NIS2 consulting: from scoping to implementation.
We establish whether and how your company is affected by NIS2, show the gaps against Article 21 and implement the measures with you – including the reporting process and management training.
What NIS2 means for your company
The EU's NIS2 directive significantly widens the group of companies that must meet binding cybersecurity requirements. It no longer covers only classic critical-infrastructure operators, but also many mid-sized companies in sectors such as energy, transport, health, digital services, manufacturing, waste management or food.
Entities in scope must implement appropriate risk-management measures, report significant incidents within tight deadlines and register with the competent authority. Responsibility for this rests explicitly with management. Many companies also feel NIS2 indirectly: their customers are in scope and pass the requirements down the supply chain.
Our NIS2 consulting at a glance
Six building blocks – you decide which of them you handle yourself.
Scoping assessment
Check sector, activity and size against the criteria of the directive and the German implementation act – with a written result on whether, and as which type of entity, you are in scope.
Gap analysis against Article 21
Compare your existing measures against every Article 21 requirement. You receive a prioritised gap list rather than a catalogue that treats everything as equally important.
Risk management and ISMS
Build or extend an information security management system as the framework for the NIS2 measures – certifiable to ISO 27001 if you wish.
Reporting and incident process
Responsibilities, escalation paths and reporting templates for the 24-hour, 72-hour and one-month deadlines – rehearsed before it counts and aligned with your incident response.
Supply chain and service providers
Identify critical suppliers, anchor security requirements in contracts and review them regularly – structured, not by circulating a questionnaire.
Management training
Management must approve and oversee the measures and be trained regularly. We deliver the training and the evidence for it.
How we implement NIS2 with you
Six steps that build on each other. Duration depends on size and maturity – we estimate it after the gap analysis.
Determine scope
Are you in scope, and if so as an essential or important entity? Supervision and the sanctions framework depend on it.
Gap analysis
Current state against Article 21, reporting duties and management duties. Result: a prioritised gap list with a rough effort estimate.
Registration and governance
Prepare registration with the competent authority, assign roles, have management adopt the policy.
Implement measures
Close the prioritised gaps – organisationally and technically, with your team, your providers or with us.
Rehearse reporting
Walk through a realistic incident scenario: who decides, who reports, what goes into the early warning?
Evidence and continue
Documentation, internal audit and management review, so you can show authorities, customers and insurers what you do.
Was Sie erhalten
- Written result of the scoping assessment
- Gap analysis with a prioritised action plan against Article 21
- Mapping between NIS2 requirements and existing measures (e.g. ISO 27001)
- Reporting and escalation process with templates for all deadlines
- Training records for management
- Documentation that holds up with supervisors and customers
An ISMS as the foundation
An ISMS to ISO 27001 covers a large part of Article 21 and keeps NIS2 manageable over time instead of a one-off project.
ISO 27001 consultingWhen an incident occurs
The reporting deadlines start when you become aware of the incident. Our incident response supports containment, forensics and preparing the notifications.
Incident ResponseFrequently asked questions about NIS2
- Is my company affected by NIS2?
- That depends on two questions: do you operate in one of the sectors listed in Annexes I and II of the directive – such as energy, transport, health, digital infrastructure, manufacturing of certain products, waste management or food? And do you reach the size threshold of a medium-sized enterprise (generally 50 or more employees, or annual turnover and balance sheet above EUR 10 million)? For some entities NIS2 applies regardless of size. In the scoping assessment we settle this definitively for your specific activities.
- What does NIS2 require?
- Article 21 requires appropriate technical, operational and organisational risk-management measures – including risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, vulnerability management, cryptography, access control, training and multi-factor authentication. On top of that come reporting obligations for significant incidents and registration with the competent authority.
- Which reporting deadlines apply to a security incident?
- The directive sets out a staged procedure: an early warning within 24 hours of becoming aware of a significant incident, an incident notification with an initial assessment within 72 hours and a final report within one month. For this to work in an emergency, responsibilities, templates and decision paths have to be in place beforehand.
- Is senior management personally accountable?
- NIS2 explicitly holds management bodies responsible: they must approve the risk-management measures, oversee their implementation and take part in training regularly. For breaches, the directive provides for sanctions against the entity and accountability of management. We prepare management so that it can demonstrably fulfil this role.
- Is an ISO 27001 certification enough for NIS2?
- An ISMS to ISO 27001 covers a large part of the Article 21 requirements and is a very good foundation. It does not automatically cover everything, though: reporting processes, registration, management duties and individual measures such as MFA or supply-chain security are checked separately. A mapping shows you what is already covered and where something is missing.
- What does NIS2 consulting cost?
- That depends on size, sector and your current maturity. After a free initial consultation you receive an offer with clearly defined service packages. Terms on request.
Find out whether NIS2 applies to you.
In a free initial consultation we check whether you are in scope and outline the next steps.
Get a scoping assessmentHow we work with you
We treat every engagement as a long-term partnership rather than a one-off delivery. Our approach is organised into four clear phases so that you always know what happens when, who owns which responsibility and which outcomes you can expect.
1. Free initial conversation
We learn about your starting position, your goals and the constraints you operate under. In 30 to 45 minutes we check whether our offering fits your situation, outline possible paths and answer your questions – no obligation attached.
2. Structured assessment
We capture the current state systematically – technically, organisationally and in regulatory terms. You receive a prioritised assessment that clearly names strengths, gaps and action areas and forms the basis for a robust offer.
3. Delivery with a dedicated lead
A senior lead guides you through the delivery with clear milestones, transparent effort and cost planning and a weekly status. All results are documented and remain fully owned by you.
4. Continuous operations & review
After project close, we stay alongside you in operations – via managed-service components, regular reviews, action tracking and proactive recommendations on new threats, regulatory changes or technology shifts.