NIS2 Consulting

The NIS2 Directive raises the bar for cybersecurity and risk management requirements for tens of thousands of companies in Germany. mgm security partners takes a pragmatic approach to helping you meet these requirements: with a clear gap analysis, a customized and achievable roadmap, and active support during implementation. We provide particularly in-depth support to companies that develop software.
The NIS2 Implementation Act (NIS2UmsuCG) has been in effect in Germany since December 6, 2025, with no transition period. Affected companies must already comply with these requirements. Those who have not yet begun should take action now.
Background
What is NIS2?
NIS2 is the second EU Directive on Network and Information Security (Directive (EU) 2022/2555). It significantly expands the scope of regulated sectors and requires affected companies to implement risk-based cybersecurity management, security incident reporting processes, and verifiable technical and organizational measures. In Germany, the directive is transposed into national law through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG).
The law took effect on December 6, 2025. It does not provide for a general transition period: Those affected must comply with the requirements as of the effective date. According to estimates, approximately 29,500 companies in Germany fall within the scope of the law, significantly more than under the previous regulations. Another new feature is the personal responsibility of management: governing bodies must approve risk management measures, monitor their implementation, and undergo regular training.
The challenge
- NIS2UmsuCG has been in effect since December 2025 without a transition period; the requirements are already in effect
- It is unclear whether one is affected and, if so, as what type of facility
- Comprehensive List of Responsibilities: Risk Management, Supply Chain, Reporting, Business Continuity
- Reporting procedures for the 24-hour and 72-hour deadlines are missing
- Personal Liability and Training Requirements for Management
- Requirements are abstract and difficult to apply to one's own software development
I am the reading text. I can be deselected below via the toggle. Lorem ipsum dolor sit amet sed Marcus is here today in the Colosseum. But where is Cornelia? She waits a long time. Finally she rejoices and laughs. There she is! There she sits!
Our Added Value
- A clear impact assessment and gap analysis as a solid foundation
- A personalized, achievable plan instead of a standard checklist
- Active support in implementing changes within the company—not just recommendations
- NIS2 Requirements Specifically Mapped to Software Development
- Experts who understand the technology, not just the regulations
- Meaningful integration with existing standards such as ISO 27001, without any obligation
I am the reading text. I can be deselected below via the toggle. Lorem ipsum dolor sit amet sed Marcus is here today in the Colosseum. But where is Cornelia? She waits a long time. Finally she rejoices and laughs. There she is! There she sits!
Are you affected?
NIS2 covers 18 sectors, divided into 11 high-criticality sectors (Annex 1) and seven other critical sectors (Annex 2). Whether you are affected and which category you fall into depends on your sector and the size of your company. This classification determines the regulatory regime and the range of fines. Therefore, assessing whether you are affected is always the first step.

The Three Types of Arrangements
This classification determines the regulatory regime and the range of fines.
Major institutions
Generally, those with 50 or more employees or annual revenue and total assets of 10 million euros, operating in a sector listed in Annex 1 or 2.
Reactive, event-driven supervision. Fines of up to 7 million euros or 1.4% of global annual revenue.
Particularly important institutions
Large companies with 250 or more employees, or with revenue of more than 50 million euros and total assets of more than 43 million euros, as well as certain institutions regardless of size.
Proactive, off-site supervision. Fines of up to 10 million euros or 2% of global annual revenue.
Operators of critical infrastructure (KRITIS)
Facilities that exceed the KRITIS thresholds and whose failure would significantly jeopardize the supply to the general public. They are considered particularly important facilities.
Highest level of oversight. Additional requirements, such as attack detection systems.
Our NIS2 Services
Five coordinated components, ranging from the impact assessment and the customized roadmap to guided implementation and documentation.
1 - Impact Assessment & Gap Analysis
Determine whether and how you are affected, and compare your current status against the NIS2 requirements.
- Determine the extent of impact and facility type according to NIS2UmsuCG
- Compare the current status against risk management requirements
- Quantify gaps and prioritize them by risk
- Clarify registration and reporting requirements with the BSI
- Technical and organizational classification; the binding legal assessment should be conducted with your legal counsel or attorneys
2 - Customized Roadmap
Use the gaps to develop a defined, achievable roadmap with clear milestones and responsibilities.
- Prioritize measures based on effort, impact, and risk
- Set realistic milestones and assign responsibilities
- Tailored to existing processes and resources
- Incorporate existing standards such as ISO 27001 where it is beneficial
3 - Governance & Risk Management
: Establish roles, processes, and a risk-based security management system that is integrated into day-to-day operations.
- Define Roles, Responsibilities, and Reporting Lines
- Develop a risk management methodology and a catalog of measures
- Addressing Supply Chain and Service Provider Security
- Involve management and fulfill mandatory training requirements
4 - Technical Measures & Reporting
Effectively implement technical obligations and establish reporting processes to meet statutory deadlines.
- Implement technical and organizational measures—don't just document them
- Set up the reporting process for the 24-hour and 72-hour deadlines
- Strengthening Business Continuity, Backup, and Crisis Management
- Integration with SOC and incident response structures
5 - Documentation & Audit Readiness
Demonstrate compliance and prepare for audits by the regulatory authority.
- Prepare evidence and documentation in a way that stands up to scrutiny
- Conduct internal reviews and readiness checks
- Prepare for both routine and event-specific audits
- Embedding Continuous Improvement in Day-to-Day Operations
NIS2 for Companies That Develop Software
This is where we really showcase our greatest strength. mgm security partners has been providing application security for over 20 years. We’ve broken down the NIS2 requirements into specific software development tasks, turning abstract obligations into tangible tasks for your development organization.
Many NIS2 consulting projects stop at the door of the development department. That’s exactly where we start. Because we’ve been practicing application security for over two decades, we’re familiar with both the regulatory side and the code, and we map NIS2 requirements to specific components from our application security portfolio.
- Risk Management & Architecture: Threat modeling and security architecture workshops embed risk analysis and secure design decisions from the very beginning.
- Secure Development: Lean Application Security, Agile Security, and Secure DevOps bring "Security by Design" and secure coding into your SSDLC.
- Automated Security Testing: Security test automation in the build chain, static code analysis, and the ASPM platform mgm ATLAS centrally aggregate findings.
- Vulnerabilities & Supply Chain: Application security penetration tests, OWASP ASVS assessments, and Docker security help identify vulnerabilities and third-party components.
- AI & LLM Security: LLM Security protects AI components, which are increasingly becoming part of regulated applications and their attack surface.
Your Path to NIS2 Compliance
A well-defined, customized, and—above all—feasible roadmap, from the impact assessment to verifiable continuous operation.

ISO 27001 can help, but it is not a requirement
An existing ISO 27001 ISMS already covers many NIS 2 requirements and significantly speeds up implementation. Risk management, policies, reporting chains, business continuity, and technical measures are already systematically embedded within it, so that a large portion of the NIS 2 obligations can build on existing processes.
However, ISO 27001 is not mandatory for NIS2. Even if you are not seeking certification, you can still meet the NIS2 requirements through a streamlined, targeted approach. In our gap analysis, we assess what you already have in place, leverage existing structures where they are beneficial, and otherwise implement only what NIS2 actually requires. If certification makes sense for you, we integrate both into a single process.
No in-house resources? Outsourced ISB
Once implementation is complete, someone must manage these responsibilities on an ongoing basis: maintaining the ISMS, overseeing reporting processes, and reporting to senior management. If your organization lacks the time or the appropriate qualifications internally, we can assume the role of Information Security Officer as a service and transition your NIS2 implementation to ongoing operations.
Regulatory Compliance and Secure Code from a Single Source
- Over 20 years of experience in application security
- 25+ Years of Enterprise Security Consulting
- A personalized, achievable plan instead of a standard checklist
- 100% led by senior security experts
We are familiar with both the regulatory aspects of NIS2 and its technical implementation, drawing on over 25 years of experience working on projects for banks, insurance companies, industry, and software vendors. Our particular strength lies in application security: For over 20 years, we’ve been making software development secure, and we’ve specifically mapped NIS2 to the requirements of the development process. Instead of duplicating processes on paper, we integrate NIS2 right into the workflows your teams already use.
NIS2 Guidance: Quick Answers to Your Questions
When does NIS2 take effect for us?
The German NIS2 Implementation Act (NIS2UmsuCG) entered into force on December 6, 2025. There is no general transition period: Affected companies must comply with the requirements as of the date of entry into force, and the BSI registration deadline has already passed. Those who have not yet begun should assess their compliance status now and quickly develop a roadmap.
How do we know if we're even affected?
The extent to which you are affected depends on your sector and the size of your company. As a general rule, the obligations apply to companies with 50 or more employees or annual revenue of 10 million euros in one of the covered sectors; for certain sectors, they apply regardless of company size. In our impact assessment, we classify you as a particularly important or important entity and clarify the registration and reporting requirements. You will make the final, legally binding assessment in consultation with your legal department or your attorneys, with whom we work closely as needed.
What are the consequences of violations?
For particularly important organizations, fines can be up to 10 million euros or 2% of global annual revenue; for important organizations, fines can be up to 7 million euros or 1.4%. In addition, senior management bears personal responsibility and must approve and monitor the measures and undergo training.
Is ISO 27001 absolutely necessary for NIS2?
No. ISO 27001 is not a requirement for NIS2. However, an existing ISO 27001-compliant ISMS already covers many NIS2 requirements and speeds up implementation. We leverage existing structures where they are beneficial and, otherwise, build specifically on what NIS2 requires.
What makes your consulting services for software companies unique?
We’ve been working in application security for over 20 years and have mapped the NIS2 requirements specifically to software development. From threat modeling to secure SSDLC, SBOM, and supply chain security, all the way to reporting, we translate abstract obligations into concrete tasks for day-to-day development without slowing teams down.
What does a typical NIS2 project look like?
We begin with a scope assessment and gap analysis, which will provide a solid foundation within a few weeks. Based on this, we develop a customized, feasible roadmap and actively support its implementation within the company. Finally, we ensure the implementation is audit-ready and establish a framework for ongoing operations.
