Who’s in Scope?
NIS2 covers 18 sectors with tiered requirements. Essential entities (stricter): energy, transport, banking, health, digital infrastructure. Important entities (lighter): postal, waste, chemicals, food, manufacturing. Threshold: 50+ employees OR €10M+ turnover.
Article 21: The 10 Minimum Measures
- Risk analysis and IS security policies
- Incident handling (detection, response, reporting)
- Business continuity and crisis management
- Supply chain security
- Security in network systems acquisition, development, maintenance
- Assessment of cybersecurity effectiveness
- Basic cyber hygiene and training
- Cryptography and encryption policies
- HR security, access control, asset management
- MFA, secured communications, emergency protocols
Where ISO 27001 Isn’t Enough
Incident Reporting Timelines
24h early warning → 72h full notification → 1 month final report. Most ISO 27001 orgs lack this cadence.
Management Accountability
Geschäftsführung/Vorstand personally accountable. Must approve measures, oversee implementation, complete training.
Supply Chain Specifics
Must assess actual cybersecurity posture of direct suppliers—not merely questionnaires.
Practical Roadmap
Phase 1 — Scope & Gap (Weeks 1–4)
Confirm classification. Map Article 21 to existing controls. Assess 24h reporting capability. Review supply chain assessment processes.
Phase 2 — Remediate (Weeks 5–12)
Update IR with strict timelines. Establish management accountability. Strengthen supply chain. Deploy MFA, encryption, vulnerability management.
Phase 3 — Sustain (Ongoing)
Continuous monitoring. Regular testing of IR, BC, and supply chain. Documentation maintenance.
AI Acceleration
| Task | Without AI | With AI Agents |
|---|---|---|
| Vendor assessment | 2–3 weeks | 3 hours |
| Incident report draft | 4–6 hours | Minutes |
| Policy gap analysis | 2 weeks | 2 hours |
| Compliance checks | Quarterly | Continuous |
Need help implementing this?
First strategy session is complimentary. We typically respond within 4 hours.