30,000 companies are in scope. Management is personally liable.

NIS2: implement the EU cybersecurity directive before the BSI audits you

NIS2 is binding law in Germany: risk management under Art. 21, reporting within 24 hours, BSI registration and personal accountability of management bodies. We take you from scope assessment through gap analysis to audited implementation, pragmatic, audit-proof and integrated with your existing ISMS.

  • Applicability settled reliably: essential or important entity, with BSI-ready documentation
  • Gap analysis against all ten Art. 21 minimum measures in two to three weeks
  • Reporting processes that pass the 24-hour test: playbooks, templates, exercises
  • Management body training with attendance evidence, as required by law
  • ISO 27001 and IT-Grundschutz are credited instead of rebuilt

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

What is NIS2? Obligations, deadlines and liability at a glance

Our Strengths

  • In-depth NIS2 expertise and EU cybersecurity knowledge
  • Proven cybersecurity governance methodologies
  • Sector-specific critical infrastructure experience
  • Integrated risk management and compliance automation

The BSI has been auditing actively since 2026

The BSI registration deadline expired on 6 March 2026 and the enforcement phase is running: the BSI reviews evidence and can impose fines of up to 10 million euros or 2 percent of global turnover. Management bodies are personally accountable for implementing the risk management measures.

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

We pursue a systematic, risk-minimizing approach to NIS2 compliance that combines technical excellence with strategic governance integration.

Our Approach:

Comprehensive current-state analysis and NIS2 gap assessment

Design of tailored cybersecurity governance frameworks

Phased implementation with continuous testing

Integration into existing risk management structures

Continuous optimization and compliance monitoring

"With our NIS2 compliance framework, we transform cybersecurity governance into a genuine competitive factor. Through systematic implementation and continuous optimization, we not only ensure regulatory conformity but also lay the foundation for sustainable cyber excellence and operational resilience."
Sarah Richter

Sarah Richter

Head of Information Security, Cyber Security

Expertise & Experience:

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Our Services

We offer you tailored solutions for your digital transformation

NIS2 scope and applicability assessment

Legally sound clarification within days: does your company fall under NIS2, as an essential or important entity, and which obligations follow in concrete terms.

  • Sector and size test under the NIS2UmsuCG including group perspective
  • Classification as essential or important with BSI-ready documentation
  • Derivation of the concrete obligation catalogue per classification

Gap analysis against Art. 21

Structured baseline against the ten minimum measures: from risk analysis and incident handling to supply chain security, MFA and cryptography.

  • Maturity rating per measure based on evidence, not self-assessment
  • Reconciliation with your existing ISMS (ISO 27001, BSI IT-Grundschutz)
  • Prioritised roadmap by risk, effort and audit relevance

Implementation of security measures

Delivery with your teams: policies, processes and technology, integrated into existing structures instead of building a parallel world.

  • Measure implementation along the roadmap with clear ownership
  • ISMS integration: existing certifications are credited, not duplicated
  • Evidence documentation that withstands BSI audits

BSI registration and reporting processes

Catch up on registration, set up and rehearse reporting channels: a 24-hour early warning only works with prepared playbooks.

  • BSI registration including late registration after missed deadlines
  • 24h/72h/1M reporting process with playbooks and templates
  • Incident response exercises with your teams

Management body training

NIS2 requires demonstrable training of management bodies. We train boards and managing directors compactly, liability-focused and documented.

  • Mandatory training under the NIS2UmsuCG with attendance evidence
  • Liability scenarios and oversight duties, hands-on
  • Board reporting: the right questions to ask your own organisation

Supply chain security and provider governance

Art. 21 demands supply chain security: we build the processes for supplier assessment, contract clauses and continuous monitoring.

  • NIS2 requirement catalogue for procurement and supplier contracts
  • Assessment of critical providers including cloud
  • Connection to outsourcing and third-party risk management

Our Competencies

Choose the area that fits your requirements

NIS2 Readiness Assessment

Systematic NIS2 readiness assessment for essential and important entities: We conduct a structured gap analysis, evaluate your NIS2 maturity level, and develop a prioritized implementation roadmap for sustainable NIS2 compliance.

NIS2 Sector-Specific Requirements

The NIS2 Directive covers 18 sectors across two categories: essential and important entities. We assess whether and to what extent your organization falls under NIS2 and develop sector-specific compliance strategies tailored to your industry.

NIS2 Security Measures

Professional implementation of all required security measures according to the NIS2 directive. We develop with you a comprehensive cybersecurity strategy that optimally integrates technical, organizational, and procedural protection measures.

Frequently Asked Questions about NIS2 Consulting

What is NIS2 in simple terms?

NIS 2 is the EU directive on cybersecurity, transposed in Germany through the NIS 2 Implementation Act (NIS2UmsuCG). It obliges around 30,

000 companies from

18 sectors to run state-of-the-art risk management (Art. 21), to report security incidents to the BSI (24-hour early warning, 72-hour follow-up, one-month final report) and to register with the BSI. Management bodies are personally accountable; fines reach up to

10 million euros or

2 percent of global turnover.

Who is affected by NIS2?

Essential and important entities from

18 sectors, including energy, transport, banking, healthcare, water, digital infrastructure, IT service providers, public administration, postal services, waste, chemicals, food, manufacturing and research. As a rule of thumb: from

50 employees or

10 million euros in turnover in one of the sectors. Smaller companies can also be pulled into scope contractually as suppliers of affected customers. Our scope assessment settles applicability reliably.

Which deadlines apply under NIS2 in Germany?

The NIS2UmsuCG is in force; the BSI registration deadline expired on

6 March 2026, and late registrants should act immediately. The reporting obligations apply continuously: early warning within

24 hours of becoming aware of a significant incident, follow-up within

72 hours, final report within one month. The BSI has been actively auditing the Art.

21 measures since 2026; there is no transition period.

Which 18 sectors fall under NIS2?

Annex I (sectors of high criticality): energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space. Annex II (other critical sectors): postal and courier services, waste management, chemicals, food, manufacturing (including medical devices, electronics, machinery and vehicles), digital providers and research. Annex I companies from

250 employees generally count as essential entities; smaller and Annex II companies as important entities.

Am I affected by NIS2? The quick check.

Three questions settle the first assessment: First, does your company belong to one of the

18 sectors in Annex I or II? Second, do you have

50 or more employees or more than

10 million euros in annual turnover? Third, are you an operator of critical facilities, a qualified trust service provider or a TLD registry (NIS 2 then applies regardless of size)? Two yes answers mean: very likely in scope. And even with three no answers, customer contracts can pass NIS 2 requirements down your supply chain. Our scope assessment delivers the legally reliable classification including BSI documentation.

What does NIS2 specifically require from management?

Three non-delegable duties: First, management bodies must approve the Art.

21 risk management measures themselves and monitor their implementation. Second, they must attend regular cybersecurity training and be able to prove it. Third, they are personally liable for breaches of duty. For CISOs this means establishing reporting lines to management, delivering board-ready risk reports and organising the training obligation. Compliance officers anchor NIS 2 in the internal control system and in supplier governance.

What does NIS2 mean for suppliers that are not regulated themselves?

Art.

21 obliges regulated companies to secure their supply chain. In practice they pass the requirements on contractually: security evidence, audit rights, incident notification duties, sometimes certifications. Suppliers of essential or important entities will therefore have to meet NIS 2 requirements without being in scope themselves. Proactive preparation becomes a sales argument: those who can provide evidence win tenders against unprepared competitors.

Success Stories

Discover how we support companies in their digital transformation

Digitalization in Steel Trading

Steel trading company from Germany

Digital Transformation in Steel Trading

Case Study

Results

Over 2 billion euros in annual revenue through digital channels
More than half of revenue through online channels as a strategic goal
Improved customer satisfaction through automated processes

AI-Powered Manufacturing Optimization

Industrial group from Germany

Smart Manufacturing Solutions for Maximum Value Creation

Case Study

Results

Significant increase in production performance
Reduction of downtime and production costs
Improved sustainability through more efficient resource utilization

AI Automation in Production

Automation specialist from Germany

Intelligent Networking for Future-Proof Production Systems

Case Study

Results

Improved production speed and flexibility
Reduced manufacturing costs through more efficient resource utilization
Increased customer satisfaction through personalized products

Generative AI in Manufacturing

Technology group from Germany

AI Process Optimization for Improved Production Efficiency

Case Study

Results

Reduction of AI application implementation time to just a few weeks
Improvement in product quality through early defect detection
Increased manufacturing efficiency through reduced downtime

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance