Inhalt.
NIS2 has been part of German law since October 2024. Even so, many mid-sized companies still treat it as something to deal with next quarter. In 2026 that becomes a problem: the first official inspections are running, the first fines are being collected, and insurers are starting to require NIS2 compliance as a condition for cyber policies.
This article summarises what we, as an IT provider for mid-market clients, think actually needs doing. It does not replace legal advice, and it is not a complete checklist. It is the minimum set of measures that currently gets our clients through audit conversations.
Are you even in scope?
The first question is not “how do we comply with NIS2?” but “does NIS2 apply to us?”. Three paths lead there:
-
Direct sector relevance. If your company operates in one of the 18 essential or important sectors (energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space, post, waste, chemicals, food, manufacturing, digital services, research) AND you cross the size thresholds (50+ staff or 10+ million EUR turnover as important; 250+ or 50+ million as essential), you are obliged.
-
Supply chain relevance. Even if you are not directly in scope, clients from affected sectors can require NIS2-compliant processes from you. We are seeing this right now with automotive suppliers, energy service providers and medical suppliers: OEMs and operators pass their obligations down by contract.
-
Insurance relevance. Cyber insurers increasingly require NIS2-equivalent controls, even where there is no legal obligation. If you want to keep or renew your cyber policy, you should have the main NIS2 measures in place.
If none of that applies to you, read on anyway. The measures described are sensible independently of NIS2.
The seven core measures
Article 21 of NIS2 lists the requirements for “technical, operational and organisational measures”. Condensed, that comes down to seven fields of action:
1. Risk management concept
You need a documented process for identifying, assessing and prioritising cyber risks. That is not a 200-page spreadsheet, but it is also not a half-page PDF. A pragmatic risk management document covers:
- A list of critical systems (mail, file servers, ERP, accounting, production IT)
- An assessment of confidentiality, integrity and availability per system
- Identified threats and the protective measures currently in place
- Residual risk and measures to reduce it
We typically produce a document like that in two to four weeks of project work with our clients.
2. Incident response plan
What happens when there is a cyber incident? NIS2 requires notification within 24 hours (early warning) and 72 hours (initial report). Without a prepared plan those deadlines will not be met. The plan should:
- Define escalation paths, internal and external
- Hold reporting templates ready for the BSI and other authorities
- Have forensics providers contracted in advance
- Include communication templates for clients and press
3. Backup and recovery
Backups are not NIS2-specific, but NIS2 makes verification mandatory. That means backups must not only exist, they must demonstrably work. We recommend monthly test restores with a written record. The 3-2-1 rule (three copies, two media, one off site) is the standard; in ransomware-exposed environments, an offline or air-gapped copy on top.
4. Access management
Multi-factor authentication for every external access route, documented permission concepts, regular access reviews, prompt deletion of accounts when people leave. Concretely: in audit preparation we regularly find former employees who still have access to client portals. That is the single point at which a NIS2 audit will certainly fail.
5. Supply chain security
You have to document which external providers have access to your systems and how you assess their security. For cloud providers that usually means a data processing agreement, SOC 2 or ISO 27001 evidence, and documentation of the data categories involved. For smaller providers a security self-assessment is often enough.
6. Basic IT hygiene
Patch management, endpoint protection, network segmentation, secure configuration baselines, encryption of storage media. This is everyday operational work, but NIS2 requires evidence. We recommend making the key points measurable in monitoring (patch status, EDR coverage, backup success).
7. Training
Management and staff have to be trained regularly. The obligation on directors is written explicitly into NIS2 and cannot be delegated. We work with mandatory annual training and phishing simulations at irregular intervals.
What it realistically costs in effort
An honest assessment for a mid-sized company with 50 to 250 workstations:
- Initial effort: 30 to 80 person-days over three to six months, roughly half of that external consulting and implementation
- Ongoing effort: 0.5 to 1.5 days per month for operations, monitoring and evidence
- Initial budget: typically 15,000 to 40,000 EUR in external costs (consulting, tool adjustments, training)
- Ongoing budget: 200 to 500 EUR per month for monitoring, evidence and tool licences
That is a lot, but it is not a leap into the void. Most of the measures are sensible anyway. NIS2 only forces you to do them now instead of postponing them again.
How we support this
We have a structured approach to NIS2 preparation:
- A four-hour screening conversation. Together we establish whether you are in scope at all and where the biggest gaps are.
- Gap analysis. We assess the current state against NIS2 and produce a prioritised action plan.
- Implementation support. We build the technical measures and coordinate the organisational ones with your legal advisors.
- Audit preparation. We prepare the evidence for an official or insurance review.
This is not a one-off service. NIS2 compliance is a process, not a certificate. We support existing clients on an ongoing basis with the documentation obligations and monitoring reports.
If you are unsure where you stand, arrange an intro call. The first 30 minutes are always free.