← All Articles

NIS2 Readiness: What German CISOs Actually Need to Do

January 28, 2026 · 6 min read
18
sectors in scope
24h
reporting deadline
€10M
max fine
60–70%
ISO 27001 overlap

Who’s in Scope?

NIS2 covers 18 sectors with tiered requirements. Essential entities (stricter): energy, transport, banking, health, digital infrastructure. Important entities (lighter): postal, waste, chemicals, food, manufacturing. Threshold: 50+ employees OR €10M+ turnover.

Article 21: The 10 Minimum Measures

  1. Risk analysis and IS security policies
  2. Incident handling (detection, response, reporting)
  3. Business continuity and crisis management
  4. Supply chain security
  5. Security in network systems acquisition, development, maintenance
  6. Assessment of cybersecurity effectiveness
  7. Basic cyber hygiene and training
  8. Cryptography and encryption policies
  9. HR security, access control, asset management
  10. MFA, secured communications, emergency protocols

Where ISO 27001 Isn’t Enough

Incident Reporting Timelines

24h early warning → 72h full notification → 1 month final report. Most ISO 27001 orgs lack this cadence.

Management Accountability

Geschäftsführung/Vorstand personally accountable. Must approve measures, oversee implementation, complete training.

Supply Chain Specifics

Must assess actual cybersecurity posture of direct suppliers—not merely questionnaires.

Penalties: Essential entities: up to €10M or 2% global turnover. Important entities: up to €7M or 1.4% turnover. Personal liability for management board members.

Practical Roadmap

Phase 1 — Scope & Gap (Weeks 1–4)

Confirm classification. Map Article 21 to existing controls. Assess 24h reporting capability. Review supply chain assessment processes.

Phase 2 — Remediate (Weeks 5–12)

Update IR with strict timelines. Establish management accountability. Strengthen supply chain. Deploy MFA, encryption, vulnerability management.

Phase 3 — Sustain (Ongoing)

Continuous monitoring. Regular testing of IR, BC, and supply chain. Documentation maintenance.

AI Acceleration

Task Without AI With AI Agents
Vendor assessment2–3 weeks3 hours
Incident report draft4–6 hoursMinutes
Policy gap analysis2 weeks2 hours
Compliance checksQuarterlyContinuous

Need help implementing this?

First strategy session is complimentary. We typically respond within 4 hours.