Ensuring NIS-2 Compliance
We accompany you from the impact assessment to the implementation of the NIS2 requirements and take over the entire process for you.
- Personal support instead of standard solution
- Fast and free NIS2 impact check
- Complete takeover of the process without in-house research
- Personal contact person during the project
NIS2 introduces new requirements.
Are you prepared?
- Extended circle of affected companies
- Stricter security requirements
- Extensive reporting and verification obligations
- High fines for violations
- Personal liability risks for the management
Fines of up to
10 million €
or
2 %
of the annual turnover possible
Our service model
Modular. End-to-end. Tailored to your business.
current situation analysis & gap assessment
We analyze your current security status and compare it to the NIS2 requirements.
Risk Assessment & Action Plan
We assess your risks in a structured manner and create a prioritized action plan for NIS2 compliance.
Implementation &
Support
We accompany you in the implementation of all measures and ensure efficient compliance with the NIS2 requirements.
Training & Awareness
We sensitize every level of the company to cybersecurity risks in a practical way.
Your journey with us – in 4 easy steps
Free initial consultation & impact assessment
We analyze free of charge whether your company is affected.
Kick-Off & Scoping
We understand your business and define the scope.
Risk Analysis & Measures
We analyze your processes and hazards and develop a suitable action plan.
Implementation
We support you in achieving NIS2 compliance.
Your benefits
- Objective Safety Assessment
- Avoid fines
- Minimizing risks
- Relief of internal resources
- Securing competitive advantages
We specialise in advising small and medium-sized enterprises and also offer attractive conditions for micro-enterprises.
Why with us?
Minimal internal effort
We take care of the organizational work and reduce your time expenditure to a minimum.
Practical relevance
Advice
As a TISAX® certified company, we meet even the highest requirements for information security.
Complete process takeover
You don't have to do any complex preparatory work. We take care of the entire NIS2 process
Personal
Supervision
A permanent expert will personally accompany you through the entire project.
NIS2 Quick Check
Answer a few questions and receive a free initial assessment of your company's NIS2 impact.
NIS-2 - FAQ
Information about the NIS2 EU Directive to strengthen cybersecurity.
What is the NIS2 Directive?
The NIS2 Directive is an EU legislation aimed at improving cybersecurity in critical sectors. NIS stands for network and information security. It obliges companies to secure their networks and information systems against cyber risks and to report incidents. The first NIS Directive was adopted by the EU Parliament in 2016. Building on this, the second version of the Directive (NIS2) was introduced in 2022, which has already entered into force and must be transposed into national law by October 2024. The German NIS2 Implementation Act (NIS2UmsuCG) came into force on 6 December 2025.
Who is affected by the new directive?
The NIS2 applies to companies in sectors such as energy, healthcare, transport, food supply, finance, digital infrastructure and public administration, in both the private and public sectors. There are no fixed thresholds in NIS2 that clearly apply to all affected companies. However, for some sectors, small and medium-sized enterprises (SMEs) are taken into account, which means that companies with fewer than 50 employees and an annual turnover of less than €10 million are usually not directly affected by the NIS2. However, despite their size, small companies operating in critical sectors such as healthcare or energy supply must meet certain minimum requirements, even if they are not fully covered by the NIS2. If you are unsure, please feel free to contact us – we will help you to correctly classify your impact on the NIS2 requirements.
What are the main requirements of NIS2?
Companies must take a variety of measures to meet the requirements of NIS2. The starting point for this is an ISMS. In addition, the following points in particular must be implemented:
Risk management and safety precautions: Companies must establish an effective risk management system based on the identification and minimization of cyber risks. Security precautions must be taken to protect sensitive data and systems from attacks.
Report cybersecurity incidents: In the event of an incident, companies are obliged to report it to the competent national authorities within 24 hours. A detailed report of the incident must be submitted within 72 hours of the initial report.
Monitoring and regular audits: Companies need to regularly review their security measures and ensure that they are up-to-date and effective. This includes conducting security audits and implementing improvement measures.
What are the penalties for non-compliance with NIS2?
Companies that do not comply with the requirements of the NIS2 Directive can be subject to significant penalties. These penalties can be as high as €10 million or 2% of the company’s annual global turnover, whichever is higher. In addition to the financial penalties, there may also be legal consequences and a loss of trust on the part of customers and partners, which can lead to long-term business damage. Therefore, it is crucial to meet the requirements in a timely manner to avoid these risks.
What is an ISMS and how does it help with NIS2 implementation?
An ISMS (Information Security Management System) is a structured system for managing and improving information security in an organization. It includes processes, policies, tools, and procedures for identifying, assessing, and addressing security risks. An ISMS according to the ISO 27001 standard forms the basis for the implementation of the NIS2 requirements. It helps businesses implement the necessary security measures, report incidents, and continuously improve their cybersecurity. The introduction of an ISMS ensures that all requirements of NIS2 are taken into account in a systematic framework.
What costs can I expect for NIS2 compliance?
The actual cost will depend on the size and complexity of your business. Factors such as locations, business units and existing IT structures play a role in this.
The following guidelines apply for orientation:
- Initial consultation or examination of concern: free of charge (approx. 30 minutes)
- Micro-enterprises (< 10 employees): from €1,299 net
- Small companies (< 50 employees): from €1,999 net
- Medium-sized companies (< 100 employees): from €2,950 net
- Medium-sized companies (< 250 employees): from €3,950 net
The prices quoted are non-binding guidelines (net, plus statutory VAT). The actual expenditure is determined individually and transparently after a short initial examination.
Ready for NIS2 compliance?
Let us check your concern without obligation and free of charge.
No obligation. Free of charge. Results in 30 minutes.