COMPLIANCE · NIS-2

NIS-2 requiresdemonstrablerisk management.

Directive (EU) 2022/2555 significantly expands the set of covered entities and holds the management body personally accountable. In Germany it has applied since 6 December 2025 through the recast BSI-Gesetz. We deliver the technical evidence for the core risk-management obligations.

01 · SCOPE

Who falls under NIS-2 – and why the obligations already bind.

NIS-2 distinguishes between essential and important entities and covers far more sectors than its predecessor: energy, transport, health, digital infrastructure, public administration, providers of digital services, manufacturers of critical products and more. Germany transposed the directive through the NIS2UmsuCG: the resulting BSI-Gesetz has applied since 6 December 2025. It uses the categories besonders wichtige Einrichtung and wichtige Einrichtung and as a rule derives them in §28 BSIG from sector, headcount, turnover and balance sheet total – though some categories, qualified trust service providers and DNS service providers among them, are covered regardless of size. Anyone in scope has been directly obliged ever since – to register with the BSI under §33 BSIG, to run risk management under §30 BSIG and to report significant security incidents under §32 BSIG. For telecommunications providers, for energy companies subject to §§5c to 5e EnWG and for Finanzunternehmen, which are governed by DORA instead, §28 Abs. 5 and Abs. 6 BSIG do however disapply those risk-management, reporting and management-body duties in whole or in part; the registration duty under §33 BSIG stands in all three cases.

02 · OBLIGATIONS

The four blocks we plug into technically.

  1. BLOCK · 01

    Risk management measures (§30 BSIG)

    §30 BSIG obliges besonders wichtige and wichtige Einrichtungen to take appropriate, proportionate and effective technical and organisational measures reflecting the state of the art. The catalogue in §30 Abs. 2 BSIG explicitly names vulnerability handling and disclosure (Nr. 5), access control (Nr. 9) and policies and procedures to assess the effectiveness of those measures (Nr. 6). Penetration testing and continuous vulnerability management provide exactly that evidence – documented, as §30 Abs. 1 BSIG requires.

  2. BLOCK · 02

    Incident reporting obligations (§32 BSIG)

    Under §32 Abs. 1 BSIG a significant security incident must be reported within 24 hours as an early warning and within 72 hours as an assessed notification carrying a severity rating and indicators of compromise; the BSI may request interim reports on top (Nr. 3), and the final report follows no later than one month after the 72-hour notification (Nr. 4). We prepare the forensic data baseline and the communication workflows that hold up under that time pressure.

  3. BLOCK · 03

    Management body accountability (§38 BSIG)

    §38 BSIG obliges management bodies to implement the risk-management measures required under §30 BSIG and to oversee that implementation; §38 Abs. 3 BSIG additionally requires regular training. Managers who breach those duties are liable to their own entity for culpably caused damage (§38 Abs. 2 BSIG). Our reports are deliberately structured so they can be signed off by the management body.

  4. BLOCK · 04

    Evidence towards the supervisor (§§61 and 62 BSIG)

    Under §61 Abs. 1 BSIG the BSI may order individual besonders wichtige Einrichtungen to have audits, reviews or certifications carried out by independent bodies; from all other besonders wichtige Einrichtungen it may request evidence at the earliest three years after the act entered into force, and from zugelassene Krankenhäuser under §108 SGB V at the earliest five years unless a Rechtsverordnung under §56 Abs. 6 BSIG sets an earlier date (§61 Abs. 3 BSIG). For wichtige Einrichtungen, supervision under §62 BSIG applies once facts suggest a breach. We document tests, findings and retests in a form that holds up to such a review.

03 · OUR CONTRIBUTION

How penetration testing makes NIS-2 risk management measurable.

Risk management measures are only as good as the evidence of their effectiveness. We test the relevant attack paths against your production environment, document findings along your control objectives and deliver a retest that proves remediation. The result is an evidence chain that withstands audits and regulatory inquiries.

RELATED FRAMEWORKS

Adjacent regulation we also test against.

NIS-2 PREPARATION

NIS-2 puts management on the hook. We make you demonstrably compliant.

We examine with you which NIS-2 obligations concretely apply to your organisation today and which technical evidence is still missing.