Skip to content

NIS2 Directive

NIS2 software: implement requirements and prove compliance to the BSI

Assign security measures, business continuity, supply-chain risks and incident processes to accountable owners. KaitoSec connects implementation, approval and evidence with ISMS, BCMS, DSMS and AIMS.

Sectors under Annex I and II
18
Early-warning deadline
24h
Baseline measures under Article 21
10

One control, several standards

Implement NIS2 with ISO 27001 or IT-Grundschutz

Reuse approved controls and evidence through ISMS software or your IT-Grundschutz programme while keeping the NIS2-specific scope, accountability and reporting obligations visible.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • NIS2Requirement satisfied
  • ISO 27001Requirement satisfied
  • BSI IT-GrundschutzRequirement satisfied
  • DORARequirement satisfied
  • ISO 22301Requirement satisfied

From control to policy

The measures under Section 30 BSIG

Section 30 BSIG brings risk analysis, incident handling, continuity, supply-chain security, access control, cryptography and effectiveness checks into one managed set of measures.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

Who is subject to NIS2

Applicability depends on sector, service, entity size and statutory exceptions. KaitoSec records the classification rationale and the accountable review; legal assessment remains with your organisation.

01

Classify essential and important entities

Check sector, services, company size and relevant exceptions in a guided assessment. KaitoSec keeps the proposed classification and its rationale reviewable; your organisation confirms the legal result.

02

Traceable management accountability

Section 38 BSIG requires management to implement the measures, oversee their implementation and attend training. If those duties are breached, management may be liable to the entity under company law for culpably caused damage. KaitoSec logs approvals, risk acceptances and policy decisions as an audit-ready trail.

03

Incident reporting with clear accountability

Configure the notification steps, deadlines and approvals that apply to your organisation. KaitoSec keeps status, owner and prepared reporting data with the incident.

04

Keep supply-chain risks accountable

Prepare questionnaires from existing context, document supplier risks and assign follow-up actions to an owner. Assessment remains a professional decision.

05

One NIS2 measure also counts in your ISMS, BCMS and DSMS

Article 21 requires ten baseline measures, from risk analysis and incident handling through business continuity and supply chain security to cryptography. KaitoSec implements each control once, then maps it into the BCMS, ISMS and DSMS where the substance overlaps. An ISO 22301 BC exercise is also NIS2 continuity evidence; an ISMS access policy is also a NIS2 measure. The control is maintained once and counts in every audit it belongs in.

Reporting obligations and BSI registration

Prepare the information, responsibilities and evidence needed for BSI registration and incident reporting. Submission and legal classification remain controlled by your authorised team.

01

Prepare BSI registration

Bring entity classification, services, contact responsibilities and the required organisational information into one reviewed record before authorised staff transfer it to the BSI portal.

02

NIS2 Obligation Dashboard

A single view of all NIS2 Article 21 security measures mapped to your organisation, from access control and encryption to business continuity and supply chain security. Each obligation shows owners, evidence status, and implementation deadline.

03

Incident Response Playbooks

Response playbooks guide detection, containment and the notification steps configured for your organisation. Deadlines and accountability remain visible on the incident and require professional review.

04

Sector Classification Wizard

NIS2 distinguishes essential and important entities across 18 sectors, each with its own obligations. KaitoSec's setup assistant asks about activity, size and services, proposes your classification and hides requirements that do not apply to you. The rationale stays documented, professional confirmation stays with you.

05

Business Continuity & Crisis Management

NIS2 Article 21 explicitly requires business continuity measures, including backup management, disaster recovery, and crisis management. KaitoSec maps these obligations to structured workflows: run your BIA, define recovery strategies, build BC plans, and manage crisis escalation. Every measure links back to your NIS2 obligations register, so you can evidence implementation at any point.

Frequently asked questions about NIS2

Who is subject to NIS2?

NIS2 applies to essential and important entities whose activities fall within a covered entity type and whose statutory size criteria or special rules apply. For important entities, the usual threshold is at least 50 employees or both more than €10 million in annual revenue and more than €10 million on the annual balance sheet. The free NIS2 applicability check provides an initial classification in five minutes.

What measures does NIS2 require in concrete terms?

NIS2 requires measures in ten areas under Section 30 BSIG: risk analysis and information security; incident handling; business continuity; supply-chain security; secure acquisition, development and maintenance including vulnerability handling; effectiveness checks; cyber hygiene and training; cryptography; personnel security, access control and asset management; and, where appropriate, MFA or continuous authentication plus secure communications. Through compliance mapping, KaitoSec maps them to ISO 27001 and BSI IT-Grundschutz. Our NIS2 compliance guide walks through implementation end to end.

What reporting obligations apply under NIS2?

NIS2 reporting obligations apply to significant security incidents: after becoming aware of one, an early warning is due within 24 hours, an incident notification within 72 hours and, as a rule, a final report no later than one month after the incident notification. In reporting, KaitoSec keeps reporting paths, responsibilities and templates ready, so the facts do not have to be found during an incident.

Is an ISO 27001 certificate sufficient for NIS2?

No, an ISO 27001 certificate does not fully satisfy NIS2, but it covers most of the requirements. NIS2 additionally demands explicit supply-chain governance, reporting processes and management accountability. KaitoSec's risk management and vendor management close these gaps.

Is management personally liable under NIS2?

Personal liability of management is possible under Section 38 BSIG. Management must implement the measures and oversee their implementation; if those duties are breached, company-law liability may apply for culpably caused damage to the entity. KaitoSec provides the management view in reporting: implementation status without another request to IT.

Supply-chain risk management

Connect suppliers, contracts, supported services, findings and follow-up actions to the same risk context used for NIS2 oversight.

Connect NIS2 with ISO 27001 and IT-Grundschutz

Keep NIS2 connected to the management systems and sector obligations your organisation already operates. Operators already scoped under the KRITIS-Dachgesetz face closely related obligations — see how NIS2 and the KRITIS-Dachgesetz relate.