Skip to main content

NIS2, as a reference process you can map against.

Directive (EU) 2022/2555 and its German transposition (BSIG, in force since 6 December 2025) turned into a documented target process across 12 modules and 22 grounded controls — every step cited to the directive article and the BSIG paragraph.

22
grounded controls
12
process modules
2025
BSIG in force · 6 Dec
NIS2 (EU 2022/2555) & BSIG 2025
EU basis
Directive (EU) 2022/2555
German law
BSIG 2025 · in force 6 Dec 2025
BSI registration
3 months · grace until 31 Jul 2026
Fines up to
EUR 10m / 2% of turnover
Controls
22 (article + BSIG paragraph)
Map & Gap

From target process to a prioritised gap list.

01

Reference process (target state)

The blueprint lays out the documented target process across its modules — every step anchored to the article or clause it derives from.

02

Map your current state

Map your existing processes module by module against the reference — system of record, owner, last review.

03

See the gaps

Each module yields a gap status (absent · partial · met) with a severity, a concrete remediation action and a target date.

04

Evidence, not opinion

The deterministic scanner grades the controls; the specialist advisor assists with the mapping — grounded in the regulation, ready for the auditor.

Target process

12 modules, each control covered exactly once.

The reference process groups all 22 NIS2/BSIG controls into 12 modules — from scope classification to MFA.

Art. 2-3 / § 28

Scope & classification

Size thresholds and Annex I/II sector mapping decide whether the entity is essential or important — documented and re-assessed annually.

§§ 33-34 BSIG

BSI registration & master data

Register with the BSI within three months and keep the data current; special regime for digital-infrastructure entities.

Art. 20 / § 38

Governance & management duties

Management implements and monitors the measures, trains regularly and documents fulfilment — personal liability attaches to breaches.

Art. 21(2)(a) / § 30

Risk analysis & measures framework

All-hazards risk analysis and the full measures catalogue, proportionate and per the state of the art.

Art. 21(2)(b) / § 31

Incident handling & attack detection

Incident response with severity classification; critical facilities additionally operate attack detection systems (German gold-plating).

Art. 23 / § 32

Reporting: 24h / 72h / 1 month

Three-stage notification to the BSI — early warning, full notification, final report — plus informing service recipients.

Art. 21(2)(c)

Business continuity & crisis management

Continuity plans with RTO/RPO, tested backups incl. offline copies, and a crisis organisation with exercises.

Art. 21(2)(d)

Supply chain security

Assess direct suppliers, anchor cybersecurity clauses contractually, consider EU coordinated risk assessments.

Art. 21(2)(e)

Secure acquisition, development & vulnerabilities

Lifecycle security in procurement and development plus a vulnerability management process with patch SLAs.

Art. 21(2)(f) / § 39

Effectiveness assessment & BSI evidence

Audits, pentests and KPI reviews — critical-facility operators prove implementation to the BSI every three years.

Art. 21(2)(g)+(h)

Cyber hygiene, training & cryptography

Recurring role-based training with tracking, basic hygiene baselines and a cryptography policy with key management.

Art. 21(2)(i)+(j)

Access control, assets & MFA

Role-based access with PAM and timely deprovisioning, a complete asset inventory, MFA and secured emergency communications.

Accuracy first

EU directive and German law, kept apart.

Every control cites the directive article and, where applicable, the BSIG paragraph — but the two are never blended: the § 30(2) catalogue is cited at paragraph level because the item-by-item numbering has not been verified digit-for-digit against the Federal Law Gazette. The BSI registration grace period (31 Jul 2026) is enforcement practice, not law, and sector-specific ordinances are still pending — all of it labelled as such instead of presented as settled.

Book a demo

Set up your NIS2 blueprint together.

30 minutes with our team: we walk the target process, map it against your current state and show the path to a prioritised gap list — no sales loop.