NIS 2 consulting – clarity instead of knee-jerk action

The NIS2UmsuCG (NIS2-Umsetzungsgesetz, the German act transposing the NIS 2 Directive into national law and amending the BSIG) makes IT security binding for companies in a large number of sectors, from healthcare through energy supply to food production. For many companies the first question is a very simple one: does this apply to us at all? We answer it before you spend money on measures you may not need.

Is your company in scope?

Whether you are in scope depends on three things: your sector, the size of your company and who your customers are. The last point is regularly overlooked. Even companies that do not fall under the directive themselves often have the requirements passed down to them by customers in regulated sectors.

An individual assessment settles the question. It usually takes a few hours and may well save you an entire project.

Who this service is for

What you get

Do you really have to implement NIS 2?

This question comes up in almost every first conversation. The honest answer: NIS 2 asks for nothing radical. At its core the directive requires measures that responsible companies should be taking anyway to protect their IT systems, their business processes and their ability to keep operating.

What changes is less the what than the proving it. You are probably doing much of this already – it is just not documented anywhere. That is where we start.

What NIS 2 asks for in practice

Article 21 of the directive names ten areas. They sound technical, but only some of them are:

The larger part of this is organisational. These points do not need new software; they need a rule, someone responsible and a record.

Who in the company answers for it

The directive places the obligation directly on the management level. The managing directors have to approve the measures, supervise their implementation and undergo training themselves. The work can be delegated to IT, the responsibility cannot.

In practice that means three things: a documented decision, regular reporting to management and evidence that management has been trained. We prepare all three so that they fit into meetings you already hold. Where a management system is running, we attach the reporting to the management review. Then no second cycle grows up alongside it.

How we work

  1. Establish whether you are in scope

    Sector, size, customer base, supply chain. The result is a written assessment. Duration: a few hours.

  2. Take stock

    What security measures, processes and documentation are already in place? In our experience, more than the people involved believe.

  3. Prioritise the actions

    Not everything at once. We sort by obligation, risk and effort. You decide the order and the pace.

  4. Implement and evidence

    Registration, reporting channels for significant security incidents, technical and organisational measures. And the evidence that shows, when it matters, that all of it works.

  5. Stay with it

    A reporting channel nobody knows about is no help. We train the people involved and check effectiveness in the internal audit.

Who handles this at our end

Rüdiger Rammé – IRCA certified and registered QMS / OHSMS Lead Auditor #01192806, specialist fields include ISO/IEC 27001 and information security. As a developer of databases and interfaces he knows both sides: the requirement and the system that has to meet it.

That is the difference from a pure security consultancy – when the evidence needs a technical solution, we build it.

Phone: +49 4131 2198634

How this looked in practice

Starting point: A small manufacturing business, classified as an important entity under the new law, with its own plant control systems in production and an already certified ISO management system. Legal advice had confirmed that it was in scope, and registration with the authorities had been completed. For implementation there was a checklist contributed by a third party. It was meant to serve as the basis.

Approach: The first step was to check that list rather than adopt it. It followed the 2013 edition of ISO 27001, whose transition period expired at the end of October 2025. The old edition lists 114 controls across 14 chapters, the current one 93 across four themes. Eleven controls in the new edition would not have been covered by the old list, among them topics that are central to a business with a production network. Three numbering errors came on top. After that, two separate question sets rather than one: 121 technical questions for the IT lead, 86 for the management, of which 36 cover the current state and 50 call for decisions. The split is deliberate, so that nobody is pushed into decisions that are not theirs to make. The scope expressly includes production technology, not just office IT.

Result: The business now holds a network overview, an asset inventory that carries through into risk assessment, and a signature-ready role description for information security, together with a roadmap towards the ten minimum measures required by law and the reporting deadlines of 24 hours, 72 hours and one month. The engagement is ongoing; evaluating the completed question sets is the next step.

The client's name, its sector and all details of the network remain confidential.

Frequently asked questions

What does NIS 2 consulting cost?

The scope assessment is a manageable start of a few hours. What comes after that depends entirely on what the assessment finds – from “you are not in scope, here are the reasons for your files” to an implementation project running over several months. After the assessment we tell you what to expect, before you commit to anything.

We already have ISO 27001 – do we still need anything?

You have then done a substantial part of it, but not all of it. NIS 2 contains duties that go beyond the standard, such as the registration and the reporting obligations with their deadlines. We assess the gap instead of selling you a second system.

Who is liable if we do nothing?

The directive places the obligation expressly on the management level. That is one of the reasons why the topic is currently landing on the managing director's desk so quickly.

Do you also do the technical implementation?

The organisational side and the evidence, yes, including bespoke database solutions. For running your IT infrastructure we work together with your existing service provider.

How long does the scope assessment take?

Usually a few hours, split between a conversation and the written evaluation.

Let us talk about it

The first conversation is free and without obligation. It usually takes half an hour. Afterwards you know what to expect and whether we are the right people for your project.

Prefer to write? The contact form reaches us just as well.