The EU's NIS2 Directive brings far more companies under mandatory cybersecurity standards than ever before. Germany's national implementation (NIS2-UmsuCG) affects an estimated 30,000 companies. Most of those affected have not yet started. Here is the roadmap.
Who Is Affected
NIS2 distinguishes between essential and important entities. Essential entities are large companies in highly critical sectors (energy, transport, banking, healthcare, digital infrastructure). Important entities are medium-sized companies in these and additional sectors (postal services, food, chemicals, digital providers).
Thresholds:
- Medium-sized company: 50–249 employees or annual turnover of €10–50 million
- Large company: 250+ employees or annual turnover above €50 million
The Obligations at a Glance
1. Risk Management Measures (Art. 21)
- Policies on risk analysis and information system security
- Handling of cybersecurity incidents
- Business continuity management (BCM)
- Supply chain security
- Security in the acquisition, development and maintenance of IT systems
- Policies to assess the effectiveness of the measures
- Policies on cryptography and encryption
- Human resources security (awareness, access control)
- Multi-factor authentication
2. Reporting Obligations (Art. 23)
- Early warning: within 24 hours of becoming aware of a significant cybersecurity incident
- Incident notification: within 72 hours of becoming aware — including an initial assessment
- Final report: no later than 1 month after notification
3. Management Accountability
Company management must approve the cybersecurity measures and oversee their implementation. Mandatory training for executives. Personal liability in the event of non-compliance.
Non-compliance carries fines of up to €10 million or 2% of global annual turnover (for essential entities). For important entities: €7 million or 1.4% of turnover. Plus personal sanctions for executives.
The 6-Month Roadmap
Month 1: Scope Assessment
- Assessment: sector + size ⇒ essential / important / out of scope
- If in scope: mandatory registration with the BSI
- Inventory of existing security measures
Months 2–3: Gap Analysis & Concept
- Gap analysis against NIS2 requirements
- Risk analysis with threat modelling
- Prioritised measures roadmap
- Executive workshop
Months 4–5: Implementing the Core Measures
- MFA rollout across all access points
- EDR/XDR endpoint protection
- Backup strategy + disaster recovery exercise
- Documented incident response plan
- Awareness training for all employees
Month 6: Documentation & Audit
- ISMS documentation
- Internal audit of all measures
- Evidence compilation for BSI review
- Ongoing awareness mechanisms in place
What we do at TABAK
For every client within NIS2 scope, we deliver a complete NIS2 package: scope assessment, gap analysis, roadmap, implementation of the technical measures, ISMS documentation. We coordinate technical delivery with our data centre partner DAVINCIRechenzentrum. Typical project duration: 4–6 months. Typical cost: €25,000–80,000, depending on company size.
Find out if NIS2 applies to you.
In a free initial consultation, we clarify whether you fall under NIS2 and what implementation would involve in your case.