Knowledge Hub
Ten articles on the duties under the BSIG
Articles on scope, governance, supply chain, incidents and implementation, as orientation rather than legal advice.
- Articles
- 10
- Templates
- 49
- Readiness check
- 1
5 articles
Basics & Compliance
Scope, registration, deadlines and how NIS2 relates to ISO 27001.
- 01How to check whether NIS2 applies to your organisationSector, size threshold, exceptions, entity type, registration deadline: in five concrete steps, determine whether your organisation is subject to NIS2, with updated BSIG references (§§ 28, 33, 65).8 min readRead article
- 02BSI registration step by step in the BSI portal (MUK + ELSTER)NIS2 registration runs through the BSI portal at portal.bsi.bund.de, with sign-in via "Mein Unternehmenskonto" (MUK) and an ELSTER organisation certificate. This guide walks through the complete process, all mandatory fields, and the most common mistakes.10 min readRead article
- 03NIS2 and ISO 27001, and how the two fit togetherISO 27001-certified organisations already cover eight of ten NIS2 mandatory measures, but four critical gaps remain: the BSI notification cascade, the MFA mandate, registration obligations, and management liability. This article maps the overlaps, identifies the gaps, and answers whether ISO certification counts as BSI evidence.15 min readRead article
- 04Which organisations NIS2 actually covers (Section 28 BSIG)The applicability assessment in detail: all 18 sectors, EU SME size thresholds with the tightened AND operator, size-independent special categories under Section 28(1), the consolidation rule for corporate groups, and what a correct self-assessment under Section 33 BSIG actually requires.12 min readRead article
- 05Running a NIS2 gap assessment with template and guideThe gap assessment measures your NIS2 implementation status against the 12 mandatory measures of § 30 BSIG. This guide takes you through five steps from deriving the audit catalogue to management approval, with concrete assessment criteria and an action plan.20 min readRead article
1 articles
Risk Management
The ten statutory minimum measures, how they are read and where implementations usually fail.
1 articles
Incident Response
The reporting cascade at 24 hours, 72 hours and 30 days, and what belongs in each step.
2 articles
Governance & Accountability
The personal duty of the management body and the policy set small organisations actually need.
- 01The minimal NIS2 policy stack for small organisationsWhy most IS-Policy first drafts fail at four points, which pitfall per sub-policy produces audit findings, and how management approval must be structured to hold up after a BSI audit visit.15 min readRead article
- 02Personal liability of management under Section 38 BSIGSection 38 BSIG requires management to personally implement and oversee cybersecurity measures. Failure to comply creates internal liability toward the entity itself. This article explains the liability mechanism, the documentation that protects, and the most common misconceptions.15 min readRead article
1 articles
Supply Chain Security
The supplier inventory without which the supply chain duties cannot be evidenced.
Scope settled, what now?
Once the classification stands, the work starts: ten measures under Section 30 BSIG, reporting routes, the supply chain and the evidence the BSI expects. We go through your case and tell you what is still open.