Cybervize
NIS-2 for Mid-Market

NIS-2 consulting that delivers the implementation

We implement NIS-2 in your organisation, either as a fixed-price project or on an ongoing basis as a vCISO mandate from €3,600 per month. We keep the evidence in OdySecure. Gap assessment from €4,500; full implementation in 12 weeks from €18,000.

Free initial consultation

What has applied since 6 December 2025

What governs you is the German BSI Act (BSIG) in the version it received through the NIS-2 implementation act (NIS2UmsuCG) on 6 December 2025, with no transition period. What that means for affected companies, and what is at stake for non-compliance.

6 Dec 2025
NIS2UmsuCG in force

Germany's NIS-2 implementation law entered into force the day after publication in the Federal Law Gazette (5 Dec 2025). No transition period.

3 months
BSI registration

§ 33 BSIG sets no calendar deadline but a rolling one: within three months of first or newly qualifying as an essential or important entity. If you cross the thresholds today, your three months start today. Changes to the registered details carry their own deadlines, some without undue delay and some on a longer cycle; § 33 BSIG distinguishes them by the type of detail.

24h / 72h
Incident reporting

Early warning without undue delay and within 24 hours of becoming aware of a significant incident. Confirmation and first assessment without undue delay and within 72 hours. Final report within one month of that notification; while the incident is ongoing, a progress report comes first.

ongoing
Effectiveness review

Training, awareness and effectiveness reviews are ongoing measures under § 30 BSIG, not a one-time exercise. The law does not impose a general duty to run regular audits.

What's at stake for non-compliance

  • Fines up to €10M for 'essential' entities; where total revenue exceeds €500M, up to 2 % of total revenue instead (§ 65 BSIG)
  • Fines up to €7M for 'important' entities; where total revenue exceeds €500M, up to 1.4 % of total revenue instead (§ 65 BSIG)
  • Duty of the management body under § 38 BSIG to implement the risk management measures and oversee their implementation, plus a training duty of its own. A breach of the implementation or oversight duty makes the management body liable to its own entity for damage culpably caused, primarily under the company law rules applicable to the entity’s legal form and, failing those, under the BSIG itself
  • BSI supervisory and enforcement measures (e.g. orders to remedy deficiencies under §§ 61 und 62 BSIG) until compliance is restored

Are you in scope of NIS-2?

Scope follows from the BSIG, not from your industry alone. It is decided in four steps. Size alone obliges nobody, and sector alone does not either: both must come together, unless one of the size-independent special cases applies. The legally binding classification remains a matter for a law firm; we provide the professional basis for it.

  • Step 1, activity: does your concrete activity fall under Annex 1 or Annex 2 BSIG? What counts is the activity, not the industry label.
  • Step 2, size under § 28 BSIG: at least 50 employees OR annual turnover and balance sheet total each above €10M. For the higher class: at least 250 employees OR turnover above €50M AND balance sheet total above €43M.
  • Step 3, size-independent special cases: operators of critical installations, qualified trust service providers, TLD registries, DNS service providers and certain public telecommunications providers qualify regardless of size.
  • Step 4, sector exemptions under § 28(5) and (6) BSIG: they do not remove the classification as an entity, they exempt from specific provisions. For DORA financial entities §§ 30, 31, 32, 35, 36, 38 and 39 BSIG fall away; telecommunications and energy supply networks and the telematics infrastructure follow their own regimes, but activity by activity and with counter-exceptions: whoever also operates critical installations falls back under the BSIG to that extent.
  • Result: essential entity, important entity, or out of scope. Supplier status alone does not oblige you; whether you are in scope follows from your own activity and size under steps 1 to 3. Independently of that, the requirements reach you contractually, because § 30 BSIG requires your customer to manage supply chain risk.

NIS-2 Consulting Packages

Two fixed-price projects and one ongoing mandate, without timesheets.

Gap Assessment

4 weeks
from €4,500

Structured scoping, gap evaluation, prioritised roadmap.

  • Initial workshop with management and cyber owners
  • Evaluation of the ten minimum measures per § 30 BSIG
  • Maturity scorecard across all 10 minimum measures: one-page overview in Excel and PDF with maturity status per measure (1 insufficient to 4 optimised), including top three action recommendations
  • Gap report with detailed gap analysis per measure
  • Prioritised roadmap (quick wins and strategic)
  • Management briefing including liability implications
Book gap assessment

Implementation

12 weeks
from €18,000

Audit-ready NIS-2 readiness: ISMS build-out, processes, documentation, evidence. The legally binding compliance statement remains a matter for counsel.

  • Includes gap assessment
  • ISMS build-out using OdySecure
  • Security policies, incident response plan, BCM plan
  • Controls register with responsibilities and deadlines per minimum measure
  • Incident response playbook tailored to your organisation, with documented 24-hour and 72-hour reporting paths to the BSI
  • NIS-2 BSI registration template for registering your entity with the BSI
  • Supply-chain risk inventory of critical third parties
  • Employee training (e-learning and workshops)
  • Effectiveness measurement and audit preparation
Request implementation

Ongoing: vCISO mandate

Ongoing mandate
from €3,600/month

We fill the CISO function on a permanent basis and keep NIS-2 running in day-to-day operations, with OdySecure included. Scope follows the tier (days per month).

  • ISMS management: artefacts from Gap Assessment and Implementation kept current
  • NIS-2 gap check and updates when regulation changes
  • Reporting to management
  • OdySecure platform licence included
Intro call about the vCISO mandate

Final pricing for Gap Assessment and Implementation depends on company size, number of sites, and IT complexity. The tiers of the vCISO mandate are listed on the pricing page. We define the precise scope in a free intro call.

How the NIS-2 Engagement Works

Four phases over twelve weeks. Each phase with a clear output, management sign-off, and structured handover.

Phase 1
Week 1-2

Scoping and initial workshop

Clarify NIS-2 status, scope, ownership, critical services and processes. Output: stakeholder map and scope document.

Phase 2
Week 3-6

Gap assessment

Structured evaluation of the ten minimum measures using OdySecure, maturity score, gap analysis, risk assessment.

Phase 3
Week 7-8

Roadmap and steering

Prioritised roadmap, effort and cost estimates, management sign-off, implementation plan with ownership.

Phase 4
Week 9-12+

Implementation and evidence

Execution of prioritised measures, documentation, training, effectiveness measurement, audit preparation.

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT

NIS-2, ISO 27001 and GDPR in One System

Companies with ISO 27001 or TISAX don't need to build NIS-2 from scratch. OdySecure automatically maps controls between frameworks: no duplicate implementation, no isolated compliance silos.

One data layer for all frameworks

ISMS module per ISO 27001:2022. Assessment module for IEC 62443, BSI Grundschutz, NIST and your own standards, imported via OSCAL or created directly in the platform. All modules share risks, assets, and measures.

NIS-2 meets ISO 27001

Eight of ten NIS-2 minimum measures are covered by ISO 27001 Annex A controls. The platform automatically shows what's already addressed and which NIS-2-specific gaps remain.

GDPR as a subset

Incident management addresses the GDPR 72h notification requirement and NIS-2 24h early warning in one workflow. Records of processing and asset inventory share the same data foundation.

Audit trail for all standards

Actions are logged: who, when, what, from which IP. Auditor roles with cross-module read access. CSV export, audit-proof snapshots, automated reports.

More about NIS-2 consulting

The 18 sectors of the NIS2 Directive (Annexes I and II)

Three levels that often get mixed up. EU Directive (EU) 2022/2555 lists its sectors in Annexes I and II in Roman numerals. The German BSI Act, which is what applies to you, lists its sectors in Annexes 1 and 2 in Arabic numerals and uses the classes “besonders wichtig” and “wichtig” where the Directive says “essential” and “important”. The NIS2UmsuCG is not a third norm but the amending act that gave the BSIG this version. The two groupings do NOT match one to one: the BSI Act combines what the Directive separates, and it covers the federal administration separately in § 29 BSIG rather than through the annexes. The list below therefore follows the Directive; what counts for your classification is the wording of the annexes. What governs you is the BSIG. Whether an entity is essential or important follows from the activity together with size, not from the annex alone.

Sectors of high criticality (Annex I of the Directive)

  • Energy (electricity, district heating, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking
  • Financial market infrastructures
  • Healthcare
  • Drinking water
  • Wastewater
  • Digital infrastructure (DNS, TLD, cloud, data centres, internet exchanges, ICT managed services)
  • Managed ICT services (B2B IT service providers)
  • Public administration
  • Space

Other critical sectors (Annex II of the Directive)

  • Postal and courier services
  • Waste management
  • Chemicals (manufacturing, production, distribution)
  • Food (production, processing, distribution)
  • Manufacturing (medical devices, computers and electronics, machinery, motor vehicles)
  • Digital providers (online marketplaces, search engines, social networks)
  • Research

Important or Essential?

NIS-2 distinguishes two entity classes. Both must implement the ten minimum measures, but supervision intensity and fine levels differ.

Essential entities

Thresholds
  • An activity under Annex 1 BSIG (sectors of high criticality)
  • 250 or more employees OR (more than €50M annual revenue AND more than €43M balance sheet total)
  • Or defined by law (for example transmission system operators or qualified trust service providers)
Supervision

Proactive BSI inspections, on-site audits, random spot checks. The BSI can demand evidence and documents at any time.

Maximum fine

Up to €10M for the most serious offences listed in § 65 BSIG. Where total revenue exceeds €500M, the fine may instead reach up to 2 % of total revenue.

Important entities

Thresholds
  • An activity under Annex 1 or Annex 2 BSIG
  • 50 or more employees OR (more than €10M annual revenue AND more than €10M balance sheet total)
  • Annex 2 entities remain important entities regardless of headcount; only Annex 1 entities move up at 250 employees or above €50M turnover and above €43M balance sheet total
Supervision

Reactive supervision by the BSI, typically triggered by an incident, a complaint or a specific suspicion. No routine on-site audits.

Maximum fine

Up to €7M for the most serious offences listed in § 65 BSIG. Where total revenue exceeds €500M, the fine may instead reach up to 1.4 % of total revenue.

Both classes must register with the BSI, implement the ten minimum measures per § 30 BSIG, and comply with the 24-hour and 72-hour reporting obligations. The management duties under § 38 BSIG, to implement the risk management measures, oversee their implementation and attend regular training, apply equally to both classes. § 28 (5) to (7) BSIG exempts certain entity types from some of these provisions, for example financial entities covered by DORA.

Supply Chain Logic: Why Indirect Companies Feel NIS-2 Too

NIS-2 requires in-scope entities to actively manage cybersecurity along their supply chain. Many suppliers who are not themselves in scope therefore have to meet the requirements contractually.

  • Companies that supply NIS-2 obligated entities are pulled into NIS-2-like requirements via contractual clauses. This is the so-called trickle-down effect.
  • In practice that means cybersecurity clauses in contracts, evidence requirements towards the customer, and occasionally audits performed by the customer's supplier risk management.
  • Cloud and software providers, managed-service providers, maintenance vendors and engineering service providers often receive the requirements through contracts with their regulated customers, even when they stay below the size thresholds. That does not create an obligation of their own under the BSIG.

Practical tip: suppliers of NIS-2 obligated entities should aim for ISO 27001 or equivalent maturity even if they are not directly in scope. It substantially simplifies evidence handling towards the customer.

The 10 Minimum Measures (§ 30 BSIG)

NIS-2 mandates a risk-based approach with ten concrete minimum measures every in-scope organisation must implement.

1. Risk analysis and security policies

Cyber-risk assessment methodology and binding security policies for the entire organisation.

2. Incident handling

Detection, containment, remediation, and reporting processes for security incidents, with clear ownership and timelines.

3. Business continuity and crisis management

Continuity plans, backup strategies, recovery procedures: tested, documented, exercise-ready.

4. Supply-chain security

Assessment of critical suppliers and service providers, contractual cybersecurity requirements, ongoing monitoring.

5. Security in procurement, development, and maintenance

Secure-by-design for IT procurement, secure development processes, patch and vulnerability management.

6. Effectiveness assessment

Concepts and procedures to assess whether the implemented measures are effective.

7. Cyber hygiene and training

Basic training and awareness measures on cyber hygiene. Who and how often follows from your risk; § 30 BSIG sets no fixed cadence.

8. Cryptography and encryption

Concepts and processes for the use of cryptography, including encryption where appropriate, with key management. What gets encrypted follows from risk, not from a blanket duty.

9. Personnel security, access control, and asset management

Clear access concepts (least privilege), asset inventory, and lifecycle management.

10. Multi-factor authentication and secured communication

Multi-factor or continuous authentication solutions and secured voice, video and text communication must be used; what is risk-based is how they are set up, not whether to use them. Secured emergency communication is required only where appropriate under § 30 (2) no. 10.

Source: § 30 of the German BSI Act as amended by the NIS-2 Implementation and Cybersecurity Reinforcement Act (NIS2UmsuCG), which transposes EU Directive (EU) 2022/2555 into German law.

Why Cybervize for NIS-2 consulting?

Because our vCISO carries out the implementation of the NIS-2 requirements and keeps management informed throughout, following one methodology that applies to every mandate.

Every mandate is run with the same methodology and evidenced in OdySecure, in the mid-market and in large groups alike.

We founded Cybervize in 2021 on one thesis: NIS-2 compliance must not become a tick-box exercise running parallel to day-to-day operations, the way classic GRC tools force it to. Instead, compliance requirements have to be woven into the running security and IT processes, so that evidence is generated within day-to-day operations. Cybervize Consulting GmbH (2021) runs the consulting, Cybervize Operations GmbH (2023) built the platform, funded by the German federal government's StartupSecure programme in a 14-month partnership with the CISPA incubator at the Helmholtz Center for Information Security. When our vCISO leads your NIS-2 implementation, they work with a tool that grew out of the same engagements.

NIS-2 by sector

Sources

Frequently Asked Questions about NIS-2 Consulting

What is NIS-2?
NIS-2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. In Germany it applies through the German BSI Act (BSIG) as amended by the NIS2UmsuCG, in force since 6 December 2025. Entities in scope must implement risk management measures, report significant incidents and register with the BSI. We clarify whether your company is in scope and implement the measures with audit-ready evidence in OdySecure.
What does NIS-2 consulting cost for a mid-market company?
Cybervize offers two fixed-fee packages: Gap Assessment from €4,500 (4 weeks) and full Implementation from €18,000 (12 weeks, includes the gap assessment). Final pricing depends on company size, number of sites, and IT complexity. As an example, at roughly 200 employees and one site, implementation runs at €20,000 to €30,000 one-time. The range across mid-market implementations overall runs from €20,000 to €40,000. For ongoing operation afterwards, we fill the CISO function under a vCISO mandate from €3,600 per month, with OdySecure included.
Am I in scope of NIS-2?
You carry obligations of your own in three cases: (1) as an entity under Annex 1 or Annex 2 BSIG with 50 or more employees, or with more than €10M annual turnover and more than €10M balance sheet total; (2) as the operator of a critical installation in one of the sectors of those two annexes (energy, healthcare, finance, transport and others), regardless of size; (3) as a trust service provider, top-level domain registry, DNS service provider, provider of publicly available telecommunications services or operator of public telecommunications networks, all regardless of size. A fourth case reaches you without an obligation of your own: as a supplier to a regulated entity, contractual requirements can come your way, because your customer has to manage supply-chain risk under § 30 BSIG. We provide the specialist assessment in the free initial call; the legally binding determination stays with a law firm.
Who is liable if NIS-2 requirements are not met?
For the most serious of the offences listed in § 65 BSIG, fines reach up to €10M for essential entities and up to €7M for important entities. Where total revenue exceeds €500M, the fine may instead reach up to 2 % or 1.4 % of total revenue. Other offences carry lower maxima, graduated from €5M down to €100,000. On top of that come management duties: § 38 BSIG requires the management body to implement the risk management measures under § 30 BSIG and to oversee their implementation. Where it breaches that duty, it is liable to its own entity for damage culpably caused, under the company law rules applicable to the entity’s legal form. Where those rules contain no liability provision, liability follows from the BSIG itself.
How does NIS-2 differ from GDPR?
GDPR focuses on protecting personal data. NIS-2 focuses on the cybersecurity of the entire organisation: all data, systems, processes, and services, not only personal data. The two overlap on incident reporting and encryption but are complementary. NIS-2 also requires a full ISMS, supply-chain risk management, and explicit management responsibility.
Is the German NIS-2 implementation law in force already?
The NIS-2 Implementation and Cybersecurity Reinforcement Act (NIS2UmsuCG) was passed in November 2025 and entered into force on 6 December 2025 (promulgated 5 December 2025, Federal Law Gazette 2025 I No. 301). In-scope companies must register with the BSI and implement the ten minimum measures. There is no transition period; the obligations apply from entry into force.
How fast can NIS-2 compliance be achieved?
With the Cybervize Implementation package you reach audit readiness in 12 weeks from contract start. Speed depends on three factors: existing ISMS maturity, employee availability for workshops, and the number of suppliers to be integrated into the supply-chain assessment. Complex multi-site setups can realistically take 16-20 weeks.
What role does OdySecure play in NIS-2 consulting?
OdySecure is the technical backbone of our NIS-2 engagement. The Assessment module digitises the evaluation of the ten minimum measures with structured questionnaires and automated reporting. The ISMS module manages security policies and measures. The TPRM module automates supply-chain assessment. The BCM module covers business continuity. You retain ownership of the data, even after the engagement ends.
Do you also offer training only, without the full engagement?
Yes. The half-day on-site NIS-2 training for the management board in Düsseldorf/NRW is offered separately on the page 'NIS-2 and DORA Executive Training'. It can be booked standalone or as part of the implementation package.
What is the difference between NIS and NIS-2?
NIS-2 (Directive (EU) 2022/2555) replaces the original NIS directive from 2016. It expands the sector scope (from 7 to 18 sectors), the thresholds (from 50 employees, no longer KRITIS-only), the minimum measures (now ten explicit ones), the supply-chain requirements, and the sanctions including personal liability of management. The old NIS had a much narrower scope and no harmonised fine regime.
Am I in scope of NIS-2 if I don't operate critical infrastructure?
Possibly. It depends on your activity, not on the industry label. Annexes 1 and 2 BSIG cover a broad field, including machinery manufacturing, chemicals, food, B2B IT service providers and research, but in each case only for specific activities. If your activity appears there AND you meet the size thresholds of § 28 BSIG, you are in scope; whether as an essential or an important entity follows from annex and size together. Regardless of size, operators of critical installations and qualified trust service providers, among others, are covered. Conversely, § 28(5) and (6) BSIG exempt certain areas from individual provisions without removing the classification itself: a DORA financial entity remains an entity under the BSIG, but §§ 30, 31, 32, 35, 36, 38 and 39 fall away. Even without an obligation of your own, requirements can reach you through the supply chain of an obliged entity.
What does an NIS-2 implementation cost?
Cybervize offers two fixed-fee packages: Gap Assessment from €4,500 (4 weeks) and full Implementation from €18,000 (12 weeks, includes the gap assessment). The range for a full mid-market implementation is €20,000 to €40,000 one-time, depending on company size, number of sites and IT complexity; a single example with roughly 200 employees and one site runs at €20,000 to €30,000. Ongoing operation afterwards can be covered by the vCISO mandate from €3,600 per month. External NIS-2 implementations at comparable providers often run in the five- to six-figure range, frequently without published prices.
How long does an NIS-2 implementation take?
Standard is 12 weeks from contract start to audit readiness. Organisations with an existing ISO 27001 ISMS or TISAX certification usually finish in 8 to 10 weeks because eight of the ten minimum measures are already covered. Complex group structures with multiple sites or OT environments can require 16 to 20 weeks. Speed depends on ISMS maturity, internal stakeholder availability and the number of critical suppliers.
What are the 10 minimum measures under § 30 BSIG?
§ 30 BSIG defines ten minimum measures: risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, security in procurement and development, effectiveness assessment, cyber hygiene and training, cryptography and encryption, personnel security and access control, and multi-factor authentication and secured communication. A detailed description for each is available on this page in the section on the 10 minimum measures.
What happens if I don't implement NIS-2?
For the most serious offences listed in § 65 BSIG, fines reach up to €10M for essential entities and up to €7M for important entities; where total revenue exceeds €500M, up to 2 % or 1.4 % of total revenue instead. Under § 38 BSIG the management body must implement the risk management measures and oversee their implementation. Where it breaches that duty, it is liable to its own entity for damage culpably caused, under the company law rules applicable to the entity’s legal form; where those rules contain no liability provision, liability follows from the BSIG itself. The BSI can impose supervisory and enforcement measures (e.g. orders to remedy deficiencies) until compliance is restored. Civil liability claims after an incident also become substantially more likely when NIS-2 obligations have not been met.
Do I need an ISO 27001 certification for NIS-2?
No, NIS-2 does not mandate ISO 27001 certification. However, large parts of the NIS-2 requirements can be mapped onto ISO 27001 structures, which accelerates NIS-2 implementation and simplifies evidence handling towards the BSI. Organisations with existing ISO 27001 or TISAX typically focus on closing the NIS-2-specific gaps: explicit incident reporting paths to the BSI and effectiveness assessment with measurable indicators.
How do I demonstrate NIS-2 compliance to the BSI?
Evidence flows through three channels: first, the one-time BSI registration with master data and accountable contacts; second, ongoing incident reporting via the BSI reporting portal within 24 and 72 hours; third, documentation to be provided on BSI request (risk analysis, controls register, effectiveness reports, training records, audit trail). NIS-2 itself does not provide a certification, but an audit-proof trail is a prerequisite for any BSI inquiry.

Find the right entry point in an intro call

Schedule a free consultation. In 45 minutes we assess your likely scope, discuss the next steps, and clarify whether a gap assessment, an implementation project or a vCISO mandate is the right entry point for you. If you would rather start with an indicative classification, the NIS-2 risk check takes 30 minutes.

Schedule consultation