Add your offcanvas content in here

The Company

Simplifying your IT-security journey.

NIS2 Consulting

The NIS2 Directive raises the bar for cybersecurity and risk management requirements for tens of thousands of companies in Germany. mgm security partners takes a pragmatic approach to helping you meet these requirements: with a clear gap analysis, a customized and achievable roadmap, and active support during implementation. We provide particularly in-depth support to companies that develop software.

The NIS2 Implementation Act (NIS2UmsuCG) has been in effect in Germany since December 6, 2025, with no transition period. Affected companies must already comply with these requirements. Those who have not yet begun should take action now.

Background

Fundamentals

What is NIS2?

NIS2 is the second EU Directive on Network and Information Security (Directive (EU) 2022/2555). It significantly expands the scope of regulated sectors and requires affected companies to implement risk-based cybersecurity management, security incident reporting processes, and verifiable technical and organizational measures. In Germany, the directive is transposed into national law through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG).

The law took effect on December 6, 2025. It does not provide for a general transition period: Those affected must comply with the requirements as of the effective date. According to estimates, approximately 29,500 companies in Germany fall within the scope of the law, significantly more than under the previous regulations. Another new feature is the personal responsibility of management: governing bodies must approve risk management measures, monitor their implementation, and undergo regular training.

06.12.2025
Entry into force of the NIS2UmsuCG in Germany, without a transition period
approx. 29,500
Companies in Germany are expected to fall within the scope of
24 / 72 h
Early warning within 24 hours, follow-up report within 72 hours, final report within 1 month
up to €10 million / 2%
Fines for particularly important entities (based on global annual revenue), plus liability of management

The challenge

Attention!
  • NIS2UmsuCG has been in effect since December 2025 without a transition period; the requirements are already in effect
  • It is unclear whether one is affected and, if so, as what type of facility
  • Comprehensive List of Responsibilities: Risk Management, Supply Chain, Reporting, Business Continuity
  • Reporting procedures for the 24-hour and 72-hour deadlines are missing
  • Personal Liability and Training Requirements for Management
  • Requirements are abstract and difficult to apply to one's own software development

I am the reading text. I can be deselected below via the toggle. Lorem ipsum dolor sit amet sed Marcus is here today in the Colosseum. But where is Cornelia? She waits a long time. Finally she rejoices and laughs. There she is! There she sits!

Our Added Value

Result
  • A clear impact assessment and gap analysis as a solid foundation
  • A personalized, achievable plan instead of a standard checklist
  • Active support in implementing changes within the company—not just recommendations
  • NIS2 Requirements Specifically Mapped to Software Development
  • Experts who understand the technology, not just the regulations
  • Meaningful integration with existing standards such as ISO 27001, without any obligation

I am the reading text. I can be deselected below via the toggle. Lorem ipsum dolor sit amet sed Marcus is here today in the Colosseum. But where is Cornelia? She waits a long time. Finally she rejoices and laughs. There she is! There she sits!

Are you affected?

Information

NIS2 covers 18 sectors, divided into 11 high-criticality sectors (Annex 1) and seven other critical sectors (Annex 2). Whether you are affected and which category you fall into depends on your sector and the size of your company. This classification determines the regulatory regime and the range of fines. Therefore, assessing whether you are affected is always the first step.

The Three Types of Arrangements

Information

This classification determines the regulatory regime and the range of fines.

Reactive, event-driven supervision. Fines of up to 7 million euros or 1.4% of global annual revenue.

Proactive, off-site supervision. Fines of up to 10 million euros or 2% of global annual revenue.

Highest level of oversight. Additional requirements, such as attack detection systems.

Our NIS2 Services

Offer

Five coordinated components, ranging from the impact assessment and the customized roadmap to guided implementation and documentation.

  • Determine the extent of impact and facility type according to NIS2UmsuCG
  • Compare the current status against risk management requirements
  • Quantify gaps and prioritize them by risk
  • Clarify registration and reporting requirements with the BSI
  • Technical and organizational classification; the binding legal assessment should be conducted with your legal counsel or attorneys
  • Prioritize measures based on effort, impact, and risk
  • Set realistic milestones and assign responsibilities
  • Tailored to existing processes and resources
  • Incorporate existing standards such as ISO 27001 where it is beneficial
  • Define Roles, Responsibilities, and Reporting Lines
  • Develop a risk management methodology and a catalog of measures
  • Addressing Supply Chain and Service Provider Security
  • Involve management and fulfill mandatory training requirements
  • Implement technical and organizational measures—don't just document them
  • Set up the reporting process for the 24-hour and 72-hour deadlines
  • Strengthening Business Continuity, Backup, and Crisis Management
  • Integration with SOC and incident response structures
  • Prepare evidence and documentation in a way that stands up to scrutiny
  • Conduct internal reviews and readiness checks
  • Prepare for both routine and event-specific audits
  • Embedding Continuous Improvement in Day-to-Day Operations

NIS2 for Companies That Develop Software

Result

This is where we really showcase our greatest strength. mgm security partners has been providing application security for over 20 years. We’ve broken down the NIS2 requirements into specific software development tasks, turning abstract obligations into tangible tasks for your development organization.

Many NIS2 consulting projects stop at the door of the development department. That’s exactly where we start. Because we’ve been practicing application security for over two decades, we’re familiar with both the regulatory side and the code, and we map NIS2 requirements to specific components from our application security portfolio.

Go to the Application Security Portfolio →

  • Risk Management & Architecture: Threat modeling and security architecture workshops embed risk analysis and secure design decisions from the very beginning.
  • Secure Development: Lean Application Security, Agile Security, and Secure DevOps bring "Security by Design" and secure coding into your SSDLC.
  • Automated Security Testing: Security test automation in the build chain, static code analysis, and the ASPM platform mgm ATLAS centrally aggregate findings.
  • Vulnerabilities & Supply Chain: Application security penetration tests, OWASP ASVS assessments, and Docker security help identify vulnerabilities and third-party components.
  • AI & LLM Security: LLM Security protects AI components, which are increasingly becoming part of regulated applications and their attack surface.

Your Path to NIS2 Compliance

Approach

A well-defined, customized, and—above all—feasible roadmap, from the impact assessment to verifiable continuous operation.

ISO 27001 can help, but it is not a requirement

Information

An existing ISO 27001 ISMS already covers many NIS 2 requirements and significantly speeds up implementation. Risk management, policies, reporting chains, business continuity, and technical measures are already systematically embedded within it, so that a large portion of the NIS 2 obligations can build on existing processes.

However, ISO 27001 is not mandatory for NIS2. Even if you are not seeking certification, you can still meet the NIS2 requirements through a streamlined, targeted approach. In our gap analysis, we assess what you already have in place, leverage existing structures where they are beneficial, and otherwise implement only what NIS2 actually requires. If certification makes sense for you, we integrate both into a single process.

No in-house resources? Outsourced ISB

Information

Once implementation is complete, someone must manage these responsibilities on an ongoing basis: maintaining the ISMS, overseeing reporting processes, and reporting to senior management. If your organization lacks the time or the appropriate qualifications internally, we can assume the role of Information Security Officer as a service and transition your NIS2 implementation to ongoing operations.

Regulatory Compliance and Secure Code from a Single Source

  • Over 20 years of experience in application security
  • 25+ Years of Enterprise Security Consulting
  • A personalized, achievable plan instead of a standard checklist
  • 100% led by senior security experts

We are familiar with both the regulatory aspects of NIS2 and its technical implementation, drawing on over 25 years of experience working on projects for banks, insurance companies, industry, and software vendors. Our particular strength lies in application security: For over 20 years, we’ve been making software development secure, and we’ve specifically mapped NIS2 to the requirements of the development process. Instead of duplicating processes on paper, we integrate NIS2 right into the workflows your teams already use.

NIS2 Guidance: Quick Answers to Your Questions

The German NIS2 Implementation Act (NIS2UmsuCG) entered into force on December 6, 2025. There is no general transition period: Affected companies must comply with the requirements as of the date of entry into force, and the BSI registration deadline has already passed. Those who have not yet begun should assess their compliance status now and quickly develop a roadmap.

The extent to which you are affected depends on your sector and the size of your company. As a general rule, the obligations apply to companies with 50 or more employees or annual revenue of 10 million euros in one of the covered sectors; for certain sectors, they apply regardless of company size. In our impact assessment, we classify you as a particularly important or important entity and clarify the registration and reporting requirements. You will make the final, legally binding assessment in consultation with your legal department or your attorneys, with whom we work closely as needed.

For particularly important organizations, fines can be up to 10 million euros or 2% of global annual revenue; for important organizations, fines can be up to 7 million euros or 1.4%. In addition, senior management bears personal responsibility and must approve and monitor the measures and undergo training.

No. ISO 27001 is not a requirement for NIS2. However, an existing ISO 27001-compliant ISMS already covers many NIS2 requirements and speeds up implementation. We leverage existing structures where they are beneficial and, otherwise, build specifically on what NIS2 requires.

We’ve been working in application security for over 20 years and have mapped the NIS2 requirements specifically to software development. From threat modeling to secure SSDLC, SBOM, and supply chain security, all the way to reporting, we translate abstract obligations into concrete tasks for day-to-day development without slowing teams down.

We begin with a scope assessment and gap analysis, which will provide a solid foundation within a few weeks. Based on this, we develop a customized, feasible roadmap and actively support its implementation within the company. Finally, we ensure the implementation is audit-ready and establish a framework for ongoing operations.

Maximiliane Mayer

Ready for NIS2? Contact us for a free initial consultation and an initial assessment of how this affects your business!