
You registered with BSI before the deadline. Good. Your CISO has been writing risk assessments. Better. Your board still thinks “we’re compliant” because the registration went through - and they’re wrong. Registration is paperwork. The first audit is in 2027, and €10 million or 2% of global turnover is the downside if you’re not ready.
Organizations now pulled into scope in Germany
Regulated sectors across the directive
Maximum fine of €10million - or 2% of global turnover
First audits and enforcement actions arrive
1
NIS 2 is an EU directive, transposed into German law on 6 December 2025, that expanded cybersecurity obligations to roughly 29,500 organizations across 18 sectors - energy, transport, healthcare, banking, drinking water, digital infrastructure, public administration, postal, chemicals, food, the manufacture of medical devices and electronics, digital providers and research.
It splits regulated organizations into two tiers - particularly important and important entities - with fines up to €10M or €7M respectively. It introduces personal liability for executives, a strict incident-reporting cadence of 24 hours, 72 hours and 30 days, and a requirement for audit-ready evidence by 2027. There is no NIS 2 certificate to “get” - only evidence to produce, and ISO/IEC 27001:2022 is the most defensible way to produce it.
2
NIS 2 stops being someone else’s problem the moment one of these describes you.
The threshold catches scale-ups, not just enterprises. If your headcount or turnover crosses the line and your sector is listed, you are in scope - directly.
Regulators are watching these categories first. Expect to be early in the queue when enforcement begins.
Short answer: it covers 70–80% of NIS 2’s substantive expectations. Long answer: it depends on your sector and scope - which is exactly what a gap assessment settles.
Even if you’re not directly in scope, your customers are - and they will push their obligations down the supply chain. That’s how regulation works.
3
We could write four paragraphs of marketing copy - instead:
Avoid the €10M downside. Not hypothetical. The first enforcement actions arrive in 2027 - and the fines reach €10 million or 2% of global turnover.
Replace BSI registration with audit-ready evidence. Most companies that registered have nothing real to show yet. The ones that do will be tomorrow’s preferred suppliers.
Cover NIS 2, ISO/IEC 27001:2022, DORA and VAIT in one program. These regimes have 60–80% overlap. Don’t pay three consultants for the same evidence.
Protect executives personally. NIS 2 introduces director-level liability. Documented governance is the only defense.
Win contracts competitors lose. Procurement teams in regulated sectors are starting to require NIS 2 evidence from suppliers. Be ready first.
4
NIS 2 reaches across eighteen sectors, grouped by how critical they are to society and the economy. If your sector is listed and you cross the size threshold, the directive applies - directly to you, and indirectly to the suppliers you depend on.
5
Every regulated organization is classed into one of two tiers. The substantive duties are much the same — the penalty ceiling and the intensity of oversight are not.
STRICTEST OVERSIGHT
The most critical operators - energy, transport, banking, digital infrastructure and the like at scale. They carry the heaviest exposure under the directive.
€10 million
2%
Personal
24h / 72h / 30d
MODERATE OVERSIGHT
Still in scope, still regulated, still audited - but a tier below the most critical operators in both oversight intensity and penalty ceiling.
€7 million
1.4%
Personal
24h / 72h / 30d
6
NIS 2 imposes a fixed reporting cadence on significant incidents - three deadlines, each measured from the moment you become aware. Missing them is itself a breach.
An initial incident notification to the authorities within 24 hours of becoming aware of a significant incident.
A fuller incident report within 72 hours - assessment, severity, indicators of compromise and any cross-border impact.
A final report within one month: root cause, the full course of the incident and the mitigation measures applied.
NIS 2 makes cybersecurity a board-level duty: directors are personally accountable for governance, and audit-ready evidence is required by 2027. Documented governance is the only defense.
7
There’s no certificate to chase - there is a structured path to defensible evidence. One coordinator, one evidence pool, one outcome that satisfies regulators and procurement teams at the same time.
STEP 1
We confirm whether - and how - NIS 2 applies to you: which sector, which entity tier, and where the supply-chain obligations reach. No guesswork about whether the directive bites.
STEP 2
We map your current posture against NIS 2’s substantive requirements, reusing any ISO/IEC 27001:2022 evidence you already hold - which covers 70–80% of the expectations out of the box.
STEP 3
A clear, sequenced plan that closes the gaps that matter most first - risk-led, not checklist-led - so effort lands where regulators and procurement teams actually look.
STEP 4
ISO/IEC 27001:2022 certification as the audit-ready capstone: one outcome that satisfies regulators and procurement teams simultaneously, and the most defensible evidence your controls are effective.
8
NIS 2, ISO/IEC 27001:2022, DORA and VAIT share 60-80% of their substantive requirements. There is no reason to pay three consultants to assemble the same evidence three times.
Our program runs them from a single evidence pool with ISO/IEC 27001:2022 as the audit-ready capstone - the most defensible piece of evidence a regulator will accept when they ask, “show me your controls are effective.” One coordinator owns the engagement from scope analysis through certification.
ISO/IEC 27001:2022
DORA
VAIT
ISO 22301
IEC 62443
ISO/IEC 27019
KRITIS
Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.
9