NIS2 Directive · Cybersecurity

NIS2 - cybersecurity that stands up to regulatory scrutiny.

The EU is drastically tightening cybersecurity requirements - and for the first time is holding management personally liable. We assess whether you are in scope, close the gaps, and implement the technical measures.

Scope

Are you affected? The answer is yes more often than you might think.

NIS2 distinguishes between “essential” and “important” entities - and also covers many suppliers through the supply chain that previously believed they were unaffected.

01

Essential entities (soggetti essenziali)

Generally companies with at least 250 employees or €50 million in revenue in highly critical sectors: energy (electricity, photovoltaics, hydropower, district heating), transport, banking, financial markets, healthcare, drinking water, wastewater, digital infrastructure and public administration. Stricter supervision and proactive inspections.

02

Important entities (soggetti importanti)

Medium-sized companies with at least 50 employees or €10 million in revenue in other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing, research, and digital service providers. Supervision is reactive - but the obligations still apply in full.

Obligations under Art. 21

Ten areas of action that must demonstrably be applied in practice

Article 21 of NIS2 requires appropriate state-of-the-art risk management. We translate the requirements into concrete, audit-ready measures.

  • Risk analysis & security concept for information systems.
  • Security incident handling - detection, response, recovery.
  • Business continuity - backup management, emergency plans, crisis management.
  • Supply chain security including relationships with suppliers.
  • Security in procurement, development, and maintenance of systems.
  • Effectiveness assessment of cybersecurity measures.
  • Cyber hygiene & training for all employees.
  • Cryptography & encryption based on suitable concepts.
  • Access control & asset management - who is allowed to do what, and on which device.
  • Multi-factor authentication and secure communications.
Personal liability

Management is personally liable.

NIS2 requires management to approve the risk management measures, oversee their implementation, and receive regular training. For essential entities, breaches may be punished with fines of up to €10 million or 2% of worldwide annual turnover.

Unlike under previous regulatory frameworks, responsibility cannot be fully delegated. We prepare your leadership specifically for this role.

Free & completed in 2 minutes

NIS2 readiness check

Five questions about your NIS2 maturity. You receive an immediate initial assessment - with no email required.

Have you assessed whether NIS2 applies to you and, if so, what type of entity you are?

Sector, size (employees/revenue), and role in the supply chain.

Yes, our status has been assessed and documented
We have an assumption, but no reliable assessment
No / unknown
Frage 1 von 5

Have the risk management measures under Art. 21 been implemented?

Risk analysis, encryption, access control, MFA, business continuity.

Yes, comprehensively and with documentation
Basic measures, but with gaps
Barely / not in place

Do you have a functioning reporting process for security incidents?

24-hour early warning and 72-hour notification to the competent authority.

Yes, the process is defined and has been tested
On paper, but not rehearsed
No

Do you address the security of your supply chain and suppliers?

Requirements for service providers, contracts, and assessment of critical dependencies.

Yes, suppliers are assessed and contractually bound
Partially, only for selected service providers
No / not considered

Does your management actively fulfill its responsibilities?

Approval of measures, oversight of implementation, and regular training.

Yes, management is involved and trained
Awareness exists, but there is no established process
No / not addressed
Implementation with Nuviax

From scope assessment to audit-ready compliance

Step 01

Scope & gap analysis

We determine with legal certainty whether NIS2 applies to you and what type of entity you are, and assess the gap between your current state and the obligations under Art. 21.

Step 02

Implementation roadmap

You receive a prioritized plan covering effort, responsibilities, and deadlines - ordered by risk and impact, not alphabetically.

Step 03

Technical implementation

Our IT team implements encryption, MFA, access concepts, logging, backups, and infrastructure hardening - so you do not need a second service provider.

Step 04

Reporting process & training

We establish the 24/72-hour reporting process, train your team and management, and rehearse an actual incident in a tabletop exercise.

Step 05

Evidence & ongoing support

We produce audit-ready documentation, keep you up to date when authorities make inquiries, and provide ongoing support for your security posture.

From scope assessment to audit-ready compliance
Cybersecurity

NIS-2, ISO 27001, and security services

From NIS-2 to ISO 27001: we combine regulatory requirements with security and ISMS components for resilient operations.

01

Scope and requirements analysis

Assessment of whether NIS-2, DORA, CRA, or other EU requirements apply and which specific obligations arise from them.

02

Gap analysis and implementation plan

Comparison of the current security level with regulatory requirements, including a prioritized roadmap.

03

ISMS under ISO 27001

Establishment or further development of an information security management system with scope, policies, and risk and control structures.

04

Risk management and technical and organizational measures

Technical and organizational measures, supply chain security, access rights, emergency planning, and documentation of compliance.

05

Incident response

Reporting processes, escalation, documentation, and management responsibility for security incidents.

06

Cybersecurity compliance management

Continuous reviews instead of one-off project files - with training, audit preparation, and ongoing improvement.

ISO 27001

Five steps to a robust security concept

We treat IT security as an ongoing program - with clear steps from the initial assessment through continuous improvement.

Step 01

Gap and status check

Assessment of infrastructure, processes, documentation, risks, and applicable regulatory requirements.

Step 02

ISMS development and concepts

Scope, risk analysis, IAM/PAM, third parties, business continuity, and documentation are brought together.

Step 03

Training and awareness

Management and employees understand responsibilities, reporting channels, and secure working practices.

Step 04

Audit support

Preparation for internal and external audits, including evidence and action tracking.

Step 05

Operations and improvement

Regular reviews, KPIs, updates, and ISO 27001-aligned support as an ongoing service.

Security is an ongoing operationNIS-2, DORA, CRA, and the AI Act are considered together in the security concept.
FAQ

Frequently asked questions about NIS2

The EU deadline for national implementation was October 17, 2024; several Member States implemented it late. This does not change the substantive requirements: organizations in scope should establish the measures now instead of waiting for the final legislative deadline. Implementation and evidence take months in any event.
Directly, only if you meet the sector and size criteria yourself. Indirectly, very likely: NIS2 requires entities in scope to manage the security of their supply chain. Large customers pass these requirements on to you through contracts and audits - making a strong security posture a prerequisite for winning business.
You must submit an early warning within 24 hours, a notification with an initial assessment within 72 hours, and a final report no later than one month afterward. This schedule is difficult to meet without a rehearsed process - which is why we practice the procedure with you in advance.
Significantly. An information security management system operated in accordance with ISO/IEC 27001 already addresses a large proportion of the NIS2 requirements under Art. 21 in a structured way and provides the supporting evidence. We build NIS2 specifically on an existing ISMS or establish both together.

Cybersecurity you can demonstrate

Clarify whether you are in scope and identify the most effective next steps in 30 minutes - with consulting and implementation from a single provider.