
Implement NIS2 in practice
Translate NIS2 requirements into responsible, effective and verifiable security measures.
NIS2 does not require isolated tool adoption for affected entities, but rather managed cybersecurity risk management. In Germany, the corresponding obligations have applied since the NIS 2 Implementation Act and the amended BSIG came into force on December 6, 2025. A pragmatic approach combines management responsibility, risks, reporting channels, supply chain and reliable evidence in a prioritised roadmap. Whether a company is covered must be legally examined on a case-by-case basis.
Background

Many organisations already have security measures in place, but responsibilities, risk decisions, service provider management and evidence are not always linked in a robust overall picture. This becomes particularly critical in the case of security incidents: Who decides, who coordinates the technical steps, who evaluates the reporting requirement and what information is available in a timely manner?
NIS2 makes these connections a managerial and operational task. The approach should therefore not start with an unrelated list of measures, but with the services, systems, supply relationships and risks that are material to the company.
Technical context
Directive (EU) 2022/2555 creates an EU framework for a high common level of cybersecurity. As a guideline, it had to be implemented nationally. In Germany, the NIS 2 Implementation Act was announced on December 5, 2025; According to the BSI, the amended BSIG came into force on December 6, 2025. The implementation law is an article law and amends other specialist laws in addition to the BSIG.
The scope of application depends, among other things, on the type of facility according to the appendixes to the BSIG, size thresholds and special cases. The BSI provides a non-binding impact assessment for this, but does not make a binding decision on a case-by-case basis. ADIUMENTO also does not establish any binding effect and does not provide legal advice.
NIS2 is of product obligations of the Cyber Resilience Act to distinguish. For the higher-level classification leads Cybersecurity & Resilience on.
What companies need to clarify specifically

- Which companies, services and activities fall within the scope of the audit and which legal advice assesses whether they are affected.
- How management approves risk management measures, monitors their implementation and fulfills their training requirements.
- Which cyber risks to network and information systems, services, dependencies and the supply chain are prioritised.
- How to detect, assess, contain, internally escalate and timely report significant security incidents.
- Which roles, decisions, controls and operational data make the implementation traceable.
The NIS2 policy provides, among other things, risk management measures for security incidents, business continuity, supply chain security, vulnerability remediation, effectiveness testing and cybersecurity training. The BSIG specifies the German obligations. Outsourced IT does not shift responsibility: The BSI points out that the affected institution must continue to ensure service provider control, verification and incident reporting.
From requirements to implementation
Leadership Responsibility and Training
Risk: Security decisions remain uncontrolled
Organisational measure: Establish decision-making, approval and training cadence
Technical implementation: Provide metrics and management reporting
Possible evidence: Resolutions, training and review evidence
Risk management
Risk: Gaps remain unprioritized
Organisational measure: Establish risk analysis, ownership and action roadmap
Technical implementation: Implement protection for identities, endpoints, cloud and data in a risk-oriented manner
Possible evidence: Risk register, action plan, control reviews
Security incidents and reports
Risk: Detection or reporting occurs too late
Organisational measure: Practice incident response playbooks, escalation and communication channels
Technical implementation: Operate logging, monitoring, alerting and forensic data backup
Possible evidence: Playbooks, practice logs, event and alert reports
Supply chain security
Risk: Service provider and component risks remain unknown
Organisational measure: Agree on requirements, assessments and periodic review
Technical implementation: Segment access, harden interfaces and monitor service provider access
Possible evidence: Ratings, contracts, access and review protocols
Evidence capability
Risk: Effectiveness is not verifiable
Organisational measure: Define documentation structure and control rhythm
Technical implementation: Record configuration statuses and operating data in a comprehensible manner
Possible evidence: Policies, approvals, audit and system reports
The in-depth study is suitable for the operational chain of prevention, detection and response Defender, WDAC, monitoring and incident response. Assigns security requirements in the development and delivery process Secure Software Lifecycle / DevSecOps a.
90-day starting plan

Days 1–30
Working objective: Define the scope and assumption of impact with the responsible functions, record critical services and responsibilities.
Days 31–60
Working objective: Test the incident reporting chain including German reporting channels, prioritise top risks and relevant suppliers.
Days 61–90
Working objective: Determine the sequence of measures, proof of control and a proof backlog for operations and management.
This is not a universal compliance roadmap; Triggers, obligations and evidence must be examined for the specific case.
Working with ADIUMENTO
ADIUMENTO supports the structured recording of existing security controls, responsibilities and operational processes and transferring them to a prioritised roadmap. Depending on the initial situation, this can include the structured analysis of existing controls, the implementation of identity, access, endpoint and security modules as well as monitoring and documentable operating processes - within the scope of the confirmed service areas on adiumento.de.
The implementation will be with IT Security & Compliance and the Services overview tied together. Binding legal assessments, determinations of impact, attestations and certifications remain with the relevant legal advice, auditors or certification bodies.
Typical Results

- delimited investigation framework and structured risk overview;
- prioritised roadmap with responsibilities and implementation stages;
- Working principles for reporting, escalation and supplier processes;
- documented control and evidence structure for ongoing operations;
- technical work packages for identity, endpoints, monitoring and response.
These results are not a promise of legal compliance, certification or official recognition.
Limitations and dependencies
The legal classification depends, among other things, on the activity, company structure, size thresholds and special constellations. It cannot be replaced by an online check or a technical inventory. The appropriateness and effectiveness of the measures depend on risk, architecture, service providers, resources and ongoing operations.
An ISO 27001 or IT-Grundschutz certification can support the verification, but according to the BSI it does not automatically replace the examination of the legal catalogue of measures. ADIUMENTO does not provide legal advice and does not issue a guarantee of conformity.
Further official sources
Orientation
Frequently asked questions
Does the BSI make a binding determination as to whether we are affected by NIS2?
No. The BSI offers a non-binding impact assessment and points out that no binding individual decision on whether or not it is affected is made. If anything is unclear, external legal support should be involved.
Is a certificate sufficient as NIS2 proof?
No. The BSI explains that there is no general certificate to prove all requirements. Depending on the situation, documentation, test reports, audits or certifications can support evidence; The risk management measures and their implementation must still be appropriate.
Which reporting deadlines do we have to prepare technically and organisationally?
For significant security incidents, the guideline calls for an early warning within 24 hours, a report within 72 hours and a final report within one month. For Germany, registration and reports via the BSI portal as well as the current BSIG and BSI specifications are relevant; Triggers, content and exceptions must be checked on a case-by-case basis.
Next sensible step

Start with a granular view of relevant services, responsibilities, risks and existing controls. IT Security & Compliance can structure a technical roadmap or security assessment as a starting point; Legal advice and impact assessment remain separate. For context, the leads Regulatory hub on the other topics.
