NIS2 Consulting for Companies
Since December 2025, NIS2 has been German law (NIS2UmsuCG). Around 30,000 companies must protect themselves against data breaches, ransomware, phishing attacks, insider threats and DDoS attacks — with fines of up to EUR 10 million and personal liability for managing directors under Section 38 BSIG. We guide you from the applicability assessment through penetration testing to full NIS2 compliance.
Why NIS2 Consulting?
Protect your company from fines and liability risks
Applicability Assessment
Clarifying whether NIS2 applies to your company: from 50 employees or EUR 10 million turnover across 18 sectors. The NIS2 Implementation Act clearly defines the thresholds — we verify your exact classification as an 'essential' or 'important' entity in accordance with Section 28 BSIG.
Fine Protection up to EUR 10 Million
Avoid fines of up to EUR 10 million or 2% of global annual turnover through timely NIS2 compliance. 'Important entities' face fines of up to EUR 7 million or 1.4% of turnover. The deadline has already passed — act now.
Safeguard Management Liability
NIS2 provides for personal liability of the management (Section 38 BSIG). Managing directors must oversee the implementation of risk management measures and take part in cybersecurity training. We document your compliance completely.
Penetration Testing
A NIS2 obligation under Section 30 BSIG: regular security tests for web applications, networks, APIs and mobile applications by certified experts. We identify vulnerabilities before attackers do — with a detailed report and action plan.
Set Up the 24h Reporting Obligation
Section 32 BSIG requires: an initial report to the BSI within 24 hours, a detailed report within 72 hours and a final report within one month. We establish your complete incident response process with clear roles, communication channels and templates for the BSI report.
Systematic Risk Management
Systematic risk assessment and action plan under Section 30 BSIG — the foundation of your NIS2 compliance. We identify, evaluate and prioritise your IT risks and create a documented treatment plan with concrete measures and timelines.
ISMS Setup (ISO 27001)
An Information Security Management System (ISMS) in accordance with ISO 27001 is the ideal foundation for NIS2 compliance. We support you in building or extending your ISMS — from policy development through risk assessment to certification preparation.
BSI Registration
Affected companies must register with the BSI and designate a point of contact. We handle the complete registration, document your reporting channels and ensure that all deadlines are met.
Cyber Hygiene & Training
NIS2 requires verifiable cybersecurity training for managing directors and employees (Section 38 BSIG). We offer phishing simulations, security awareness training and management workshops — documented and audit-ready.
NIS2 Compliance at a Glance
Compliance Documentation
Risk Assessment & Audit
Full Control over Your NIS2 Compliance
From the applicability assessment through gap analysis to complete BSI registration — our dashboard gives you an overview at all times. Fines of up to EUR 10 million and personal liability for managing directors are avoidable.
Our NIS2 Services
From gap analysis to full compliance under Section 30 BSIG
NIS2 Gap Analysis
A current-vs-target comparison of your IT security against the NIS2 requirements (Section 30 BSIG). You receive a detailed action plan with prioritisation, timeline and cost estimate for every identified gap.
Applicability Analysis under the NIS2 Implementation Act
A detailed review of whether and which NIS2 obligations apply to your company — including sector assignment under Annexes I/II of the EU Directive and classification as an 'essential' or 'important' entity (Section 28 BSIG).
Penetration Testing under Section 30 BSIG
Web, network and API pentests — legally required under NIS2 for regular vulnerability analysis. We use OWASP Top 10, PTES and OSSTMM as frameworks. Detailed report with CVSS scoring.
Risk Assessment under Section 30 BSIG
Systematic risk management with documented assessment and treatment plan. Based on BSI baseline protection (IT-Grundschutz) or ISO 27005 — tailored to your company size and industry requirements.
Incident Response Plan (Section 32 BSIG)
A complete reporting process: 24h initial report, 72h detailed report and final report to the BSI. Including role assignment, escalation paths, communication templates and regular incident response exercises.
Supply Chain Security (Section 30 (2) No. 4)
Supply chain security for NIS2 compliance: assessment and protection of your suppliers and service providers. Contractual safeguards, regular security reviews and risk assessment across the entire value chain.
Security Awareness (Section 38 BSIG)
Management and employee training — NIS2 requires verifiable cybersecurity training. Including phishing simulations, social engineering tests and individual training plans.
Compliance Documentation & Audit
ISMS setup, complete evidence documentation and audit preparation for the BSI review. All policies, guidelines and records structured and verifiable at any time — including for external auditors.
Business Continuity Management
Section 30 BSIG requires measures to maintain operations. We create BCM plans, define recovery times (RTO/RPO), implement backup strategies and carry out regular recovery tests.
Cryptography & Encryption
NIS2 requires the use of cryptography (Section 30 (2) No. 7). We review and implement encryption concepts for data at rest, in transit and during processing. Including a key management strategy.
The Most Important NIS2 Provisions
What the NIS2 Implementation Act specifically requires from your company
Section 28 BSIG — Classification of Entities
The NIS2 Implementation Act distinguishes between 'essential entities' (essential sectors, from 250 employees or EUR 50 million) and 'important entities' (important sectors, from 50 employees or EUR 10 million). The classification determines the scope of obligations and the level of possible fines.
Section 30 BSIG — Risk Management Measures
The core of the NIS2 obligations: risk analysis, security measures, incident handling, business continuity, supply chain security, vulnerability management, cyber hygiene, cryptography, access control and multi-factor authentication. All measures must be proportionate.
Section 32 BSIG — Reporting Obligations
In the event of significant security incidents: 24 hours for the initial report, 72 hours for the detailed report and a maximum of one month for the final report. Reporting is submitted to the BSI via an electronic reporting system. Late reports can themselves trigger fines.
Section 38 BSIG — Management Duties
Managing directors must approve the implementation of the risk management measures, oversee their implementation and take part in cybersecurity training. If they breach these duties, they are personally liable. This liability cannot be removed through delegation.
Are You Affected by NIS2?
Check for free in 4 steps whether your company falls under the NIS2 Directive.
Start the Free NIS2 CheckVerwandte Leistungen
Passende Services, die Ihr Vorhaben ergänzen
Ready for the next step?
Let's discuss in a free initial consultation how we can move your business forward.


