NIS2 Consulting

Statutory obligation, practically implemented. The NIS2 Implementation Act has been in force in Germany since December 6, 2025, without a transition period. Approximately 29,500 companies fall under its scope—significantly more than under previous IT security legislation. With our NIS2 consulting, we clarify your applicability, bring you up to the required standard, and guide you through registration, risk management, and reporting obligations.

Request consultationAll consulting services

NIS2
Compliance

Legal Obligation

Legal Basis

NIS2UmsuCG

In Force Since

December 6, 2025

Affected Companies

approx. 29,500

Fines

up to €10M or 2% of annual turnover

Important Notice

The three-month registration deadline with the BSI ended on March 6, 2026. This deadline has therefore passed. Companies that have not yet registered remain legally obligated to do so, and failure to register constitutes an independent fineable offense, regardless of whether a security incident occurs. Late registration is possible and urgently recommended.

Whether You Fall Under NIS2

Classification depends on two factors: sector and company size.

Sectors
The law distinguishes 18 sectors, including energy, water, manufacturing, mechanical engineering, food production, pharmaceuticals, digital infrastructure, transport, healthcare, and waste management. Suppliers and service providers in these sectors can also be affected, not just the core entities themselves.

Size Categories
As a general guideline, companies with 50 or more employees or €10 million or more in annual turnover within an affected sector are classified as “important” or “essential” entities. For certain sectors and special cases, different thresholds apply regardless of size.

Why It Is Not Obvious
Studies indicate that a significant proportion of companies underestimate their applicability, especially as suppliers or service providers to an affected sector. While initial orientation is possible using the BSI NIS2 Checker, the result is non-binding. A reliable determination requires an individual analysis of your specific business model.

What NIS2 Specifically Requires

The law does not mandate a specific certification, but requires “appropriate, effective, and proportionate” technical and organizational measures aligned with the state of the art. In practice, this means:

  • Registration with the BSI via the reporting and notification portal as soon as applicability is determined.
  • Risk Management Measures across multiple core areas: including policies for risk analysis, incident handling, business continuity, supply chain security, access control, and cryptography.
  • Reporting Obligations for significant security incidents, tiered and governed by very tight deadlines.
  • Management Responsibilities, including personal liability for breaches of supervisory and implementation duties. Executive leadership must approve risk management measures and monitor their implementation.
  • Documentation and Audit Obligations, such as in the context of BSI inquiries and audits.

When a Security Incident Occurs

In the event of a significant security incident, a multi-stage, strictly timed process applies:

  • Early Warning within 24 hours of becoming aware of the incident.
  • Incident Notification with initial assessment within 72 hours.
  • Final Report no later than one month after the notification.

These deadlines apply regardless of whether technical remediation is still underway. If you require operational assistance during an active incident, please refer to our Incident Response service. NIS2 consulting ensures that processes and responsibilities are firmly established beforehand.

When You Should Act Now

  • You are unsure whether your organization counts among the approximately 29,500 affected entities.
  • The registration deadline has already passed and you have not yet registered.
  • A customer in an affected sector requires proof of your security measures as a supplier.
  • Security measures exist, but no one has evaluated them against the specific statutory requirements.
  • Executive leadership seeks clarity regarding personal obligations and liability risks arising from the law.
  • Incident reporting processes are missing or not structured to meet tight legal deadlines.

How We Support You

Applicability Assessment: Reliable assessment of whether and in which category you fall under the legislation
Registration Support: Assistance with BSI registration, even after the initial deadline has expired
Gap Analysis: Comparison of your existing security measures against the requirements of £30 NIS2UmsuCG
Measure Implementation: Prioritized action plan to close identified gaps across required core areas
Incident Reporting Process: Well-defined workflow to ensure adherence to tiered incident notification deadlines
Executive Training: Clear guidance on personal responsibilities and liability risks for company leadership
Audit Readiness: Structured preparation for potential audits and inquiries by the BSI

NIS2 and Other Frameworks

NIS2 is a statutory obligation, not a voluntary standard, and does not require its own certification. In practice, ISO 27001 is the most established way to demonstrate required measures systematically, alongside BSI IT-Grundschutz. Organizations already operating under one of these frameworks typically satisfy a large portion of NIS2 requirements.

In addition, the Critical Entities Resilience Umbrella Act (KRITIS-Dachgesetz), effective March 17, 2026, establishes physical resilience requirements for operators of critical facilities. We assess whether this applies to your organization during the same consultation.

How the Consultation Process Works

1

Applicability Assessment

We determine based on your business model whether and under which entity category you fall under NIS2.

2

Registration

If not yet completed, we guide you through the registration with the BSI, even after the initial deadline.

3

Gap Analysis

Benchmarking your existing measures against legal requirements, complete with a prioritized roadmap.

4

Implementation & Reporting Workflow

Guidance during implementation and establishing a workflow capable of meeting strict statutory reporting deadlines in an incident.

NIS2 Consulting

Clarify your applicability with us first. In an initial consultation, we structure obligations, deadlines, and next steps.

  • Reliable applicability assessment
  • Registration with the BSI, including late filing
  • Gap analysis against §30 NIS2UmsuCG
  • Incident workflow for 24/72-hour deadlines

Frequently Asked Questions

What clients want to know beforehand.

No. The legal obligation to register continues regardless of the elapsed deadline, and late registration is explicitly permitted. However, the longer it is delayed, the greater the risk of administrative penalties.

The BSI NIS2 Checker provides initial non-binding guidance. A definitive determination requires examining your specific business model, which we clarify during an initial consultation.

A large portion of requirements overlaps, but certification does not automatically replace legal applicability verification and BSI registration. We evaluate your exact coverage.

The law establishes direct duties and liability risks for company leadership regarding violations of supervisory and implementation obligations. While case-by-case legal assessments remain with your legal counsel, we structure the technical and organizational requirements.

This can also trigger direct applicability or introduce stringent contractual obligations from your client. We assess this together.