OdySecure, the security platform by Cybervize, supports the implementation and evidence trail for the 10 minimum measures per § 30 BSIG: risks, controls, evidence in one system. External CISOs implement in 12 weeks, from €4,500. Fixed-fee packages instead of hourly billing.
Free initial consultation
What governs you is the German BSI Act (BSIG) in the version it received through the NIS-2 implementation act (NIS2UmsuCG) on 6 December 2025, with no transition period. What that means for affected companies, and what is at stake for non-compliance.
Germany's NIS-2 implementation law entered into force the day after publication in the Federal Law Gazette (5 Dec 2025). No transition period.
§ 33 BSIG sets no calendar deadline but a rolling one: within three months of first or newly qualifying as an essential or important entity. If you cross the thresholds today, your three months start today. Changes to the registered details carry their own deadlines, some without undue delay and some on a longer cycle; § 33 BSIG distinguishes them by the type of detail.
Early warning without undue delay and within 24 hours of becoming aware of a significant security incident. Confirmation and first assessment without undue delay and within 72 hours. Final report within one month of that notification; while the incident is ongoing, a progress report comes first.
Training, awareness and effectiveness reviews are ongoing measures under § 30 BSIG, not a one-time exercise. The law does not impose a general duty to run regular audits.
Scope follows from the BSIG, not from your industry alone. It is decided in four steps. Size alone obliges nobody, and sector alone does not either: both must come together, unless one of the size-independent special cases applies. The legally binding classification remains a matter for a law firm; we provide the professional basis for it.
Three levels that often get mixed up. EU Directive (EU) 2022/2555 lists its sectors in Annexes I and II in Roman numerals. The German BSI Act, which is what applies to you, lists the same sectors in Annexes 1 and 2 in Arabic numerals and uses the classes “besonders wichtig” and “wichtig” where the Directive says “essential” and “important”. The NIS2UmsuCG is not a third norm but the amending act that gave the BSIG this version. What governs you is the BSIG. Whether an entity is essential or important follows from the activity together with size, not from the annex alone.
NIS-2 distinguishes two entity classes. Both must implement the ten minimum measures, but supervision intensity and fine levels differ.
Proactive BSI inspections, on-site audits, random spot checks. The BSI can demand evidence and documents at any time.
Up to €10M for the most serious offences listed in § 65 BSIG. Where total revenue exceeds €500M, the fine may instead reach up to 2 % of total revenue.
Reactive supervision by the BSI, typically triggered by an incident, a complaint or a specific suspicion. No routine on-site audits.
Up to €7M for the most serious offences listed in § 65 BSIG. Where total revenue exceeds €500M, the fine may instead reach up to 1.4 % of total revenue.
Both classes must register with the BSI, implement the ten minimum measures per § 30 BSIG, and comply with the 24-hour and 72-hour reporting obligations. The management duties under § 38 BSIG, to implement the risk management measures, oversee their implementation and attend regular training, apply equally to both classes. § 28 (5) to (7) BSIG exempts certain entity types from some of these provisions, for example financial entities covered by DORA.
NIS-2 requires in-scope entities to actively manage cybersecurity along their supply chain. Many suppliers who are not themselves in scope therefore have to meet the requirements contractually.
Practical tip: suppliers of NIS-2 obligated entities should aim for ISO 27001 or equivalent maturity even if they are not directly in scope. It substantially simplifies evidence handling towards the customer.
NIS-2 mandates a risk-based approach with ten concrete minimum measures every in-scope organisation must implement.
Cyber-risk assessment methodology and binding security policies for the entire organisation.
Detection, containment, remediation, and reporting processes for security incidents, with clear ownership and timelines.
Continuity plans, backup strategies, recovery procedures: tested, documented, exercise-ready.
Assessment of critical suppliers and service providers, contractual cybersecurity requirements, ongoing monitoring.
Secure-by-design for IT procurement, secure development processes, patch and vulnerability management.
Concepts and procedures to assess whether the implemented measures are effective.
Basic training and awareness measures on cyber hygiene. Who and how often follows from your risk; § 30 BSIG sets no fixed cadence.
Concepts and processes for the use of cryptography, including encryption where appropriate, with key management. What gets encrypted follows from risk, not from a blanket duty.
Clear access concepts (least privilege), asset inventory, and lifecycle management.
Multi-factor or continuous authentication solutions and secured voice, video and text communication must be used; what is risk-based is how they are set up, not whether to use them. Secured emergency communication is required only where appropriate under § 30 (2) no. 10.
Source: § 30 of the German BSI Act as amended by the NIS-2 Implementation and Cybersecurity Reinforcement Act (NIS2UmsuCG), which transposes EU Directive (EU) 2022/2555 into German law.
Three clearly defined packages along your NIS-2 maturity. Transparent fixed fees, no hourly billing.
Structured scoping, gap evaluation, prioritised roadmap.
Audit-ready NIS-2 readiness: ISMS build-out, processes, documentation, evidence. The legally binding compliance statement remains a matter for counsel.
Ongoing NIS-2 compliance, BSI reporting readiness, annual effectiveness review. Scope and pricing tailored to your setup.
Final pricing for Gap Assessment and Implementation depends on company size, number of sites, and IT complexity. Maintenance & Audit is priced individually based on audit frequency, maturity level, and required response times. We define the precise scope in a free initial call.
Four phases over twelve weeks. Each phase with a clear output, management sign-off, and structured handover.
Clarify NIS-2 status, scope, ownership, critical services and processes. Output: stakeholder map and scope document.
Structured evaluation of the ten minimum measures using OdySecure, maturity score, gap analysis, risk assessment.
Prioritised roadmap, effort and cost estimates, management sign-off, implementation plan with ownership.
Execution of prioritised measures, documentation, training, effectiveness measurement, audit preparation.
Companies with ISO 27001 or TISAX don't need to build NIS-2 from scratch. OdySecure automatically maps controls between frameworks: no duplicate implementation, no isolated compliance silos.
ISMS module per ISO 27001:2022. Assessment module for IEC 62443, BSI Grundschutz, NIST and your own standards, imported via OSCAL or created directly in the platform. All modules share risks, assets, and measures.
Eight of ten NIS-2 minimum measures are covered by ISO 27001 Annex A controls. The platform automatically shows what's already addressed and which NIS-2-specific gaps remain.
Incident management addresses the GDPR 72h notification requirement and NIS-2 24h early warning in one workflow. Records of processing and asset inventory share the same data foundation.
Every action logged: who, when, what, from which IP. Auditor roles with cross-module read access. CSV export, audit-proof snapshots, automated reports.
Because the platform and methodology grew out of 25 years of ISMS implementation in mid-market companies, not from a SaaS whiteboard.
Cybervize's founder led ISMS implementations at PwC, Deloitte and KPMG for over two decades, from mid-market to DAX-listed enterprise, across financial services, telecommunications, public sector and manufacturing. ISO 27001 Lead Auditor since 2006, BSI IT-Grundschutz auditor, CISA, BS 25999.
Cybervize was founded in 2021 with a clear thesis: NIS-2 compliance must not become a tick-box exercise running parallel to day-to-day operations, the way classic GRC tools force it to. Instead, compliance requirements have to be woven into the running security and IT processes, so that evidence is generated within day-to-day operations. Cybervize Consulting GmbH (2021) runs the consulting, Cybervize Operations GmbH (2023) built the platform, funded by the German federal government's StartupSecure programme in a 14-month partnership with the CISPA incubator at the Helmholtz Center for Information Security. When our vCISO leads your NIS-2 implementation, they work with a tool designed by someone who has run the same engagements personally.
Sector-specific obligations, risks and platform building blocks for the most NIS-2-affected industries. Each page with indicative classification, minimum measures at the sector example, and path recommendation.
Annex 2 BSIG · important entity
Open sector pageAnnex 1 BSIG · KRITIS
Open sector pageAnnex 1 BSIG · plus DORA
Open sector pageAnnex 2 BSIG · plus TISAX
Open sector pageAnnex 2 BSIG · plus major-accident regulation
Open sector pageAnnex 1 BSIG · plus MDR · plus § 391 SGB V
Open sector pageAnnex 2 BSIG · plus IFS · plus FSSC 22000
Open sector pageAnnex 1 BSIG · ICT service management
Open sector pageSchedule a free consultation. In 45 minutes we assess your likely scope, discuss the next steps, and clarify whether the gap assessment is the right entry point for you. If you would rather start with an indicative classification, the NIS-2 risk check takes 30 minutes.
Schedule consultationMany companies treat NIS2 as a tick-box exercise. But compliance is not the same as resilience. The Cross-Border Cybersecurity Tour #2 in Saarbrücken made it clear: a functioning security operation outweighs any tool collection.
70% of SMEs treat NIS2 as a compliance checkbox. But organizations that see it as a strategic lever can turn regulatory requirements into operational excellence and genuine resilience.
Alexander Busse speaks at the CROSSBORDER CYBERSECURITY TOUR #2 in Saarbrücken on how NIS2 compliance can drive operational excellence. Why 70% of SMEs misjudge the regulation and how to turn it into a genuine competitive advantage.
Free self-check: where do you stand on the ten §30 BSIG measures? 30 questions, instant traffic light.
Learn moreStrategy, compliance and operational security for mid-market companies.
Learn moreComprehensive analysis of your IT security posture with actionable roadmap.
Learn more