nis2
NIS2 and ISMS: What Your Existing System Doesn't Cover
ISMS tools manage controls and audits, but they don't provide a NIS2 implementation path. Why ISMS vendors upsell consulting, where the guidance gap lies, and how KaitoSec closes it.
By Chris Müller · Published 17 March 2026 · Updated 26 September 2026 · 9 min read
ISMS tools manage controls, documents, and audits, but they deliver neither a NIS2-specific implementation path nor the concrete measures required by Section 30 BSIG. That is why most vendors sell NIS2 consulting as a paid add-on.
On the sufficiency question: If your ISMS is based on ISO 27001, a NIS2 gap analysis is essential. The BSI has explicitly stated that an ISO 27001 certification does not automatically result in NIS2 compliance. The full answer with the BSI quote and concrete gap list: Is an ISO 27001 certification enough for NIS2 compliance?
This article shows where ISMS tools reach their limits, why combining them with a NIS2-specific guide makes sense, and how the integration works in practice.
What Does an ISMS Tool Do Well, and Where Does Its Reach End?
An ISMS tool organizes your security management: controls, policies, audit trails, and evidence in one place. But NIS2 introduces specific requirements that go beyond pure administration, including the ten areas of measures under Section 30 BSIG, BSI registration, and German reporting obligations.
What Does an ISMS Tool Do Well?
ISMS tools have clear strengths. They excel at:
- Document management -- managing policies, procedures, and evidence in a central location
- Control catalogues and mapping -- structuring ISO 27001 and BSI IT-Grundschutz frameworks
- Audit trail and compliance status -- providing seamless traceability for auditors
- Task and deadline management -- keeping responsibilities and deadlines in check
- Reporting -- supplying management and auditors with up-to-date metrics
These are important functions. For operating an ISMS, they are indispensable.
Where Do ISMS Tools Fall Short on NIS2?
The problem begins where NIS2-specific expertise is required. Four gaps appear particularly often:
- No NIS2-specific content: Tools provide structure, but no expertise on Section 30 BSIG, reporting obligations, or executive liability.
- No German legal specifics: International tools map the EU Directive, not the NIS2UmsuCG with its specific penalty frameworks and BSI requirements.
- No implementation guidance: A control point labelled "Conduct risk analysis" does not tell you _how_ to carry it out for NIS2 specifically.
- Templates are missing or generic: No German-language risk register, no Section 30-compliant information security policy.
The numbers confirm this gap. According to a study by G DATA, only 12.1% of affected companies have fully implemented NIS2 -- even though many of them already have ISMS tools in place. The problem is not administration; it is the missing content.
Put differently: An ISMS tool is the bookshelf, but the books are missing. It organizes your security documentation reliably. It just does not tell you which documents you actually need for NIS2 and how to create them. For details on the consequences of failing to implement the Section 30 measures, see the article NIS2 Fines: What Penalties Can You Expect?.
Why Do ISMS Vendors Sell NIS2 Consulting on Top?
ISMS vendors know that their platform alone is not sufficient for NIS2. That is why most offer additional NIS2 consulting packages, from gap analyses and action planning to BSI registration support. At daily rates of EUR 1,000 to 2,000, this can significantly increase total costs for SMEs with limited budgets.
What Do ISMS Vendors Typically Offer as a NIS2 Add-on?
Most vendors bundle similar packages:
- Gap analysis and NIS2 readiness assessment -- comparing current status against Section 30 requirements
- Action planning and implementation support -- consulting on concrete implementation
- Training for executive management and IT teams -- particularly on executive liability under Section 38 BSIG
- BSI registration support -- guidance through the registration process
- Ongoing compliance consulting -- regular reviews and adjustments
What Does the Additional Consulting Cost?
The numbers paint a clear picture:
- Consultant daily rates: EUR 1,000--2,000 per day
- Typical NIS2 consulting project for SMEs: EUR 50,000--150,000 initial (CCVOSSEL)
- ISMS tool licence on top: EUR 10,000--50,000 per year
- Total cost in the first year: easily six figures, for a company that already has an ISMS tool
More than half of all companies still invest less than the 20% of their IT budget recommended by the BSI and Bitkom in security (Bitkom Wirtschaftsschutz 2025). Additional five-figure consulting costs only make this problem worse.
Is It Possible Without the Consulting?
The key question is: What does the consultant deliver that cannot also be conveyed in a structured way? The answer: the expertise, the guiding thread, and the concrete templates. These are exactly the three elements a specialized NIS2 compliance platform can provide. Without a daily rate.
Why Don't ISMS Tools Provide a Clear Path for NIS2 Implementation?
ISMS tools present controls as a flat list or matrix, without prioritization, without sequence, and without a clear answer to the question "Where do I start?" According to ADVISORI, a lack of prioritization is one of the ten most expensive mistakes in NIS2 implementation for mid-sized companies.
Controls Matrix Instead of Implementation Path -- Where Is the Problem?
- A typical ISMS tool lists over 100 controls, sorted by standard (Annex A, BSI building blocks), not by NIS2 relevance.
- It lacks the information on which control is actually required for NIS2 and which is not.
- No prioritization: What is urgent, what can wait? The matrix provides no answer.
- No dependencies: The matrix does not show which measure must be completed before another.
- The result: companies work unsystematically, start in the wrong place, or lose track after just a few weeks.
What Does a Structured Implementation Path Do Differently?
- Fundamentals and Registration -- verify applicability, determine classification, use the BSI portal
- Risk Management -- asset inventory, threat analysis, risk matrix, gap assessment
- Technical Measures -- access control, encryption, patching, network security
- Incident Response and Reporting Obligations -- IR plan, BSI notification, exercises, forensics
- Governance and Organization -- appoint an information security officer, create policies, executive duties, reporting
- Supply Chain Security -- inventory, assessment, contractual safeguards
- Business Continuity -- BIA, BCP, backup strategy, testing
- Awareness and Training -- build a programme, mandatory training, phishing simulations, security culture
Each individual step answers the question: "What do I need to do?" Progress is measurable: a step is either completed or open. No room for interpretation, no guessing.
According to HvS-Consulting, without a clear methodology companies end up with "extensive risk registers with limited added value." ISMS implementations typically take 6 to 12 months. Companies that are only starting now will not be fully NIS2-compliant before the end of 2026 at the earliest. A focused implementation path significantly shortens this timeline.
KaitoSec practice principle: NIS2 is not merely an IT project. Effective implementation connects security measures, governance, workforce development, reporting, and supply-chain management.
How Do an ISMS Tool and KaitoSec Work Together in Practice?
KaitoSec supplies the NIS2-specific guidance and templates. Your existing ISMS tool remains the system of record for documents, controls, and evidence.
What Role Does KaitoSec Play?
- KaitoSec provides NIS2 expertise and a prioritized implementation path. Your existing ISMS tool remains the place for documents and evidence.
- KaitoSec provides templates in Word and Excel. Your ISMS tool handles the audit trail and approvals.
- The NIS2 Checker identifies the gaps. Tasks and deadlines can then be managed in your existing system.
- KaitoSec explains the German requirements of the NIS2UmsuCG. Your ISMS tool reports implementation status to management and auditors.
What Does the Typical Workflow Look Like?
- Complete the NIS2 Checker to determine applicability, current status, and the main gaps.
- Follow the guide chapters -- work through the Section 30 measures step by step.
- Download templates and customize them -- risk register, policies, IR plan, and more.
- Import the results into your ISMS tool -- import finished documents, tick off controls.
- Use the KaitoSec NIS2 knowledge area for detailed questions -- in-depth articles on individual topics available at any time.
Why Does This Work Without Switching Systems?
- Universal formats: All templates are available in Word and Excel, importable into any ISMS tool.
- No technical integration required: No API connection, no vendor lock-in, no configuration.
What Does ISMS-NIS2 Integration Look Like in Practice?
A mechanical engineering company with 130 employees has been using an ISMS tool for two years. When the NIS2UmsuCG enters into force, the IT manager realizes that the tool shows the ISO 27001 status but not what is specifically missing for NIS2. The vendor offers a consulting package for EUR 45,000.
What Was the Starting Point?
Starting point:
- Mechanical engineering, 130 employees, EUR 22 million annual revenue, classified as an "important entity"
- ISMS tool in use since 2024, ISO 27001 controls partially implemented
- IT team of 5, no dedicated information security officer
- The ISMS vendor offers a "NIS2 Readiness Package": gap analysis, consulting, and training for EUR 45,000
Problem:
The ISMS tool shows 114 ISO 27001 controls but does not indicate which ones are NIS2-relevant. There is no Section 30 mapping and no guidance for BSI registration. An incident response plan covering the 24-hour, 72-hour, and 1-month reporting deadlines is completely missing. The managing director does not know that he is personally liable under Section 38 BSIG. For details on what that means, see the article NIS2 Fines: What Penalties Can You Expect?.
- Completed the Pre-Check: immediately reveals that the IR plan, BSI registration, and supplier inventory are missing
- Guide Chapter 1: BSI registration completed step by step
- Guide Chapter 4: IR plan created using a ready-made template, reporting deadlines set up
- Guide Chapter 5: Executive duties documented, training scheduled
- Guide Chapter 6: Supplier inventory created using a template
- All documents imported into the ISMS tool -- controls updated, evidence added
Result:
The company closed its NIS2 gaps in 8 weeks without purchasing the EUR 45,000 consulting package. The ISMS tool remains the central platform and now contains NIS2-compliant content.
This scenario is anonymized and serves illustrative purposes.
Frequently Asked Questions
Does a NIS2 guide replace my ISMS tool?
It complements your existing system with what is missing for NIS2: structured expertise across all ten Section 30 areas of measures, a concrete implementation path, and 49 templates. Documentation and administration remain in your ISMS tool.
Does KaitoSec work with every ISMS tool?
Yes, it is fully tool-agnostic. All templates are available in Word and Excel format, universally importable into any platform. There is no technical dependency and no API integration.
Is my ISMS tool alone enough for NIS2 compliance?
In most cases, no. ISO 27001 provides an excellent foundation, but according to G DATA, only 12.1% of affected companies have fully implemented NIS2. The NIS2UmsuCG goes beyond standard ISMS frameworks, particularly regarding reporting obligations, BSI registration, and executive liability under Section 38 BSIG.
Do I still need a NIS2 consultant?
Not for the structured NIS2 readiness path in most organizations. For special cases such as KRITIS operators or complex group structures, targeted consulting may still be advisable.
Related articles
- nis2
- guide
- NIS2
- ISMS
- ISO 27001
- NIS2UmsuCG
- Compliance
- ISMS-Tool
- NIS2-Umsetzung
- Mittelstand