Back to All Services
NIS2 Deadline: October 2024

NIS2 Compliance
Consulting & Implementation

The new EU cybersecurity directive affects your business

The NIS2 directive has been in force since October 2024. We support you with gap analysis, action planning and complete implementation of all NIS2 requirements. Avoid fines up to €10 million or 2% of annual turnover.

⚠️ Act Now!

  • NIS2 is mandatory since October 2024
  • Fines up to €10 million or 2% annual turnover
  • Personal liability for management
  • Mandatory incident reporting (24h!)

Are You Affected by NIS2?

These sectors fall under the NIS2 directive

Essential Entities

Energy

Electricity, gas, oil, district heating, hydrogen

Transport

Air, rail, water, road

Banking

Credit institutions, payment service providers

Health

Hospitals, laboratories, pharma, medical devices

Digital Infrastructure

DNS, TLD, cloud, data centers, CDN

Public Administration

Central and regional authorities

Important Entities

Postal & Courier

Postal services, package delivery

Waste Management

Disposal, recycling

Chemicals

Chemical production and distribution

Food

Production, processing, distribution

Manufacturing

Medical devices, electronics, vehicles, machinery

Digital Services

Online marketplaces, search engines, social media

Size Criteria

You fall under NIS2 if you have:

  • At least 50 employees OR
  • Annual turnover > €10 million OR
  • Annual balance sheet > €10 million

NIS2 Requirements Overview

These measures you must implement

Risk Management

Systematic analysis and treatment of cybersecurity risks according to recognized standards

Incident Response

Processes for detection, analysis, containment and recovery from security incidents

Business Continuity

Backup management, disaster recovery, crisis management to maintain operations

Supply Chain Security

Security requirements for suppliers and service providers, third-party risk management

Secure Development

Security by design in procurement, development and maintenance of IT systems

Reporting Obligations

Early warning within 24h, notification within 72h, final report within 1 month

Our NIS2 Services

Comprehensive support from analysis to certification

1

NIS2 Gap Analysis

Where does your company stand? We analyze your current maturity level and identify all gaps to NIS2 compliance.

  • Current state analysis
  • Compliance gap identification
  • Risk assessment
  • Prioritized action list
2

NIS2 Roadmap & Planning

Based on the gap analysis, we create a realistic implementation plan with clear milestones.

  • Prioritized measures
  • Time and resource planning
  • Budget estimation
  • Quick wins identification
3

NIS2 Implementation

We accompany you in implementing all technical and organizational measures.

  • Policies & processes
  • Technical measures
  • Employee training
  • Documentation
4

NIS2 Audit & Certification

Preparation for audits by authorities and support for ISO 27001 certification.

  • Audit preparation
  • Internal audits
  • Certification support
  • Continuous improvement

NIS2 Implementation Timeline

Typical project timeline for mid-sized companies

Week 1-2

Kick-off & Scoping

Project start, stakeholder interviews, scope definition

Week 3-4

Gap Analysis

Current state analysis, document review, interviews, gap report

Week 5-6

Roadmap

Action planning, prioritization, resource planning

Week 7-16

Implementation

Implementation of measures, policies, technical controls

Week 17-18

Testing & Audit

Internal audits, penetration tests, audit preparation

Ongoing

Continuous Improvement

Monitoring, regular reviews, adjustments

Frequently Asked Questions about NIS2

Frequently Asked Questions

NIS2 (Network and Information Security Directive 2) is the new EU cybersecurity directive that has been in effect since October 2024. It replaces NIS1 and significantly expands the scope. The goal is a uniform, high level of cybersecurity in the EU. Non-compliance can result in fines up to €10 million or 2% of annual turnover.
You fall under NIS2 if you: 1) Operate in one of the 18 affected sectors (energy, transport, health, digital infrastructure, etc.) AND 2) have at least 50 employees OR annual turnover/balance sheet over €10 million. Smaller companies may also be affected if they provide critical services.
Costs vary greatly depending on company size and current maturity level. For a mid-sized company with 100-500 employees, expect €50,000-200,000 for initial implementation. Important: The costs of non-compliance (fines, reputational damage, business interruptions) are significantly higher!
A typical NIS2 project takes 4-6 months for initial compliance. More complex organizations need 6-12 months. We recommend starting NOW as the directive is already in force and authorities are beginning inspections.
Violations can result in: 1) Fines up to €10 million or 2% of worldwide annual turnover for essential entities 2) Fines up to €7 million or 1.4% for important entities 3) Personal liability of management 4) Temporary prohibition from management 5) Public disclosure of violations
Yes, very much! ISO 27001 covers many NIS2 requirements. If you are already ISO 27001 certified, you have a significant head start. We conduct a gap analysis to identify what additional measures are required for NIS2.

Have more questions? Our team is happy to help.

Get in Touch

Start Your NIS2 Compliance Today

Schedule a free initial consultation. We analyze if and how NIS2 affects you and create an initial implementation plan.