NIS 2 - EU DIRECTIVE - BSI

Registered does not mean ready

Hexagonal badge with checkmark and text saying Compliant NIS 2 Proks Certification.

You registered with BSI before the deadline. Good. Your CISO has been writing risk assessments. Better. Your board still thinks “we’re compliant” because the registration went through - and they’re wrong. Registration is paperwork. The first audit is in 2027, and €10 million or 2% of global turnover is the downside if you’re not ready.

Hexagonal badge with checkmark and text saying Compliant NIS 2 Proks Certification.
29,500

Organizations now pulled into scope in Germany

18

Regulated sectors across the directive

€10M / 2%

Maximum fine of €10million  - or 2% of global turnover

2027

First audits and enforcement actions arrive

1

THE DIRECTIVE

What NIS 2 actually is

A directive.
Not a certificate.
The first audit is in 2027.

Registration is paperwork - it tells the regulator you exist. It does not show your controls work. That is what the audit is for, and it arrives in 2027.

NIS 2 is an EU directive, transposed into German law on 6 December 2025, that expanded cybersecurity obligations to roughly 29,500 organizations across 18 sectors - energy, transport, healthcare, banking, drinking water, digital infrastructure, public administration, postal, chemicals, food, the manufacture of medical devices and electronics, digital providers and research.

It splits regulated organizations into two tiers - particularly important and important entities - with fines up to €10M or €7M respectively. It introduces personal liability for executives, a strict incident-reporting cadence of 24 hours, 72 hours and 30 days, and a requirement for audit-ready evidence by 2027. There is no NIS 2 certificate to “get” - only evidence to produce, and ISO/IEC 27001:2022 is the most defensible way to produce it.

2

THE FIT

Who actually needs to act

NIS 2 stops being someone else’s problem the moment one of these describes you.

01
You are in one of the 18 sectors with 50+ employees or €10M+ revenue.

The threshold catches scale-ups, not just enterprises. If your headcount or turnover crosses the line and your sector is listed, you are in scope - directly.

02
You are a public-sector entity, digital-infrastructure provider or healthcare cloud.

Regulators are watching these categories first. Expect to be early in the queue when enforcement begins.

03
You already have ISO/IEC 27001:2022 and want to know if it is enough.

Short answer: it covers 70–80% of NIS 2’s substantive expectations. Long answer: it depends on your sector and scope - which is exactly what a gap assessment settles.

04
You are a critical supplier to a regulated entity.

Even if you’re not directly in scope, your customers are - and they will push their obligations down the supply chain. That’s how regulation works.

If none of these describe you - wait. If even one does - yesterday was the best time to start.

3

THE PAYOFF

What you actually get from getting ready

We could write four paragraphs of marketing copy - instead:

I.

Avoid the €10M downside. Not hypothetical. The first enforcement actions arrive in 2027 - and the fines reach €10 million or 2% of global turnover.

II.

Replace BSI registration with audit-ready evidence. Most companies that registered have nothing real to show yet. The ones that do will be tomorrow’s preferred suppliers.

III.

Cover NIS 2, ISO/IEC 27001:2022, DORA and VAIT in one program. These regimes have 60–80% overlap. Don’t pay three consultants for the same evidence.

IV.

Protect executives personally. NIS 2 introduces director-level liability. Documented governance is the only defense.

V.

Win contracts competitors lose. Procurement teams in regulated sectors are starting to require NIS 2 evidence from suppliers. Be ready first.

4

SCOPE - THE 18 SECtorS

Eighteen sectors, two levels of criticality

NIS 2 reaches across eighteen sectors, grouped by how critical they are to society and the economy. If your sector is listed and you cross the size threshold, the directive applies - directly to you, and indirectly to the suppliers you depend on.

SECTORS OF HIGH CRITICALITY
01
Energy
02
Transport
03
Banking
04
Healthcare
05
Financial markets
06
Drinking water
07
Waste water
08
Digital infrastructure
09
Public administration
OTHER CRITICAL SECTORS
10
Postal
11
Courier
12
Chemicals
13
Food
14
Waste Management
15
Digital providers
16
Research
17
Manufacturing - electronics
18
Manufacturing - medical devices

5

TWO ENTITY TIERS

The tier you fall into sets the size of the fine

Every regulated organization is classed into one of two tiers. The substantive duties are much the same — the penalty ceiling and the intensity of oversight are not.

Particularly important entities

STRICTEST OVERSIGHT

The most critical operators - energy, transport, banking, digital infrastructure and the like at scale. They carry the heaviest exposure under the directive.

MAXIMUM FINE

€10 million

OR % OF GLOBAL TURNOVER

2%

EXECUTIVE LIABILITY

Personal

REPORTING DUTIES

24h / 72h / 30d

Important entities

MODERATE OVERSIGHT

Still in scope, still regulated, still audited - but a tier below the most critical operators in both oversight intensity and penalty ceiling.

MAXIMUM FINE

€7 million

OR % OF GLOBAL TURNOVER

1.4%

EXECUTIVE LIABILITY

Personal

REPORTING DUTIES

24h / 72h / 30d

6

INCIDENT REPORTING

The clock starts the moment you notice

NIS 2 imposes a fixed reporting cadence on significant incidents - three deadlines, each measured from the moment you become aware. Missing them is itself a breach.

24 hours
Early warning

An initial incident notification to the authorities within 24 hours of becoming aware of a significant incident.

72 hours
Detailed report

A fuller incident report within 72 hours - assessment, severity, indicators of compromise and any cross-border impact.

30 days
Final report

A final report within one month: root cause, the full course of the incident and the mitigation measures applied.

Personal liability for executives

NIS 2 makes cybersecurity a board-level duty: directors are personally accountable for governance, and audit-ready evidence is required by 2027. Documented governance is the only defense.

7

THE READINESS PROGRAM

From scope to audit-ready, in four steps

There’s no certificate to chase - there is a structured path to defensible evidence. One coordinator, one evidence pool, one outcome that satisfies regulators and procurement teams at the same time.

01

STEP 1

Scope analysis

We confirm whether - and how - NIS 2 applies to you: which sector, which entity tier, and where the supply-chain obligations reach. No guesswork about whether the directive bites.

02

STEP 2

Gap assessment

We map your current posture against NIS 2’s substantive requirements, reusing any ISO/IEC 27001:2022 evidence you already hold - which covers 70–80% of the expectations out of the box.

03

STEP 3

Prioritized roadmap

A clear, sequenced plan that closes the gaps that matter most first - risk-led, not checklist-led - so effort lands where regulators and procurement teams actually look.

04

STEP 4

ISO/IEC 27001 capstone

ISO/IEC 27001:2022 certification as the audit-ready capstone: one outcome that satisfies regulators and procurement teams simultaneously, and the most defensible evidence your controls are effective.

8

ONE PROGRAM - MANY REGIMES

Build the evidence once. Satisfy four regimes.

NIS 2, ISO/IEC 27001:2022, DORA and VAIT share 60-80% of their substantive requirements. There is no reason to pay three consultants to assemble the same evidence three times.

Our program runs them from a single evidence pool with ISO/IEC 27001:2022 as the audit-ready capstone - the most defensible piece of evidence a regulator will accept when they ask, “show me your controls are effective.” One coordinator owns the engagement from scope analysis through certification.

REGIMES ONE EVIDENCE POOL CAN FEED

ISO/IEC 27001:2022

DORA

VAIT

ISO 22301

IEC 62443

ISO/IEC 27019

KRITIS

GET IN TOUCH

Start your application process
now

Stop struggling with paperwork. Experience a streamlined, digital audit process that moves as fast as you do.

9

FAQs

Clear answers, the same way we run an audit

Is there a "NIS 2 certificate" we can get?

We already hold ISO/IEC 27001:2022 - is that enough for NIS 2?

We are not directly in scope - does NIS 2 still affect us?

We registered with BSI before the deadline - aren't we compliant?

Which tier are we in, and what are the fines?

What does the Proks readiness program actually involve?