NIS2 Applicability Check
Is your company covered by the new EU cybersecurity directive? Check it in two minutes — all values are determined live, nothing is stored.
Your company
Your assessment
Initial orientation based on the EU directive (NIS2, EU 2022/2555) — not legal advice. The directive and its national implementation (in Germany the NIS2 implementation act) with their detailed rules and exemptions are authoritative. We are happy to support the in-depth assessment and implementation.
NIS2 — cybersecurity becomes mandatory
With the NIS2 directive the EU massively expands cybersecurity obligations: instead of a few critical infrastructures, entire industries are now covered — from machinery to food to logistics. Tens of thousands of companies are affected for the first time, and many do not know it yet.
The check gives you a first classification in two minutes. Covered or not: the required measures — risk management, tested backups, MFA, reporting processes — are exactly the fundamentals our security assessment reviews and that we implement together with you.
Frequently asked questions
When does NIS2 apply in Germany?
The EU directive is in force; in Germany it is transposed into national law by the NIS2 implementation act. If you are covered, do not wait for the deadline — the measures need lead time.
Is management personally accountable?
NIS2 explicitly holds the management level responsible: it must approve and oversee the risk-management measures and receive training — violations carry severe consequences.
We are not directly covered — can we ignore the topic?
Better not: covered companies must secure their supply chain. Suppliers and service providers increasingly receive these requirements through customer contracts.