{"id":73416,"date":"2026-08-05T22:34:30","date_gmt":"2026-08-05T20:34:30","guid":{"rendered":"http:\/\/adiumento.local\/?page_id=73416"},"modified":"2026-08-05T22:34:30","modified_gmt":"2026-08-05T20:34:30","slug":"nis2-umsetzung","status":"publish","type":"page","link":"https:\/\/adiumento.de\/en\/themen\/regulatorik-sicher-umsetzen\/cybersecurity-resilienz\/nis2-umsetzung\/","title":{"rendered":"Implement NIS2 in practice"},"content":{"rendered":"<div class=\"wp-block-cover alignfull is-position-center-left service-page-hero is-light alignfull\" style=\"min-height:420px;aspect-ratio:unset;\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" class=\"wp-block-cover__image-background wp-image-73452\" alt=\"Cybersecurity und Resilienz\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png\" data-object-fit=\"cover\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><span aria-hidden=\"true\" class=\"wp-block-cover__background has-dark-background-color has-background-dim-50 has-background-dim\"><\/span><div class=\"wp-block-cover__inner-container\"><p class=\"service-page-back is-layout-flow wp-block-cover-is-layout-flow\"><a href=\"https:\/\/adiumento.de\/en\/?page_id=73411\">\u2190 Cybersecurity &amp; Resilience<\/a><\/p><h1 class=\"wp-block-heading\">Implement NIS2 in practice<\/h1><p class=\"has-medium-font-size wp-block-paragraph\"><strong>Translate NIS2 requirements into responsible, effective and verifiable security measures.<\/strong><\/p><\/div><\/div>\n\n\n\n<div class=\"wp-block-group is-style-section-light service-page-orientation adiumento-passage is-layout-flow wp-block-group-is-layout-flow\"><p class=\"has-text-align-center service-orientation__text wp-block-paragraph\">NIS2 does not require isolated tool adoption for affected entities, but rather managed cybersecurity risk management. In Germany, the corresponding obligations have applied since the NIS 2 Implementation Act and the amended BSIG came into force on December 6, 2025. A pragmatic approach combines management responsibility, risks, reporting channels, supply chain and reliable evidence in a prioritised roadmap. Whether a company is covered must be legally examined on a case-by-case basis.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Background<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png\" alt=\"Cybersecurity und Resilienz\" class=\"wp-image-73452 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">Many organisations already have security measures in place, but responsibilities, risk decisions, service provider management and evidence are not always linked in a robust overall picture. This becomes particularly critical in the case of security incidents: Who decides, who coordinates the technical steps, who evaluates the reporting requirement and what information is available in a timely manner?<\/p>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">NIS2 makes these connections a managerial and operational task. The approach should therefore not start with an unrelated list of measures, but with the services, systems, supply relationships and risks that are material to the company.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Technical context<\/h2>\n\n<p class=\"wp-block-paragraph\">Directive (EU) 2022\/2555 creates an EU framework for a high common level of cybersecurity. As a guideline, it had to be implemented nationally. In Germany, the NIS 2 Implementation Act was announced on December 5, 2025; According to the BSI, the amended BSIG came into force on December 6, 2025. The implementation law is an article law and amends other specialist laws in addition to the BSIG.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The scope of application depends, among other things, on the type of facility according to the appendixes to the BSIG, size thresholds and special cases. The BSI provides a non-binding impact assessment for this, but does not make a binding decision on a case-by-case basis. ADIUMENTO also does not establish any binding effect and does not provide legal advice.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIS2 is of product obligations of the <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/cybersecurity-resilienz\/cyber-resilience-act-umsetzung\/\">Cyber Resilience Act<\/a> to distinguish. For the higher-level classification leads <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/cybersecurity-resilienz\/\">Cybersecurity &amp; Resilience<\/a> on.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">What companies need to clarify specifically<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1709\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-scaled.jpg\" alt=\"IT-Security-Spezialistin \u00fcberwacht Systeme in einem Rechenzentrum.\" class=\"wp-image-73297 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-scaled.jpg 2560w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-300x200.jpg 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-1024x684.jpg 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-768x513.jpg 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-1536x1025.jpg 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-2048x1367.jpg 2048w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-18x12.jpg 18w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<ul class=\"wp-block-list\">\n<li>Which companies, services and activities fall within the scope of the audit and which legal advice assesses whether they are affected.<\/li>\n<li>How management approves risk management measures, monitors their implementation and fulfills their training requirements.<\/li>\n<li>Which cyber risks to network and information systems, services, dependencies and the supply chain are prioritised.<\/li>\n<li>How to detect, assess, contain, internally escalate and timely report significant security incidents.<\/li>\n<li>Which roles, decisions, controls and operational data make the implementation traceable.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The NIS2 policy provides, among other things, risk management measures for security incidents, business continuity, supply chain security, vulnerability remediation, effectiveness testing and cybersecurity training. The BSIG specifies the German obligations. Outsourced IT does not shift responsibility: The BSI points out that the affected institution must continue to ensure service provider control, verification and incident reporting.<\/p>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">From requirements to implementation<\/h2>\n\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Leadership Responsibility and Training<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Security decisions remain uncontrolled<br><strong>Organisational measure:<\/strong> Establish decision-making, approval and training cadence<br><strong>Technical implementation:<\/strong> Provide metrics and management reporting<br><strong>Possible evidence:<\/strong> Resolutions, training and review evidence<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Risk management<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Gaps remain unprioritized<br><strong>Organisational measure:<\/strong> Establish risk analysis, ownership and action roadmap<br><strong>Technical implementation:<\/strong> Implement protection for identities, endpoints, cloud and data in a risk-oriented manner<br><strong>Possible evidence:<\/strong> Risk register, action plan, control reviews<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Security incidents and reports<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Detection or reporting occurs too late<br><strong>Organisational measure:<\/strong> Practice incident response playbooks, escalation and communication channels<br><strong>Technical implementation:<\/strong> Operate logging, monitoring, alerting and forensic data backup<br><strong>Possible evidence:<\/strong> Playbooks, practice logs, event and alert reports<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Supply chain security<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Service provider and component risks remain unknown<br><strong>Organisational measure:<\/strong> Agree on requirements, assessments and periodic review<br><strong>Technical implementation:<\/strong> Segment access, harden interfaces and monitor service provider access<br><strong>Possible evidence:<\/strong> Ratings, contracts, access and review protocols<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Evidence capability<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Effectiveness is not verifiable<br><strong>Organisational measure:<\/strong> Define documentation structure and control rhythm<br><strong>Technical implementation:<\/strong> Record configuration statuses and operating data in a comprehensible manner<br><strong>Possible evidence:<\/strong> Policies, approvals, audit and system reports<\/p><\/details>\n<\/div>\n\n\n\n\n<p class=\"wp-block-paragraph\">The in-depth study is suitable for the operational chain of prevention, detection and response <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-microsoft-umgebung\/defender-wdac-monitoring-incident-response\/\">Defender, WDAC, monitoring and incident response<\/a>. Assigns security requirements in the development and delivery process <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-softwarebereitstellung\/secure-software-lifecycle-devsecops\/\">Secure Software Lifecycle \/ DevSecOps<\/a> a.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">90-day starting plan<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-security-audits-assessments-8.png\" alt=\"Abstrakte Illustration: Audit-Checkliste und Shield in Blau.\" class=\"wp-image-73237 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-security-audits-assessments-8.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-security-audits-assessments-8-300x225.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-security-audits-assessments-8-768x576.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-security-audits-assessments-8-16x12.png 16w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Days 1\u201330<\/summary><p class=\"wp-block-paragraph\"><strong>Working objective:<\/strong> Define the scope and assumption of impact with the responsible functions, record critical services and responsibilities.<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Days 31\u201360<\/summary><p class=\"wp-block-paragraph\"><strong>Working objective:<\/strong> Test the incident reporting chain including German reporting channels, prioritise top risks and relevant suppliers.<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Days 61\u201390<\/summary><p class=\"wp-block-paragraph\"><strong>Working objective:<\/strong> Determine the sequence of measures, proof of control and a proof backlog for operations and management.<\/p><\/details>\n<\/div>\n\n\n\n\n<p class=\"wp-block-paragraph\">This is not a universal compliance roadmap; Triggers, obligations and evidence must be examined for the specific case.<\/p>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Working with ADIUMENTO<\/h2>\n\n<p class=\"wp-block-paragraph\">ADIUMENTO supports the structured recording of existing security controls, responsibilities and operational processes and transferring them to a prioritised roadmap. Depending on the initial situation, this can include the structured analysis of existing controls, the implementation of identity, access, endpoint and security modules as well as monitoring and documentable operating processes - within the scope of the confirmed service areas on adiumento.de.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The implementation will be with <a href=\"https:\/\/adiumento.de\/en\/loesungen\/\">IT Security &amp; Compliance<\/a> and the <a href=\"https:\/\/adiumento.de\/en\/leistungen\/\">Services overview<\/a> tied together. Binding legal assessments, determinations of impact, attestations and certifications remain with the relevant legal advice, auditors or certification bodies.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Typical Results<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png\" alt=\"Cybersecurity und Resilienz\" class=\"wp-image-73452 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<ul class=\"wp-block-list\">\n<li>delimited investigation framework and structured risk overview;<\/li>\n<li>prioritised roadmap with responsibilities and implementation stages;<\/li>\n<li>Working principles for reporting, escalation and supplier processes;<\/li>\n<li>documented control and evidence structure for ongoing operations;<\/li>\n<li>technical work packages for identity, endpoints, monitoring and response.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These results are not a promise of legal compliance, certification or official recognition.<\/p>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Limitations and dependencies<\/h2>\n\n<p class=\"wp-block-paragraph\">The legal classification depends, among other things, on the activity, company structure, size thresholds and special constellations. It cannot be replaced by an online check or a technical inventory. The appropriateness and effectiveness of the measures depend on risk, architecture, service providers, resources and ongoing operations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An ISO 27001 or IT-Grundschutz certification can support the verification, but according to the BSI it does not automatically replace the examination of the legal catalogue of measures. ADIUMENTO does not provide legal advice and does not issue a guarantee of conformity.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Further official sources<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1709\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-scaled.jpg\" alt=\"IT-Security-Spezialistin \u00fcberwacht Systeme in einem Rechenzentrum.\" class=\"wp-image-73297 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-scaled.jpg 2560w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-300x200.jpg 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-1024x684.jpg 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-768x513.jpg 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-1536x1025.jpg 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-2048x1367.jpg 2048w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-18x12.jpg 18w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/DE\/TXT\/? Uri=CELEX:32022L2555\">Directive (EU) 2022\/2555 (NIS 2)<\/a> \u2013 EUR-Lex<\/li>\n<li><a href=\"https:\/\/www.bsi.bund.de\/DE\/Themen\/Regulierte-Wirtschaft\/NIS-2-regulierte-Unternehmen\/NIS-2-FAQ\/NIS-2-FAQ-allgemein\/FAQ-zu-NIS-2.html\">BSI: FAQ about NIS-2<\/a> \u2013 BSI<\/li>\n<li><a href=\"https:\/\/www.bsi.bund.de\/DE\/Themen\/Regulierte-Wirtschaft\/NIS-2-regulierte-Unternehmen\/NIS-2-regulierte-Unternehmen_node.html\">BSI: NIS-2 regulated companies<\/a> \u2013 BSI<\/li>\n<li><a href=\"https:\/\/mip2.bsi.bund.de\/de\/info-nis2-registrierung\/\">BSI Portal: NIS-2 registration and notification<\/a> \u2013 BSI<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light service-page-topics adiumento-passage adiumento-themen-faq is-layout-flow wp-block-group-is-layout-flow\"><p class=\"has-text-align-center service-section-kicker wp-block-paragraph\">Orientation<\/p>\n<h2 class=\"wp-block-heading has-text-align-center\">Frequently asked questions<\/h2>\n\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Does the BSI make a binding determination as to whether we are affected by NIS2?<\/summary><p class=\"wp-block-paragraph\">No. The BSI offers a non-binding impact assessment and points out that no binding individual decision on whether or not it is affected is made. If anything is unclear, external legal support should be involved.<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Is a certificate sufficient as NIS2 proof?<\/summary><p class=\"wp-block-paragraph\">No. The BSI explains that there is no general certificate to prove all requirements. Depending on the situation, documentation, test reports, audits or certifications can support evidence; The risk management measures and their implementation must still be appropriate.<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Which reporting deadlines do we have to prepare technically and organisationally?<\/summary><p class=\"wp-block-paragraph\">For significant security incidents, the guideline calls for an early warning within 24 hours, a report within 72 hours and a final report within one month. For Germany, registration and reports via the BSI portal as well as the current BSIG and BSI specifications are relevant; Triggers, content and exceptions must be checked on a case-by-case basis.<\/p><\/details>\n<\/div>\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Next sensible step<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7.png\" alt=\"Abstrakte Illustration: Threat Detection und Schutzschild in Blau.\" class=\"wp-image-73233 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7-300x225.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7-768x576.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7-16x12.png 16w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">Start with a granular view of relevant services, responsibilities, risks and existing controls. <a href=\"https:\/\/adiumento.de\/en\/loesungen\/\">IT Security &amp; Compliance<\/a> can structure a technical roadmap or security assessment as a starting point; Legal advice and impact assessment remain separate. For context, the leads <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/\">Regulatory hub<\/a> on the other topics.<\/p>\n<\/div><\/div>\n\n\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Implement NIS2 in Germany in practice: prioritise responsibilities, risk management, reporting processes, the supply chain and evidence.<\/p>","protected":false},"author":3,"featured_media":0,"parent":73411,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-73416","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73416","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/comments?post=73416"}],"version-history":[{"count":4,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73416\/revisions"}],"predecessor-version":[{"id":73502,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73416\/revisions\/73502"}],"up":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73411"}],"wp:attachment":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/media?parent=73416"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}