Request a consultation

focus area · cybersecurity as an obligation

NIS 2: Cybersecurity Obligations for Companies

The NIS 2 Directive extends the EU's cybersecurity obligations to far more companies. In Germany it is implemented by the NIS 2 implementation act; the BSI is the competent authority. Affected are not only operators of critical infrastructure but many mid-sized companies from 50 employees in 18 sectors — and indirectly their suppliers. We help with classification, implementation and the interplay with AI systems.

Who falls under NIS 2

NIS 2 distinguishes “particularly important” and “important” entities. Sector and size are decisive: as a rule, companies from 50 employees or €10 million turnover are affected if they operate in one of the sectors — including energy, transport, health, water, digital infrastructure, ICT service management, postal services, waste, chemicals, food, manufacturing (incl. mechanical engineering, vehicle construction, medical devices, electronics), digital service providers and research.

Unlike earlier rules there are no official notices: companies must check themselves whether they are affected and register with the BSI. Suppliers not covered by the law themselves are effectively included via their customers' supply chain obligations.

The central obligations

The law requires a minimum level of risk management — appropriate, proportionate and documented.

Risk management

Concepts for risk analysis and information system security, incident handling, business continuity and crisis management.

Reporting duties

Significant security incidents: early warning within 24 hours, notification within 72 hours, final report within one month to the BSI.

Supply chain

Security in the supply chain and with service providers; requirements for procurement, development and maintenance.

Technology & organisation

Cryptography, access control, multi-factor authentication, vulnerability management, employee training.

Registration

Registration with the BSI including a point of contact; evidence obligations for particularly important entities.

Management

Management must approve and monitor measures and be trained itself — and is personally liable for violations.

What NIS 2 means for AI systems

AI systems are information systems within the meaning of the law. Anyone operating language models, agents or automations must include them in risk management: access, data flows, interfaces, providers. External AI providers are service providers in the supply chain — with the corresponding requirements for contracts and review.

At the same time AI helps with implementation: evaluating logs, detecting anomalies, prioritising vulnerabilities and preparing notifications within the tight deadlines. Here too: people decide, AI prepares — and its use is documented.

  • AI inventory as part of asset recording (see AI Audit & Screening)
  • Guardrails and logging of AI systems as a security measure
  • Provider assessment of AI services by supply chain criteria
  • AI-supported log analysis and preparation of notifications

Implementing NIS 2, ISO 27001, EU AI Act and GDPR together

Those already working to ISO 27001 or TISAX have structurally met a large part of the NIS 2 requirements — what is usually missing is registration, reporting processes and the formal involvement of management. Conversely, NIS 2 provides the occasion to build an information security management system that also serves the EU AI Act and GDPR. We plan implementation so that measures are built once and evidenced for all frameworks.

Sanctions and timeline

For particularly important entities, fines of up to €10 million or 2% of global annual turnover are provided, for important entities up to €7 million or 1.4%. Add BSI orders and the personal liability of management. The law is in force; registration and evidence deadlines are running. We check specific deadlines and the current state of implementation with you at project start, as details are updated through regulations and BSI requirements.

privacy first ai

Security is a leadership task — NIS 2 makes it binding

Management must approve, monitor and understand measures. We translate the law into an implementation plan that leadership can carry — and into measures that work day to day.

Classification

Applicability, entity type and sector documented traceably — as the basis for registration and audits.

Implementation

Risk management, reporting processes and supply chain requirements with clear owners and evidence.

Training

Management and employees are trained — eligible for funding through our AZAV-certified offerings.

process

How NIS 2 implementation runs

Four steps from applicability check to verifiable operation.

  1. Step 1: Applicability & gap analysis

    Classification by sector and size, comparison of existing measures with the obligations, assessment of the supply chain.

  2. Step 2: Action plan

    Prioritised measures for technology, organisation and reporting processes; inclusion of AI systems and providers.

  3. Step 3: Implementation & training

    Introduction of measures, registration with the BSI, training of management and employees.

  4. Step 4: Operation & evidence

    Regular operation with monitoring, exercises for the reporting case, documentation for evidence and audits.

contact

Let's talk

Happy to help with anything AI. We will get back to you promptly.

AddressCarolastraße 4-6, 09111 Chemnitz

Get in touch