Implementing NIS-2 securely – with coaching, risk management and optional software support
NIS-2 tightens the requirements for information security and resilience in Europe. Having come into force in January 2023, the Directive is expected to take effect at national level from late 2025 / early 2026. Funk provides support in determining the relevance and extent of the impact and in fulfilling reporting obligations.
The NIS 2 Directive requires organisations to strengthen their information security measures in order to effectively identify, assess and minimise cyber risks. It calls for systematic security management, clear lines of responsibility and evidence of the implementation of appropriate technical and organisational measures.
Company management bodies bear joint responsibility; they must actively manage risk, fulfil reporting obligations (e.g. within 72 hours in the event of a security incident) and ensure staff are properly trained. In Germany, around 30,000 companies will fall within the scope of the regulation from 2025/2026; failure to comply may result in substantial fines and personal liability.
How does NIS-2 classify companies – and who is affected?
Whether your organisation is affected is determined by a classification. The classification determines the scope of the obligations – for example, regarding reporting, security measures and regulatory inspections – and is therefore a key step in the implementation of NIS-2.
Assess the extent to which your organisation is affected by NIS 2: Categorise your organisation
Is your organisation classified as a critical or particularly critical infrastructure?
Critical infrastructure comprises large organisations in critical sectors, such as energy, transport, healthcare or water supply. Important infrastructure includes medium-sized enterprises in comparable or supporting sectors.
Important facilities include: postal and courier services, waste management, chemical products, food, manufacturers, digital service providers, research
Critically important entities include: energy, transport, banking, financial markets, healthcare, drinking water, wastewater, digital infrastructure, B2B, public administration, space
If your organisation falls within the categories listed above, please refer to the table to determine the scope of your NIS 2 obligations. These are based on the organisation’s size and turnover figures:
| Large companies | Medium-sized companies | Small companies | |
|---|---|---|---|
| Number of employees and turnover | At least 250 employees or an annual turnover of €50 million + an annual balance sheet total of €43 million | At least 50 employees or an annual turnover of €10 million + an annual balance sheet total of €10 million | Fewer than 50 employees or annual turnover of less than €10 million |
| Affected by NIS-2? | Affected | Affected | Not affected |
| Scope of obligations | Regular security audits, liability of senior management, reporting obligations | Regular safety inspections, liability of company management, reporting obligation | None |
Impact assessment and scoping in accordance with NIS-2
Organisations must independently assess whether they fall within the scope of the NIS 2 Directive and what obligations this entails – the authorities do not actively provide this information. The Funk Impact Analysis helps you to determine the relevance and extent of the impact.
Business requirements:
- Identification of affected business areas, products and subsidiaries
- Analysis of dependencies on suppliers and partners
- Documentation as part of a NIS 2 scoping report
The result is a clear assessment of your NIS 2 impact and a sound basis for the next implementation steps.
Your point of contact
Funk Consulting: NIS 2 implementation in three targeted and effective phases
We guide your company towards NIS 2 compliance in a pragmatic and effective manner, placing risk management at the centre and integrating it seamlessly into your governance framework. You receive clear priorities, actionable measures and auditable evidence as part of a continuous improvement process.
Phase 1
Orientation & Scoping
- Impact Analysis & Scope: Which entities (business units, subsidiaries and services) are affected?
- Dependency Assessment: What dependencies exist, particularly across international operations or subsidiaries?
- Maturity & Gap Analysis: Assessment of the current state against NIS 2 requirements, identification of gaps and clear priorities as a basis for decision-making
Phase 2
Implementation & Integration into Risk Management
- Roadmap & Responsibilities: Timeline, milestones and roles for the effective implementation of the prioritised measures
- Integrating Risk Management: Establishment or further development of a NIS 2-compliant risk management system
- Reporting Procedures & Training: Standardised process for reporting incidents to the BSI, as well as workshops for management bodies; in addition, we develop target group-specific e-learning courses for employees and senior management.
Phase 3
Effectiveness & Continuous Improvement
- Effectiveness Check & Review: Annual assessment of the appropriateness and effectiveness of the measures, with adjustments to reflect the state of the art and new regulatory requirements
- Exercises & Continuous Development: Case studies, crisis simulations and ongoing refinement of the measures
RIMIKS X: Your software support for NIS 2 implementation
On request, we can support Phases 2 and 3 of your implementation using our risk management software, RIMIKS X. It consolidates all risks – including NIS 2-relevant IT and information security risks – into a central inventory, assesses them consistently and aggregates them up to company or group level. Measures and audit evidence are documented transparently and in an audit-proof manner. RIMIKS X is ready for immediate use, remains up to date through ongoing regulatory updates (e.g. sustainability) and enables efficient management of your compliance risks.
RIMIKS XNIS-2 training courses for management bodies and staff
Companies must not only ensure technical compliance, but also demonstrate that staff and management have received training. We can help you raise awareness amongst these groups. This will enable you to fulfil your obligation to provide training and raise awareness.
Training coursesWould you like to find out more?
Please contact us on +49 40 35914-0 or send us a message.
Get in touch