The NIS2 Directive came into force on a European basis since January 16, 2023, introducing mandatory security measures and reporting obligations.
It sets out minimum requirements for cybersecurity. It is intended to help standardize the level of cybersecurity in The European Union and strengthen international cooperation in the fight against cyberattacks. The EU member states must transpose the directive into national law by October 2024.
The date for the implementation of the NIS2 into the national NIS2 UmsuCG is questionable. Regardless of this, companies are well advised to implement the minimum requirements in accordance with Art. 21 of NIS2 as soon as possible.
In Germany, around 30,000 companies are affected by this directive, which entails new obligations.
Not Sure If You Are Affected By The NIS2 Directive?
Together we check whether your company is affected by the NIS2 directive or not.
Step
Gap Analysis & Diagnostic
We analyse the current state of your cybersecurity, compare it with the NIS2 directives or current drafts (including country-specific requirements for EU-wide locations), help you prioritise and plan the necessary measures, including budget estimates, and draw up a timeline for implementation.
Step
Implementation projects
We take charge of project management for the implementation of measures – including the preparation of make-or-buy decisions and, where necessary, the selection and onboarding of additional solutions or managed services. We can provide dedicated support for individual projects or a comprehensive service as an interim CISO/ISO/ISB.
Check if you are affected
Overview Of The Affected Sectors
Sectors with high criticality (Annex I)
Energy
Healthcare
Traffic
Banking and Finance
Drinking Water
Waste Water
Digital Infrastructure
Space Flight
Public Administration
Management of ICT Services
Other critical Sectors (Annex II)
Post and Courier Services
Waste Management
Chemical Products
Food
Processing/Manufacturing Industry
Digital Services
Research
Check if you are affected
Are You Affected By The NIS2 Directive?
Question No. 1
Have you previously been a critical infrastructure operator (KRITIS)?
If your company is already classified as KRITIS according to BSIG, it will automatically be affected by NIS2, as these are defined as a separate category in the directive.
Question No. 2
Are you one of the sectors affected?
Companies with at least 50 employees and an annual turnover of at least €10 million that fall into one of the affected sectors are affected by NIS2. This includes both public and private institutions.
Question No. 3
Does your company meet the defined thresholds for company size and count as a highly critical according to annex I or critical sector according to annex II?
Question No. 4
Are you one of the special cases?
Some specific cases of particularly important entities, such as qualified trust services, TLD registries and DNS services, are affected by the NIS2 Directive regardless of their size.