: essential and important entities. We assess whether and to what extent your organization falls under NIS2 and develop sector-specific compliance strategies tailored to your industry.
Professional implementation of all required security measures according to the NIS2 directive. We develop with you a comprehensive cybersecurity strategy that optimally integrates technical, organizational, and procedural protection measures.
More Services in Regulatory Compliance Management
Frequently Asked Questions about NIS2 Consulting
What is NIS2 in simple terms?
NIS 2 is the EU directive on cybersecurity, transposed in Germany through the NIS 2 Implementation Act (NIS2UmsuCG). It obliges around 30,
000 companies from
18 sectors to run state-of-the-art risk management (Art. 21), to report security incidents to the BSI (24-hour early warning, 72-hour follow-up, one-month final report) and to register with the BSI. Management bodies are personally accountable; fines reach up to
10 million euros or
2 percent of global turnover.
Who is affected by NIS2?
Essential and important entities from
18 sectors, including energy, transport, banking, healthcare, water, digital infrastructure, IT service providers, public administration, postal services, waste, chemicals, food, manufacturing and research. As a rule of thumb: from
50 employees or
10 million euros in turnover in one of the sectors. Smaller companies can also be pulled into scope contractually as suppliers of affected customers. Our scope assessment settles applicability reliably.
Which deadlines apply under NIS2 in Germany?
The NIS2UmsuCG is in force; the BSI registration deadline expired on
6 March 2026, and late registrants should act immediately. The reporting obligations apply continuously: early warning within
24 hours of becoming aware of a significant incident, follow-up within
72 hours, final report within one month. The BSI has been actively auditing the Art.
21 measures since 2026; there is no transition period.
Which 18 sectors fall under NIS2?
Annex I (sectors of high criticality): energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space. Annex II (other critical sectors): postal and courier services, waste management, chemicals, food, manufacturing (including medical devices, electronics, machinery and vehicles), digital providers and research. Annex I companies from
250 employees generally count as essential entities; smaller and Annex II companies as important entities.
Am I affected by NIS2? The quick check.
Three questions settle the first assessment: First, does your company belong to one of the
18 sectors in Annex I or II? Second, do you have
50 or more employees or more than
10 million euros in annual turnover? Third, are you an operator of critical facilities, a qualified trust service provider or a TLD registry (NIS 2 then applies regardless of size)? Two yes answers mean: very likely in scope. And even with three no answers, customer contracts can pass NIS 2 requirements down your supply chain. Our scope assessment delivers the legally reliable classification including BSI documentation.
What does NIS2 specifically require from management?
Three non-delegable duties: First, management bodies must approve the Art.
21 risk management measures themselves and monitor their implementation. Second, they must attend regular cybersecurity training and be able to prove it. Third, they are personally liable for breaches of duty. For CISOs this means establishing reporting lines to management, delivering board-ready risk reports and organising the training obligation. Compliance officers anchor NIS 2 in the internal control system and in supplier governance.
What does NIS2 mean for suppliers that are not regulated themselves?
Art.
21 obliges regulated companies to secure their supply chain. In practice they pass the requirements on contractually: security evidence, audit rights, incident notification duties, sometimes certifications. Suppliers of essential or important entities will therefore have to meet NIS 2 requirements without being in scope themselves. Proactive preparation becomes a sales argument: those who can provide evidence win tenders against unprepared competitors.
Success Stories
Discover how we support companies in their digital transformation
Digitalization in Steel Trading
Steel trading company from Germany
Digital Transformation in Steel Trading
Results
AI-Powered Manufacturing Optimization
Industrial group from Germany
Smart Manufacturing Solutions for Maximum Value Creation
Results
AI Automation in Production
Automation specialist from Germany
Intelligent Networking for Future-Proof Production Systems
Results
Generative AI in Manufacturing
Technology group from Germany
AI Process Optimization for Improved Production Efficiency
Results
Let's
Work Together!
Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
Ready for the next step?
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
Prefer direct contact?
Direct hotline for decision-makers
Strategic inquiries via email
Detailed Project Inquiry
For complex inquiries or if you want to provide specific information in advance