01
Classify essential and important entities
Check sector, services, company size and relevant exceptions in a guided assessment. KaitoSec keeps the proposed classification and its rationale reviewable; your organisation confirms the legal result.
NIS2 Directive
Assign security measures, business continuity, supply-chain risks and incident processes to accountable owners. KaitoSec connects implementation, approval and evidence with ISMS, BCMS, DSMS and AIMS.
One control, several standards
Reuse approved controls and evidence through ISMS software or your IT-Grundschutz programme while keeping the NIS2-specific scope, accountability and reporting obligations visible.
One control
Supplier & third-party due diligence
From control to policy
Section 30 BSIG brings risk analysis, incident handling, continuity, supply-chain security, access control, cryptography and effectiveness checks into one managed set of measures.
One control
Supplier & third-party due diligence
Management systems
Policies and procedures
Applicability depends on sector, service, entity size and statutory exceptions. KaitoSec records the classification rationale and the accountable review; legal assessment remains with your organisation.
01
Check sector, services, company size and relevant exceptions in a guided assessment. KaitoSec keeps the proposed classification and its rationale reviewable; your organisation confirms the legal result.
02
Section 38 BSIG requires management to implement the measures, oversee their implementation and attend training. If those duties are breached, management may be liable to the entity under company law for culpably caused damage. KaitoSec logs approvals, risk acceptances and policy decisions as an audit-ready trail.
03
Configure the notification steps, deadlines and approvals that apply to your organisation. KaitoSec keeps status, owner and prepared reporting data with the incident.
04
Prepare questionnaires from existing context, document supplier risks and assign follow-up actions to an owner. Assessment remains a professional decision.
05
Article 21 requires ten baseline measures, from risk analysis and incident handling through business continuity and supply chain security to cryptography. KaitoSec implements each control once, then maps it into the BCMS, ISMS and DSMS where the substance overlaps. An ISO 22301 BC exercise is also NIS2 continuity evidence; an ISMS access policy is also a NIS2 measure. The control is maintained once and counts in every audit it belongs in.
Prepare the information, responsibilities and evidence needed for BSI registration and incident reporting. Submission and legal classification remain controlled by your authorised team.
01
Bring entity classification, services, contact responsibilities and the required organisational information into one reviewed record before authorised staff transfer it to the BSI portal.
02
A single view of all NIS2 Article 21 security measures mapped to your organisation, from access control and encryption to business continuity and supply chain security. Each obligation shows owners, evidence status, and implementation deadline.
03
Response playbooks guide detection, containment and the notification steps configured for your organisation. Deadlines and accountability remain visible on the incident and require professional review.
04
NIS2 distinguishes essential and important entities across 18 sectors, each with its own obligations. KaitoSec's setup assistant asks about activity, size and services, proposes your classification and hides requirements that do not apply to you. The rationale stays documented, professional confirmation stays with you.
05
NIS2 Article 21 explicitly requires business continuity measures, including backup management, disaster recovery, and crisis management. KaitoSec maps these obligations to structured workflows: run your BIA, define recovery strategies, build BC plans, and manage crisis escalation. Every measure links back to your NIS2 obligations register, so you can evidence implementation at any point.
NIS2 applies to essential and important entities whose activities fall within a covered entity type and whose statutory size criteria or special rules apply. For important entities, the usual threshold is at least 50 employees or both more than €10 million in annual revenue and more than €10 million on the annual balance sheet. The free NIS2 applicability check provides an initial classification in five minutes.
NIS2 requires measures in ten areas under Section 30 BSIG: risk analysis and information security; incident handling; business continuity; supply-chain security; secure acquisition, development and maintenance including vulnerability handling; effectiveness checks; cyber hygiene and training; cryptography; personnel security, access control and asset management; and, where appropriate, MFA or continuous authentication plus secure communications. Through compliance mapping, KaitoSec maps them to ISO 27001 and BSI IT-Grundschutz. Our NIS2 compliance guide walks through implementation end to end.
NIS2 reporting obligations apply to significant security incidents: after becoming aware of one, an early warning is due within 24 hours, an incident notification within 72 hours and, as a rule, a final report no later than one month after the incident notification. In reporting, KaitoSec keeps reporting paths, responsibilities and templates ready, so the facts do not have to be found during an incident.
No, an ISO 27001 certificate does not fully satisfy NIS2, but it covers most of the requirements. NIS2 additionally demands explicit supply-chain governance, reporting processes and management accountability. KaitoSec's risk management and vendor management close these gaps.
Personal liability of management is possible under Section 38 BSIG. Management must implement the measures and oversee their implementation; if those duties are breached, company-law liability may apply for culpably caused damage to the entity. KaitoSec provides the management view in reporting: implementation status without another request to IT.
Connect suppliers, contracts, supported services, findings and follow-up actions to the same risk context used for NIS2 oversight.
Keep NIS2 connected to the management systems and sector obligations your organisation already operates. Operators already scoped under the KRITIS-Dachgesetz face closely related obligations — see how NIS2 and the KRITIS-Dachgesetz relate.