NIS 2 consulting – clarity instead of knee-jerk action
The NIS2UmsuCG (NIS2-Umsetzungsgesetz, the German act transposing the NIS 2 Directive into national law and amending the BSIG) makes IT security binding for companies in a large number of sectors, from healthcare through energy supply to food production. For many companies the first question is a very simple one: does this apply to us at all? We answer it before you spend money on measures you may not need.
Is your company in scope?
Whether you are in scope depends on three things: your sector, the size of your company and who your customers are. The last point is regularly overlooked. Even companies that do not fall under the directive themselves often have the requirements passed down to them by customers in regulated sectors.
An individual assessment settles the question. It usually takes a few hours and may well save you an entire project.
Who this service is for
- You have heard that NIS 2 might apply to you, but you cannot find a reliable answer in the summaries on the web
- A customer in a regulated sector has sent you an information security questionnaire
- You know that you are in scope and are looking for somebody who translates the requirements into steps you can act on
- You already run a management system to ISO 9001 and want to fit the security requirements into it rather than set up a second system alongside
What you get
- A written assessment of whether you are in scope – with reasons, not just a yes or no
- An overview of the specific requirements for your sector, translated into your language
- A prioritised list of actions: what you have to do first, what can wait, what you already meet
- Support with the registration at the BSI (Bundesamt für Sicherheit in der Informationstechnik, the German federal information security authority)
- On request, the implementation of the technical and organisational measures, including the evidence that proves them
Do you really have to implement NIS 2?
This question comes up in almost every first conversation. The honest answer: NIS 2 asks for nothing radical. At its core the directive requires measures that responsible companies should be taking anyway to protect their IT systems, their business processes and their ability to keep operating.
What changes is less the what than the proving it. You are probably doing much of this already – it is just not documented anywhere. That is where we start.
What NIS 2 asks for in practice
Article 21 of the directive names ten areas. They sound technical, but only some of them are:
- Know your risks – which systems carry your business, and what it means when they fail
- Handle incidents – who notices an attack, who decides, who reports it, and within what deadline
- Keep working – backups that have demonstrably been restored, and a plan for a crisis
- Check the supply chain – your IT service providers and software suppliers are part of your own security level
- Buy and maintain securely – requirements for purchasing, development, updates and how you deal with vulnerabilities
- Assess effectiveness – show that the measures work, not just that they exist
- Train staff – basic rules for everyone who uses a computer
- Encrypt – a rule stating what is encrypted when, and why
- Order your access rights – who may do what, who has left, which devices belong to the company
- Secure your logins – multi-factor authentication and a communication channel that still works in an emergency
The larger part of this is organisational. These points do not need new software; they need a rule, someone responsible and a record.
Who in the company answers for it
The directive places the obligation directly on the management level. The managing directors have to approve the measures, supervise their implementation and undergo training themselves. The work can be delegated to IT, the responsibility cannot.
In practice that means three things: a documented decision, regular reporting to management and evidence that management has been trained. We prepare all three so that they fit into meetings you already hold. Where a management system is running, we attach the reporting to the management review. Then no second cycle grows up alongside it.
How we work
Establish whether you are in scope
Sector, size, customer base, supply chain. The result is a written assessment. Duration: a few hours.
Take stock
What security measures, processes and documentation are already in place? In our experience, more than the people involved believe.
Prioritise the actions
Not everything at once. We sort by obligation, risk and effort. You decide the order and the pace.
Implement and evidence
Registration, reporting channels for significant security incidents, technical and organisational measures. And the evidence that shows, when it matters, that all of it works.
Stay with it
A reporting channel nobody knows about is no help. We train the people involved and check effectiveness in the internal audit.
Who handles this at our end
Rüdiger Rammé – IRCA certified and registered QMS / OHSMS Lead Auditor #01192806, specialist fields include ISO/IEC 27001 and information security. As a developer of databases and interfaces he knows both sides: the requirement and the system that has to meet it.
That is the difference from a pure security consultancy – when the evidence needs a technical solution, we build it.
Phone: +49 4131 2198634
How this looked in practice
Starting point: A small manufacturing business, classified as an important entity under the new law, with its own plant control systems in production and an already certified ISO management system. Legal advice had confirmed that it was in scope, and registration with the authorities had been completed. For implementation there was a checklist contributed by a third party. It was meant to serve as the basis.
Approach: The first step was to check that list rather than adopt it. It followed the 2013 edition of ISO 27001, whose transition period expired at the end of October 2025. The old edition lists 114 controls across 14 chapters, the current one 93 across four themes. Eleven controls in the new edition would not have been covered by the old list, among them topics that are central to a business with a production network. Three numbering errors came on top. After that, two separate question sets rather than one: 121 technical questions for the IT lead, 86 for the management, of which 36 cover the current state and 50 call for decisions. The split is deliberate, so that nobody is pushed into decisions that are not theirs to make. The scope expressly includes production technology, not just office IT.
Result: The business now holds a network overview, an asset inventory that carries through into risk assessment, and a signature-ready role description for information security, together with a roadmap towards the ten minimum measures required by law and the reporting deadlines of 24 hours, 72 hours and one month. The engagement is ongoing; evaluating the completed question sets is the next step.
The client's name, its sector and all details of the network remain confidential.
Related topics
Frequently asked questions
What does NIS 2 consulting cost?
The scope assessment is a manageable start of a few hours. What comes after that depends entirely on what the assessment finds – from “you are not in scope, here are the reasons for your files” to an implementation project running over several months. After the assessment we tell you what to expect, before you commit to anything.
We already have ISO 27001 – do we still need anything?
You have then done a substantial part of it, but not all of it. NIS 2 contains duties that go beyond the standard, such as the registration and the reporting obligations with their deadlines. We assess the gap instead of selling you a second system.
Who is liable if we do nothing?
The directive places the obligation expressly on the management level. That is one of the reasons why the topic is currently landing on the managing director's desk so quickly.
Do you also do the technical implementation?
The organisational side and the evidence, yes, including bespoke database solutions. For running your IT infrastructure we work together with your existing service provider.
How long does the scope assessment take?
Usually a few hours, split between a conversation and the written evaluation.
Let us talk about it
The first conversation is free and without obligation. It usually takes half an hour. Afterwards you know what to expect and whether we are the right people for your project.
- Rüdiger Rammé, Lüneburg – phone: +49 4131 2198634
- Marion Rammé, Hamburg
- Email: all@bout-quality.de
Prefer to write? The contact form reaches us just as well.