/assets/images/d/three-young-people-chatting-standing-in-office-2025-03-09-02-10-50-utc-fssc2hv08mak5k9.jpg

NIS-2 Compliance: Legally Compliant Implementation & Protection against Liability Risks

Protect your business against severe regulatory sanctions and personal liability risks. With our practical NIS-2 consulting, we determine whether your company is affected, close security gaps in your risk management, and reliably guide you all the way to full NIS-2 compliance.

Meet strict cybersecurity requirements—without compromising your operational capability.

The European NIS-2 Directive drastically increases the legal requirements for information security. Thousands of companies in Germany are falling under the expanded regulatory framework for the first time—including many small and medium-sized enterprises (SMEs) and their suppliers.

Businesses face new obligations: strict risk management measures, rigid reporting deadlines for security incidents (within 24 hours), and expanded requirements to secure the entire supply chain.

In addition, NIS-2 increases the personal liability of executive management in the event of non-compliance. We support you in integrating these statutory requirements into your daily business operations in a targeted, proportionate manner—without unnecessary bureaucracy.

/assets/images/b/man-working-with-a-computer-general-data-protecti-2023-11-27-05-36-37-utc_bearbeitet-094d18ed.jpg
Regulatory Framework: NIS-2, ISO 27001, Supply Chain, and Managing Director Liability

The NIS-2 Directive is closely linked to established security standards and sets out clear statutory requirements:

  • Scope Assessment & Registration: Determination of classification as an "important" or "essential" entity based on industry codes and company size.
  • 10 Minimum Measures under NIS-2: From risk assessments and incident management to encryption and access controls.
  • Alignment with ISO 27001 & ISMS: An existing ISMS according to ISO 27001 already covers a large portion of NIS-2 requirements directly.
  • Mandatory Supply Chain Security: Companies must verify the IT security of their direct suppliers and service providers and enforce it contractually.
  • Personal Management Liability: Executives are required to monitor cybersecurity measures and participate in regular training programs.
/assets/images/3/Externer-Informationssicherheitsbeauftragter-ISB-p0fgartyc8mytyv.jpg
Risks of delayed NIS-2 implementation for your company

Failing to meet implementation deadlines or neglecting risk management obligations exposes companies to substantial risks:

  • Severe Fines: Potential penalties of up to 10 million euros or 2% of total worldwide annual turnover.
  • Personal Liability of Executive Management: Previous liability protections no longer apply—managing directors are directly liable with their personal assets in the event of non-compliance.
  • Violations of Reporting Obligations: Missing the short notification deadlines (e.g., 24-hour early warning to the Federal Office for Information Security, BSI) for cyber incidents results in immediate sanctions.
  • Termination of Supplier Contracts: Major corporate clients require proof of NIS-2 compliance from their service providers and will exclude unprepared partners from supply chains.
/assets/images/t/NIS2-7v4wp5zzd7bds3j.jpg
Comprehensive NIS-2 Implementation: Unifying Legal, Organizational, and IT Security aspects

Implementing NIS-2 is not merely an IT task, but a strategic governance priority for executive management. Without a structured integration of legal requirements, technical safeguards, and incident response processes, companies risk piecemeal solutions and unnecessarily high costs.

Typical challenges during NIS-2 preparation include:

  • Uncertainty regarding whether the company or its subsidiaries fall within the scope of the legislation.
  • Lack of a functional incident response framework to meet extremely short reporting deadlines.
  • Overwhelm when attempting to monitor and audit suppliers.
  • Insufficient auditability of implemented security measures for authorities (such as the BSI).


Our interdisciplinary team of IT security, compliance, and legal experts will guide you step by step toward a comprehensive, audit-ready NIS-2 framework.

/assets/images/5/k-pruefen_it-sicherheit-705x705-2-17070062.jpg
Our Service

We support your company flexibly—from a clear initial assessment through to the full implementation of NIS-2 requirements.

Scope & Gap Analysis

  • Legally Sound Assessment: Verification of NIS-2 applicability for your company and its subsidiaries.
  • Detailed Gap Analysis: Comprehensive target-versus-actual comparison of existing security measures against NIS-2 mandates.
  • Prioritized Action Plan: Roadmap for systematically bridging regulatory gaps.

Risk & Incident Management

  • Framework Development: Building and adapting risk management processes in line with NIS-2 minimum standards.
  • Emergency & Incident Response Chains: Establishing functional escalation workflows to adhere to the statutory 24-hour reporting deadline.
  • Crisis Playbooks: Formulating guidelines for crisis communication and cyber incident response.

IT Security Implementation

  • Technical Safeguards: Deployment of technical requirements, including Multi-Factor Authentication (MFA), end-to-end encryption, and strict access controls.
  • System Hardening: Implementing continuous vulnerability management, system hardening, and network segmentation.
  • Business Continuity: Securing operational resilience through practical backup strategies, disaster recovery plans, and emergency operating procedures.

Supply Chain Security & Governance

  • Vendor Risk Management: Designing review and auditing processes for your suppliers and service providers.
  • Contractual Safeguards: Drafting legally sound security agreements and contractual clauses for business partners.
  • Audit Trail & Documentation: Establishing internal control systems to protect executive leadership from liability.

Training & Board Awareness

  • Mandatory Executive Training: Tailored sessions for managing directors and board members to fulfill statutory NIS-2 education requirements.
  • Employee Security Awareness: Staff training programs focused on cyber risks and internal incident reporting protocols.
  • Regulatory Registration: Full guidance during the formal registration process with competent supervisory authorities (e.g., BSI).

What makes us strong:

Experience & expertise

NIS-2 requires technical expertise, legal precision, and organizational know-how. Our expert team brings together IT security specialists, legal counsel, and data protection consultants.

  • Interdisciplinary Team: Seamless collaboration between IT security specialists, legal experts, and compliance auditors.
  • 20+ Years of Experience: Established partner for mid-market businesses and operators of critical processes.
  • Holistic Approach: We align NIS-2 implementation with existing standards such as ISO 27001, ISO 22301, or GDPR.
Industry focus & practical relevance

Regulations demand security, but not at the expense of operational efficiency. We translate complex legal texts into clear, actionable tasks for your business.

  • Tailored Security Frameworks: No generic, one-size-fits-all templates—just proportionate measures designed for your specific company size.
  • Efficient Integration: We leverage your existing frameworks (e.g., data protection or quality management systems) to unlock synergies and minimize costs.
  • Executive Focus: We deliver effective protection for board members and managing directors against liability and fines.
Full-service support

End-to-End Guidance: From Analysis to Registration

We relieve the burden on your internal resources and manage your NIS-2 project from start to finish.

  • Step 1: Scope & Gap Analysis – Determination of applicability, identification of required actions, and roadmap creation.
  • Step 2: Strategy & Process Development – Formulation of security policies and emergency response plans, alongside the implementation of risk management.
  • Step 3: Training & Supply Chain Verification – Executive and employee training, as well as third-party service provider audits.
  • Step 4: Registration & Compliance Documentation – Support with regulatory registration and preparation of required documentation.

Ready for NIS-2 Compliance?

For further information on data processing activities upon use of our contact form, please refer to our privacy policy.

FAQ - NIS2

What is NIS-2 and when does the directive apply?

NIS-2 (Network and Information Security Directive) is an EU-wide directive aimed at strengthening cybersecurity. It drastically expands the range of regulated entities, affecting not only large corporations but also numerous mid-sized companies with at least 50 employees or 10 million euros in annual turnover within critical sectors.

Which sectors fall under the NIS-2 regulation?

Companies in sectors of high criticality (including energy, transport, banking, healthcare, drinking water, and digital infrastructure) as well as other important sectors (including postal and courier services, waste management, chemicals, food, manufacturing/production, and IT services) are affected.

What happens if my company fails to implement NIS-2 on time?

In cases of non-compliance, drastic sanctions apply: supervisory authorities can impose fines of up to 10 million euros or 2% of total worldwide annual turnover. Additionally, board members and managing directors face personal liability consequences in cases of grossly negligent failure to fulfill their duties of care.

What obligations arise for executive management?

Managing directors and board members must personally approve cybersecurity risk management measures and oversee their implementation. Furthermore, NIS-2 obligates executive bodies to regularly attend specialized cybersecurity training sessions.

How are NIS-2 and ISO 27001 connected?

An Information Security Management System (ISMS) according to ISO/IEC 27001 is the ideal framework for meeting NIS-2 requirements. Although NIS-2 does not explicitly mandate certification, implementing ISO 27001 automatically satisfies nearly all technical and organizational minimum requirements of NIS-2.

What does the incident reporting obligation under NIS-2 entail?

In the event of a significant security incident, a multi-stage reporting process to the competent authority (e.g., BSI) applies: an initial early warning must be submitted within 24 hours, followed by a full incident notification within 72 hours, and a final report no later than one month after.