NIS2 · Deadline expires

NIS2 Advice for the SMEs – technically implemented, demonstrable

The registration portal of the BSI is open, around 29,500 institutions in Germany are affected. We bring your IT up to the required level and ensure that you can prove what you have implemented.

technical implementationDemonstration
The clocks that run
Time limits set by NIS2
3 months
Registration with the BSI
After identifying the affected person within three months via the organization account.
24 hours
Initial reporting of an incident
Early warning to the BSI as soon as a significant security incident is detected.
72 hours
Incident reporting
Submit assessment, severity and previous findings.
1 month
Final report
Cause, impact and response.
The reporting deadlines are based on knowledge of a significant incident. Anyone who wants to comply with it needs a practiced process beforehand – not just a clarification of jurisdiction in an emergency.

Who NIS2 concerns

Three questions decide: In which sector are you active, how big are you – and for whom do you deliver?

Sector
18 sectors instead of fewer operators
NIS2 covers significantly more than the previous KRITIS regulation: energy, transport, health, digital infrastructure, waste management, food, chemicals, manufacturing and more. Many companies that have never seen themselves as critical infrastructure are now included.
Size
Usually from 50 employees
As a rule, institutions with 50 employees or 10 million euros annual turnover are considered “important”, 250 employees or 50 million euros as “particularly important”. The combination of sector and size is always decisive – and there are exceptions in both directions.
Supply chain
Even if you yourself are not affected
Anyone who produces or supplies software for an affected company becomes part of its security requirements. In practice, the pressure therefore often does not come from the law, but via questionnaire from the largest customer.

What to do concretely

Six areas where NIS2 requires action. The most complex is rarely the technique, but the proof that it works.

Registration with the BSI
The login runs through the organization account and then the BSI portal. Affected institutions have to register themselves – an official request does not come.
Implement risk management
State-of-the-art measures are required: access control, encryption, backup and recovery, vulnerability management, supply chain security and experienced handling of incidents.
Developing reporting channels
Who should report within 24 hours, needs previously clarified responsibilities, accessibility and templates. In an emergency, this no longer arises.
Evidence may lead to:
What is crucial is not only that measures exist, but that they are verifiable: protocols, documented tests, traceable changes.
Duty senior management
Management must approve, monitor and receive training. Failures threaten fines in the double-digit million range and personal liability.
Involving suppliers
Security does not end at your own firewall. Requirements for service providers and suppliers are part of contracts and regular auditing.

What we do – and what we do not

That's what we do
  • IT inventory of the required measures
  • Technical implementation: access, logging, backup, recovery
  • Monitoring and alerting so that incidents are even noticeable
  • Set up reporting channels and templates for the 24-hour case
  • Demonstration: protocols, tests, traceable changes
  • Make requirements for your service providers technically testable
This is part of legal advice
  • Legal determination whether you are affected
  • Contract drafting and legal audit
  • Representation of authorities

We are engineers, not lawyers. The classification of whether and in which category your company falls is part of the legal advice – we provide the technical facts and then work together with your law firm or your data protection officer.

Why this is different for SMEs

NIS2 was not written for the middle class, but hits him with full force. A company with 80 employees does not have a security department, but two people who keep everything going. For them, a catalogue of requirements according to the prior art is first a wall.

That is why we are breaking down the subject. Not everything has to happen at the same time, and not every measure is worth the same. At the beginning there is an inventory that says where you stand – then an order that follows the risk and not the order in the legal text.

The pressure is real: According to the situational picture of the BSI, almost 80 percent of all ransomware attacks are now aimed at SMEs. Attackers know that tangible values meet slim security budgets here. The duties from NIS2 force to what was already overdue.

  • Inventory rather than catalogue processingFirst see what is available – amazingly much it is usually already.
  • Sequence of riskWhat is most likely to be exploited comes first. Not what the law says above.
  • A contact person instead of a bodyThey talk to the same people who then implement the measures.
Your contact person in Stuttgart
Our office is located in Stuttgart-Wangen. We come to you for an inventory.
Clarification of the need for action
  • Initial consultation free of charge and without obligation
  • Also suitable if the affected is still unexplained
  • On request with initial assessment of the need for action

Select date

Frequent questions about NIS2

This is decided by the combination of sector and company size, plus a few special cases. The legal statement is part of the legal advice – we provide the technical facts and arrange what the answer would mean in practice. Often the question is also secondary: Who delivers for affected companies, get their requirements passed on anyway.
It helps considerably, but does not automatically cover everything. An existing management system provides the framework, the documentation and usually a large part of the measures. Specific points remain to be considered, such as reporting deadlines, supply chain requirements and management obligations.
Registration is an obligation the failure of which can be punished; the framework extends into the double-digit million range, in addition to the personal liability of the management. In practice, however, it is more important that a delayed registration can be made up; a security incident without functioning reporting channels cannot be made up.
We expect a robust inventory in weeks. How long the implementation takes depends on what already exists – and that is usually more than the participants think. Realistic is an approach over several months, with the riskiest gaps first.
Usually not. NIS2 does not require any particular technique, but rather state-of-the-art measures and proof that they work. Often it is about additions: logging, tested restoration, access concepts, monitoring. A complete conversion is almost never the right answer.
Yes, on request. Monitoring, alerting and regular inspection can be mapped via our managed services, with clear reaction times. Also possible is the transfer to your team, including documentation and practiced process.
Yes, and that is the rule. We bring in the technical side, the legal assessment remains where it belongs. Experience shows that this division of labor is much faster than if one side tries to do both.
Unclear where you stand?
This is the normal case and a good reason for a conversation. We arrange what comes your way, what you already fulfill and what you should start with – without fear of selling you.

Arrange free initial consultation