NIS-2 consulting that delivers the implementation
We implement NIS-2 in your organisation, either as a fixed-price project or on an ongoing basis as a vCISO mandate from €3,600 per month. We keep the evidence in OdySecure. Gap assessment from €4,500; full implementation in 12 weeks from €18,000.
Free initial consultation
What has applied since 6 December 2025
What governs you is the German BSI Act (BSIG) in the version it received through the NIS-2 implementation act (NIS2UmsuCG) on 6 December 2025, with no transition period. What that means for affected companies, and what is at stake for non-compliance.
Germany's NIS-2 implementation law entered into force the day after publication in the Federal Law Gazette (5 Dec 2025). No transition period.
§ 33 BSIG sets no calendar deadline but a rolling one: within three months of first or newly qualifying as an essential or important entity. If you cross the thresholds today, your three months start today. Changes to the registered details carry their own deadlines, some without undue delay and some on a longer cycle; § 33 BSIG distinguishes them by the type of detail.
Early warning without undue delay and within 24 hours of becoming aware of a significant incident. Confirmation and first assessment without undue delay and within 72 hours. Final report within one month of that notification; while the incident is ongoing, a progress report comes first.
Training, awareness and effectiveness reviews are ongoing measures under § 30 BSIG, not a one-time exercise. The law does not impose a general duty to run regular audits.
What's at stake for non-compliance
- Fines up to €10M for 'essential' entities; where total revenue exceeds €500M, up to 2 % of total revenue instead (§ 65 BSIG)
- Fines up to €7M for 'important' entities; where total revenue exceeds €500M, up to 1.4 % of total revenue instead (§ 65 BSIG)
- Duty of the management body under § 38 BSIG to implement the risk management measures and oversee their implementation, plus a training duty of its own. A breach of the implementation or oversight duty makes the management body liable to its own entity for damage culpably caused, primarily under the company law rules applicable to the entity’s legal form and, failing those, under the BSIG itself
- BSI supervisory and enforcement measures (e.g. orders to remedy deficiencies under §§ 61 und 62 BSIG) until compliance is restored
Are you in scope of NIS-2?
Scope follows from the BSIG, not from your industry alone. It is decided in four steps. Size alone obliges nobody, and sector alone does not either: both must come together, unless one of the size-independent special cases applies. The legally binding classification remains a matter for a law firm; we provide the professional basis for it.
- Step 1, activity: does your concrete activity fall under Annex 1 or Annex 2 BSIG? What counts is the activity, not the industry label.
- Step 2, size under § 28 BSIG: at least 50 employees OR annual turnover and balance sheet total each above €10M. For the higher class: at least 250 employees OR turnover above €50M AND balance sheet total above €43M.
- Step 3, size-independent special cases: operators of critical installations, qualified trust service providers, TLD registries, DNS service providers and certain public telecommunications providers qualify regardless of size.
- Step 4, sector exemptions under § 28(5) and (6) BSIG: they do not remove the classification as an entity, they exempt from specific provisions. For DORA financial entities §§ 30, 31, 32, 35, 36, 38 and 39 BSIG fall away; telecommunications and energy supply networks and the telematics infrastructure follow their own regimes, but activity by activity and with counter-exceptions: whoever also operates critical installations falls back under the BSIG to that extent.
- Result: essential entity, important entity, or out of scope. Supplier status alone does not oblige you; whether you are in scope follows from your own activity and size under steps 1 to 3. Independently of that, the requirements reach you contractually, because § 30 BSIG requires your customer to manage supply chain risk.
NIS-2 Consulting Packages
Two fixed-price projects and one ongoing mandate, without timesheets.
Gap Assessment
Structured scoping, gap evaluation, prioritised roadmap.
- Initial workshop with management and cyber owners
- Evaluation of the ten minimum measures per § 30 BSIG
- Maturity scorecard across all 10 minimum measures: one-page overview in Excel and PDF with maturity status per measure (1 insufficient to 4 optimised), including top three action recommendations
- Gap report with detailed gap analysis per measure
- Prioritised roadmap (quick wins and strategic)
- Management briefing including liability implications
Implementation
Audit-ready NIS-2 readiness: ISMS build-out, processes, documentation, evidence. The legally binding compliance statement remains a matter for counsel.
- Includes gap assessment
- ISMS build-out using OdySecure
- Security policies, incident response plan, BCM plan
- Controls register with responsibilities and deadlines per minimum measure
- Incident response playbook tailored to your organisation, with documented 24-hour and 72-hour reporting paths to the BSI
- NIS-2 BSI registration template for registering your entity with the BSI
- Supply-chain risk inventory of critical third parties
- Employee training (e-learning and workshops)
- Effectiveness measurement and audit preparation
Ongoing: vCISO mandate
We fill the CISO function on a permanent basis and keep NIS-2 running in day-to-day operations, with OdySecure included. Scope follows the tier (days per month).
- ISMS management: artefacts from Gap Assessment and Implementation kept current
- NIS-2 gap check and updates when regulation changes
- Reporting to management
- OdySecure platform licence included
Final pricing for Gap Assessment and Implementation depends on company size, number of sites, and IT complexity. The tiers of the vCISO mandate are listed on the pricing page. We define the precise scope in a free intro call.
How the NIS-2 Engagement Works
Four phases over twelve weeks. Each phase with a clear output, management sign-off, and structured handover.
Scoping and initial workshop
Clarify NIS-2 status, scope, ownership, critical services and processes. Output: stakeholder map and scope document.
Gap assessment
Structured evaluation of the ten minimum measures using OdySecure, maturity score, gap analysis, risk assessment.
Roadmap and steering
Prioritised roadmap, effort and cost estimates, management sign-off, implementation plan with ownership.
Implementation and evidence
Execution of prioritised measures, documentation, training, effectiveness measurement, audit preparation.
NIS-2, ISO 27001 and GDPR in One System
Companies with ISO 27001 or TISAX don't need to build NIS-2 from scratch. OdySecure automatically maps controls between frameworks: no duplicate implementation, no isolated compliance silos.
One data layer for all frameworks
ISMS module per ISO 27001:2022. Assessment module for IEC 62443, BSI Grundschutz, NIST and your own standards, imported via OSCAL or created directly in the platform. All modules share risks, assets, and measures.
NIS-2 meets ISO 27001
Eight of ten NIS-2 minimum measures are covered by ISO 27001 Annex A controls. The platform automatically shows what's already addressed and which NIS-2-specific gaps remain.
GDPR as a subset
Incident management addresses the GDPR 72h notification requirement and NIS-2 24h early warning in one workflow. Records of processing and asset inventory share the same data foundation.
Audit trail for all standards
Actions are logged: who, when, what, from which IP. Auditor roles with cross-module read access. CSV export, audit-proof snapshots, automated reports.
The 18 sectors of the NIS2 Directive (Annexes I and II)
Three levels that often get mixed up. EU Directive (EU) 2022/2555 lists its sectors in Annexes I and II in Roman numerals. The German BSI Act, which is what applies to you, lists its sectors in Annexes 1 and 2 in Arabic numerals and uses the classes “besonders wichtig” and “wichtig” where the Directive says “essential” and “important”. The NIS2UmsuCG is not a third norm but the amending act that gave the BSIG this version. The two groupings do NOT match one to one: the BSI Act combines what the Directive separates, and it covers the federal administration separately in § 29 BSIG rather than through the annexes. The list below therefore follows the Directive; what counts for your classification is the wording of the annexes. What governs you is the BSIG. Whether an entity is essential or important follows from the activity together with size, not from the annex alone.
Sectors of high criticality (Annex I of the Directive)
- Energy (electricity, district heating, oil, gas, hydrogen)
- Transport (air, rail, water, road)
- Banking
- Financial market infrastructures
- Healthcare
- Drinking water
- Wastewater
- Digital infrastructure (DNS, TLD, cloud, data centres, internet exchanges, ICT managed services)
- Managed ICT services (B2B IT service providers)
- Public administration
- Space
Other critical sectors (Annex II of the Directive)
- Postal and courier services
- Waste management
- Chemicals (manufacturing, production, distribution)
- Food (production, processing, distribution)
- Manufacturing (medical devices, computers and electronics, machinery, motor vehicles)
- Digital providers (online marketplaces, search engines, social networks)
- Research
Important or Essential?
NIS-2 distinguishes two entity classes. Both must implement the ten minimum measures, but supervision intensity and fine levels differ.
Essential entities
- An activity under Annex 1 BSIG (sectors of high criticality)
- 250 or more employees OR (more than €50M annual revenue AND more than €43M balance sheet total)
- Or defined by law (for example transmission system operators or qualified trust service providers)
Proactive BSI inspections, on-site audits, random spot checks. The BSI can demand evidence and documents at any time.
Up to €10M for the most serious offences listed in § 65 BSIG. Where total revenue exceeds €500M, the fine may instead reach up to 2 % of total revenue.
Important entities
- An activity under Annex 1 or Annex 2 BSIG
- 50 or more employees OR (more than €10M annual revenue AND more than €10M balance sheet total)
- Annex 2 entities remain important entities regardless of headcount; only Annex 1 entities move up at 250 employees or above €50M turnover and above €43M balance sheet total
Reactive supervision by the BSI, typically triggered by an incident, a complaint or a specific suspicion. No routine on-site audits.
Up to €7M for the most serious offences listed in § 65 BSIG. Where total revenue exceeds €500M, the fine may instead reach up to 1.4 % of total revenue.
Both classes must register with the BSI, implement the ten minimum measures per § 30 BSIG, and comply with the 24-hour and 72-hour reporting obligations. The management duties under § 38 BSIG, to implement the risk management measures, oversee their implementation and attend regular training, apply equally to both classes. § 28 (5) to (7) BSIG exempts certain entity types from some of these provisions, for example financial entities covered by DORA.
Supply Chain Logic: Why Indirect Companies Feel NIS-2 Too
NIS-2 requires in-scope entities to actively manage cybersecurity along their supply chain. Many suppliers who are not themselves in scope therefore have to meet the requirements contractually.
- Companies that supply NIS-2 obligated entities are pulled into NIS-2-like requirements via contractual clauses. This is the so-called trickle-down effect.
- In practice that means cybersecurity clauses in contracts, evidence requirements towards the customer, and occasionally audits performed by the customer's supplier risk management.
- Cloud and software providers, managed-service providers, maintenance vendors and engineering service providers often receive the requirements through contracts with their regulated customers, even when they stay below the size thresholds. That does not create an obligation of their own under the BSIG.
Practical tip: suppliers of NIS-2 obligated entities should aim for ISO 27001 or equivalent maturity even if they are not directly in scope. It substantially simplifies evidence handling towards the customer.
The 10 Minimum Measures (§ 30 BSIG)
NIS-2 mandates a risk-based approach with ten concrete minimum measures every in-scope organisation must implement.
1. Risk analysis and security policies
Cyber-risk assessment methodology and binding security policies for the entire organisation.
2. Incident handling
Detection, containment, remediation, and reporting processes for security incidents, with clear ownership and timelines.
3. Business continuity and crisis management
Continuity plans, backup strategies, recovery procedures: tested, documented, exercise-ready.
4. Supply-chain security
Assessment of critical suppliers and service providers, contractual cybersecurity requirements, ongoing monitoring.
5. Security in procurement, development, and maintenance
Secure-by-design for IT procurement, secure development processes, patch and vulnerability management.
6. Effectiveness assessment
Concepts and procedures to assess whether the implemented measures are effective.
7. Cyber hygiene and training
Basic training and awareness measures on cyber hygiene. Who and how often follows from your risk; § 30 BSIG sets no fixed cadence.
8. Cryptography and encryption
Concepts and processes for the use of cryptography, including encryption where appropriate, with key management. What gets encrypted follows from risk, not from a blanket duty.
9. Personnel security, access control, and asset management
Clear access concepts (least privilege), asset inventory, and lifecycle management.
10. Multi-factor authentication and secured communication
Multi-factor or continuous authentication solutions and secured voice, video and text communication must be used; what is risk-based is how they are set up, not whether to use them. Secured emergency communication is required only where appropriate under § 30 (2) no. 10.
Source: § 30 of the German BSI Act as amended by the NIS-2 Implementation and Cybersecurity Reinforcement Act (NIS2UmsuCG), which transposes EU Directive (EU) 2022/2555 into German law.
Why Cybervize for NIS-2 consulting?
Because our vCISO carries out the implementation of the NIS-2 requirements and keeps management informed throughout, following one methodology that applies to every mandate.
Every mandate is run with the same methodology and evidenced in OdySecure, in the mid-market and in large groups alike.
We founded Cybervize in 2021 on one thesis: NIS-2 compliance must not become a tick-box exercise running parallel to day-to-day operations, the way classic GRC tools force it to. Instead, compliance requirements have to be woven into the running security and IT processes, so that evidence is generated within day-to-day operations. Cybervize Consulting GmbH (2021) runs the consulting, Cybervize Operations GmbH (2023) built the platform, funded by the German federal government's StartupSecure programme in a 14-month partnership with the CISPA incubator at the Helmholtz Center for Information Security. When our vCISO leads your NIS-2 implementation, they work with a tool that grew out of the same engagements.
NIS-2 by sector
Sector-specific obligations, risks and platform building blocks for the most NIS-2-affected industries. Each page with indicative classification, minimum measures at the sector example, and path recommendation.
NIS-2 for mechanical engineering
Annex 2 BSIG · important entity
Open sector pageNIS-2 for energy providers
Annex 1 BSIG · KRITIS
Open sector pageDORA for financial services
DORA · BSIG registration if an entity
Open sector pageNIS-2 for automotive
Annex 2 BSIG · plus TISAX
Open sector pageNIS-2 for chemicals
Annex 2 BSIG · plus major-accident regulation
Open sector pageNIS-2 for healthcare
Annex 1 BSIG · plus MDR · plus § 391 SGB V
Open sector pageNIS-2 for food and beverage
Annex 2 BSIG · plus IFS · plus FSSC 22000
Open sector pageNIS-2 for IT service providers and MSPs
Annex 1 BSIG · ICT service management
Open sector pageSources
- NIS2UmsuCG in the Federal Law Gazette: recht.bund.de/bgbl/1/2025/301
- BSI press release on entry into force (5 Dec 2025): bsi.bund.de
- EU NIS-2 directive 2022/2555: eur-lex.europa.eu
- BSI IT-Grundschutz Kompendium: bsi.bund.de/IT-Grundschutz
Frequently Asked Questions about NIS-2 Consulting
What is NIS-2?
What does NIS-2 consulting cost for a mid-market company?
Am I in scope of NIS-2?
Who is liable if NIS-2 requirements are not met?
How does NIS-2 differ from GDPR?
Is the German NIS-2 implementation law in force already?
How fast can NIS-2 compliance be achieved?
What role does OdySecure play in NIS-2 consulting?
Do you also offer training only, without the full engagement?
What is the difference between NIS and NIS-2?
Am I in scope of NIS-2 if I don't operate critical infrastructure?
What does an NIS-2 implementation cost?
How long does an NIS-2 implementation take?
What are the 10 minimum measures under § 30 BSIG?
What happens if I don't implement NIS-2?
Do I need an ISO 27001 certification for NIS-2?
How do I demonstrate NIS-2 compliance to the BSI?
Find the right entry point in an intro call
Schedule a free consultation. In 45 minutes we assess your likely scope, discuss the next steps, and clarify whether a gap assessment, an implementation project or a vCISO mandate is the right entry point for you. If you would rather start with an indicative classification, the NIS-2 risk check takes 30 minutes.
Schedule consultationRelated Articles
NIS2 and True Resilience: Why Compliance Alone Is Not Enough
Many companies treat NIS2 as a tick-box exercise. But compliance is not the same as resilience. The Cross-Border Cybersecurity Tour #2 in Saarbrücken made it clear: a functioning security operation outweighs any tool collection.
NIS2 as an Operating System Upgrade: Why Compliance Is a Strategic Opportunity for Mid-Market Companies
70% of SMEs treat NIS2 as a compliance checkbox. But organizations that see it as a strategic lever can turn regulatory requirements into operational excellence and genuine resilience.
CROSSBORDER CYBERSECURITY TOUR #2: Why NIS2 Is a Strategic Opportunity for SMEs
Alexander Busse speaks at the CROSSBORDER CYBERSECURITY TOUR #2 in Saarbrücken on how NIS2 compliance can drive operational excellence. Why 70% of SMEs misjudge the regulation and how to turn it into a genuine competitive advantage.
Related Services
NIS-2 Maturity Check
Free self-check: where do you stand on the ten §30 BSIG measures? 30 questions, instant traffic light.
Learn moreCybersecurity for mid-market
Strategy, compliance and operational security for mid-market companies.
Learn moreCybersecurity Assessment
Analysis of your IT security posture with an actionable roadmap.
Learn more



