From target process to a prioritised gap list.
Reference process (target state)
The blueprint lays out the documented target process across its modules — every step anchored to the article or clause it derives from.
Map your current state
Map your existing processes module by module against the reference — system of record, owner, last review.
See the gaps
Each module yields a gap status (absent · partial · met) with a severity, a concrete remediation action and a target date.
Evidence, not opinion
The deterministic scanner grades the controls; the specialist advisor assists with the mapping — grounded in the regulation, ready for the auditor.
12 modules, each control covered exactly once.
The reference process groups all 22 NIS2/BSIG controls into 12 modules — from scope classification to MFA.
Scope & classification
Size thresholds and Annex I/II sector mapping decide whether the entity is essential or important — documented and re-assessed annually.
BSI registration & master data
Register with the BSI within three months and keep the data current; special regime for digital-infrastructure entities.
Governance & management duties
Management implements and monitors the measures, trains regularly and documents fulfilment — personal liability attaches to breaches.
Risk analysis & measures framework
All-hazards risk analysis and the full measures catalogue, proportionate and per the state of the art.
Incident handling & attack detection
Incident response with severity classification; critical facilities additionally operate attack detection systems (German gold-plating).
Reporting: 24h / 72h / 1 month
Three-stage notification to the BSI — early warning, full notification, final report — plus informing service recipients.
Business continuity & crisis management
Continuity plans with RTO/RPO, tested backups incl. offline copies, and a crisis organisation with exercises.
Supply chain security
Assess direct suppliers, anchor cybersecurity clauses contractually, consider EU coordinated risk assessments.
Secure acquisition, development & vulnerabilities
Lifecycle security in procurement and development plus a vulnerability management process with patch SLAs.
Effectiveness assessment & BSI evidence
Audits, pentests and KPI reviews — critical-facility operators prove implementation to the BSI every three years.
Cyber hygiene, training & cryptography
Recurring role-based training with tracking, basic hygiene baselines and a cryptography policy with key management.
Access control, assets & MFA
Role-based access with PAM and timely deprovisioning, a complete asset inventory, MFA and secured emergency communications.
EU directive and German law, kept apart.
Every control cites the directive article and, where applicable, the BSIG paragraph — but the two are never blended: the § 30(2) catalogue is cited at paragraph level because the item-by-item numbering has not been verified digit-for-digit against the Federal Law Gazette. The BSI registration grace period (31 Jul 2026) is enforcement practice, not law, and sector-specific ordinances are still pending — all of it labelled as such instead of presented as settled.
Set up your NIS2 blueprint together.
30 minutes with our team: we walk the target process, map it against your current state and show the path to a prioritised gap list — no sales loop.