ccbash
← Insights
Security & Compliance

NIS2 is here – what to do now

The key obligations under NIS2 and how to implement them in operations without a paper war.

Illustration: shield covering interconnected servers, next to a person with a laptop

NIS2 affects far more companies than the previous critical-infrastructure rules – by common estimates tens of thousands in Germany alone. And unlike many compliance topics, NIS2 aims directly at IT operations: at processes, systems and service providers, not at binders on a shelf.

Am I in scope?

The directive distinguishes “essential” and “important” entities across 18 sectors – from energy and transport through manufacturing to digital services. The rule of thumb: from 50 employees or ten million euros of revenue in one of those sectors, you should no longer answer the scope question with an unchecked no. And even companies not directly in scope are often caught indirectly – as part of an affected customer’s supply chain.

The obligations, translated into operations language

Behind the directive’s articles are remarkably down-to-earth requirements:

  • Risk management: know, assess and treat risks – provably and repeatably, not once for the audit.
  • Incident handling and reporting: detect, manage and report incidents on deadline – first notification within 24 hours. That presupposes detection and the reporting path have been rehearsed beforehand.
  • Continuity: backup, recovery, crisis communication – tested, not merely documented.
  • Supply chain security: the security of your providers is your obligation. If operations are outsourced, requirements must be anchored in contracts – with a real right to verify them.
  • Management accountability: executives are liable, must approve the measures and undergo training themselves. NIS2 is a matter for the top floor – literally.

The point most companies miss

Most companies do not fail on technology but on the supply chain: they are expected to prove security that their provider operates. Without a contractual basis and a right to audit, every piece of evidence becomes a favour to ask for. This is where provider governance and compliance interlock – treat them separately and you pay twice.

Getting there without a paper war

The pragmatic path starts not with a binder but with an honest assessment: what already exists, what is genuinely missing, what is the risk? Requirements are then anchored where they are fulfilled – in processes, systems and contracts. Evidence emerges as a by-product of operations instead of a special project before the audit. Compliance anchored in operations costs effort once – compliance in a binder costs it again every year.

Let's talk about your IT.

A no-obligation first conversation – we listen and tell you honestly whether and how we can help.

Talk to us