Skip to content
IT Security Management Systeme
NIS2 · Article 21 · Reporting duties

NIS2 consulting: from scoping to implementation.

We establish whether and how your company is affected by NIS2, show the gaps against Article 21 and implement the measures with you – including the reporting process and management training.

24 h
Early warning for significant incidents
72 h
Notification with initial assessment
Art. 21
Risk-management measures
Art. 20
Duties of management bodies

What NIS2 means for your company

The EU's NIS2 directive significantly widens the group of companies that must meet binding cybersecurity requirements. It no longer covers only classic critical-infrastructure operators, but also many mid-sized companies in sectors such as energy, transport, health, digital services, manufacturing, waste management or food.

Entities in scope must implement appropriate risk-management measures, report significant incidents within tight deadlines and register with the competent authority. Responsibility for this rests explicitly with management. Many companies also feel NIS2 indirectly: their customers are in scope and pass the requirements down the supply chain.

Our NIS2 consulting at a glance

Six building blocks – you decide which of them you handle yourself.

Scoping assessment

Check sector, activity and size against the criteria of the directive and the German implementation act – with a written result on whether, and as which type of entity, you are in scope.

Gap analysis against Article 21

Compare your existing measures against every Article 21 requirement. You receive a prioritised gap list rather than a catalogue that treats everything as equally important.

Risk management and ISMS

Build or extend an information security management system as the framework for the NIS2 measures – certifiable to ISO 27001 if you wish.

Reporting and incident process

Responsibilities, escalation paths and reporting templates for the 24-hour, 72-hour and one-month deadlines – rehearsed before it counts and aligned with your incident response.

Supply chain and service providers

Identify critical suppliers, anchor security requirements in contracts and review them regularly – structured, not by circulating a questionnaire.

Management training

Management must approve and oversee the measures and be trained regularly. We deliver the training and the evidence for it.

How we implement NIS2 with you

Six steps that build on each other. Duration depends on size and maturity – we estimate it after the gap analysis.

01

Determine scope

Are you in scope, and if so as an essential or important entity? Supervision and the sanctions framework depend on it.

02

Gap analysis

Current state against Article 21, reporting duties and management duties. Result: a prioritised gap list with a rough effort estimate.

03

Registration and governance

Prepare registration with the competent authority, assign roles, have management adopt the policy.

04

Implement measures

Close the prioritised gaps – organisationally and technically, with your team, your providers or with us.

05

Rehearse reporting

Walk through a realistic incident scenario: who decides, who reports, what goes into the early warning?

06

Evidence and continue

Documentation, internal audit and management review, so you can show authorities, customers and insurers what you do.

Was Sie erhalten

  • Written result of the scoping assessment
  • Gap analysis with a prioritised action plan against Article 21
  • Mapping between NIS2 requirements and existing measures (e.g. ISO 27001)
  • Reporting and escalation process with templates for all deadlines
  • Training records for management
  • Documentation that holds up with supervisors and customers

An ISMS as the foundation

An ISMS to ISO 27001 covers a large part of Article 21 and keeps NIS2 manageable over time instead of a one-off project.

ISO 27001 consulting

When an incident occurs

The reporting deadlines start when you become aware of the incident. Our incident response supports containment, forensics and preparing the notifications.

Incident Response

Frequently asked questions about NIS2

Is my company affected by NIS2?
That depends on two questions: do you operate in one of the sectors listed in Annexes I and II of the directive – such as energy, transport, health, digital infrastructure, manufacturing of certain products, waste management or food? And do you reach the size threshold of a medium-sized enterprise (generally 50 or more employees, or annual turnover and balance sheet above EUR 10 million)? For some entities NIS2 applies regardless of size. In the scoping assessment we settle this definitively for your specific activities.
What does NIS2 require?
Article 21 requires appropriate technical, operational and organisational risk-management measures – including risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, vulnerability management, cryptography, access control, training and multi-factor authentication. On top of that come reporting obligations for significant incidents and registration with the competent authority.
Which reporting deadlines apply to a security incident?
The directive sets out a staged procedure: an early warning within 24 hours of becoming aware of a significant incident, an incident notification with an initial assessment within 72 hours and a final report within one month. For this to work in an emergency, responsibilities, templates and decision paths have to be in place beforehand.
Is senior management personally accountable?
NIS2 explicitly holds management bodies responsible: they must approve the risk-management measures, oversee their implementation and take part in training regularly. For breaches, the directive provides for sanctions against the entity and accountability of management. We prepare management so that it can demonstrably fulfil this role.
Is an ISO 27001 certification enough for NIS2?
An ISMS to ISO 27001 covers a large part of the Article 21 requirements and is a very good foundation. It does not automatically cover everything, though: reporting processes, registration, management duties and individual measures such as MFA or supply-chain security are checked separately. A mapping shows you what is already covered and where something is missing.
What does NIS2 consulting cost?
That depends on size, sector and your current maturity. After a free initial consultation you receive an offer with clearly defined service packages. Terms on request.

Find out whether NIS2 applies to you.

In a free initial consultation we check whether you are in scope and outline the next steps.

Get a scoping assessment

How we work with you

We treat every engagement as a long-term partnership rather than a one-off delivery. Our approach is organised into four clear phases so that you always know what happens when, who owns which responsibility and which outcomes you can expect.

1. Free initial conversation

We learn about your starting position, your goals and the constraints you operate under. In 30 to 45 minutes we check whether our offering fits your situation, outline possible paths and answer your questions – no obligation attached.

2. Structured assessment

We capture the current state systematically – technically, organisationally and in regulatory terms. You receive a prioritised assessment that clearly names strengths, gaps and action areas and forms the basis for a robust offer.

3. Delivery with a dedicated lead

A senior lead guides you through the delivery with clear milestones, transparent effort and cost planning and a weekly status. All results are documented and remain fully owned by you.

4. Continuous operations & review

After project close, we stay alongside you in operations – via managed-service components, regular reviews, action tracking and proactive recommendations on new threats, regulatory changes or technology shifts.