Clouderio
NIS2 · KRITIS · ISO 27001 · 24h reporting obligation · Executive liability
NIS2 Directive (EU 2022/2555)KRITISISO 27001

NIS2 compliance in 12 weeks — before your supervisory authority comes knocking

Meet your NIS2 obligations — without the stress

Gap analysis, risk assessment, technical and organizational measures and reporting obligations under the NIS2 Directive. End-to-end implementation support.

PartnersMicrosoft PartnerGoogle PartnerAWS PartnerIONOS Partner
GDPR-compliant
NIS2-compliant
Servers in Germany
<4h response time
€10M
maximum fine
or 2% of global annual revenue — managing directors are personally liable
24h
incident reporting deadline
early warning within 24h, full notification within 72h
12 wks
to NIS2 compliance
from gap analysis to complete evidence
Anonymized reference caseRegional energy supplier · Rhine-Main region, 120 employees
+

Starting point

Subject to NIS2 as a KRITIS (critical infrastructure) operator, no ISMS, no documented security processes, no incident reporting channels.

Solution & result

Complete NIS2 implementation: gap analysis against all 10 requirements, ISMS setup, incident reporting, supply chain security, BSI registration.

NIS2 compliance achieved in 11 weeks, BSI registration completed, first simulated incident reported correctly, no fines.

The problem

NIS2 makes managing directors personally liable — without exception

  • Art. 20 NIS2: managing directors can be held personally liable for up to €10 million or with their private assets — ignorance is no defense
  • NIS2 applies to companies in 18 sectors — many SMEs do not know they are affected and risk fines
  • The 24h reporting obligation for security incidents cannot be met without prepared processes — missing the deadline doubles the fine
Our answer

Structured NIS2 implementation with complete evidence

  • Applicability check in the first session: are you essential or important? Which requirements apply to you specifically?
  • Implementation of all 10 NIS2 security requirements with prioritized measures and a realistic timeline
  • Complete compliance documentation for regulatory audits — including ISMS, incident reporting and supply chain security

Scope of services

What NIS2 Compliance does for you

NIS2 Gap Analysis

Assessment of whether and to what extent your company falls under NIS2 — including classification as an important or essential entity.

Technical Security Measures

Implementation of all technical requirements: access controls, cryptography, vulnerability management and network security.

Organizational Measures

Development of security policies, contingency plans, training programs and governance structures.

Incident Reporting & Early Warning

Setup of a reporting system for security incidents: early warning within 24h, full notification within 72h.

Supply Chain Security

Review and safeguarding of critical suppliers and service providers in line with NIS2 requirements.

Evidence Documentation

Complete compliance documentation for regulatory audits — NIS2 requires proof of implementation.

Approach

How we work

1

Applicability Check

Determining whether and in which category your company falls under NIS2 (essential or important).

2

Gap Analysis

Systematic target-vs.-actual comparison against all 10 NIS2 security requirements.

3

Implementation of Measures

Implementation of technical and organizational security measures by priority.

4

Evidence & Monitoring

Documentation for the authorities and ongoing compliance monitoring with an annual report.

“

As a KRITIS operator, NIS2 implementation was our top priority. Clouderio built a complete ISMS in 11 weeks and got us registered with the BSI. It was impressively well structured.

KR
Klaus R.
Technical Director · Energy supplier, Rhine-Main region, 120 employees

Affected Sectors

Does NIS2 apply to you?
Check now

NIS2 applies to companies with 50 or more employees or €10 million in revenue in these sectors. You may also be indirectly affected as a supplier or IT service provider.

⚡

Energy

essential

🚛

Transport & Logistics

essential

🏦

Banking & Finance

essential

🏥

Healthcare

essential

🌐

Digital Infrastructure

essential

💧

Water & Wastewater

essential

💻

IT Service Providers

important

📦

Postal & Courier

important

🥗

Food

important

⚗️

Chemicals

important

⚙️

Mechanical Engineering

important

🏛️

Public Administration

essential

Management Liability

Personal liability of
management

NIS2 Art. 20 is unambiguous: management bodies are personally liable for implementing cybersecurity measures. Ignorance is no defense.

Fines

Essential entities: up to €10 million or 2% of annual revenue

Personal liability

Managing directors can be temporarily barred from management functions

24-hour reporting obligation

Early warning within 24 hours, full notification within 72 hours

Solution

Full NIS2 compliance protects you from all of these consequences

NIS2 Art. 21

The 10 NIS2 Security Requirements

We fully implement all 10 requirements — with evidence for supervisory authorities.

01

Risk Analysis & Security Policies

Documented risk analysis and formal security policies for all relevant areas

02

Incident Management

Processes for detecting, reporting, and responding to security incidents, including 24-hour early warning

03

Business Continuity

Backup strategies, contingency plans, and recovery processes for critical systems

04

Supply Chain Security

Security requirements for suppliers and service providers, risk assessment of the supply chain

05

Security in Development & Procurement

Security requirements when developing new systems and procuring IT products

06

Effectiveness Assessment

Regular review of the effectiveness of all security measures, audits, and tests

07

Cyber Hygiene & Training

Regular employee training, password policies, MFA, and basic security practices

08

Cryptography

Encryption of sensitive data in transit and at rest according to the current state of the art

09

Personnel Security & Access Control

Role-based access rights, background checks, offboarding processes

10

Multi-Factor Authentication

MFA mandatory for all privileged access and external system access

Our 12-Week Program

Wk. 1–2

Applicability & Gaps

Applicability check, gap analysis against all 10 requirements, risk prioritization

Wk. 3–8

Measures

Implement technical and organizational measures by priority

Wk. 9–11

Documentation

Finalize the ISMS, set up incident reporting, conduct training

Wk. 12

Evidence

Compliance evidence, final presentation, BSI (German Federal Office for Information Security) registration if required

FAQ

Frequently asked questions

Everything you need to know about NIS2 Compliance at a glance.

01Am I subject to NIS2?+

NIS2 applies to medium-sized and large companies (50+ employees or €10M+ revenue) in 18 sectors: energy, transport, water, banking, financial markets, health, digital infrastructure, public administration and more. In a free initial consultation, we check whether you are affected — including indirect obligations as a supplier.

02What are the 10 NIS2 security requirements?+

NIS2 Art. 21 requires: (1) risk analysis & security policies, (2) incident handling, (3) business continuity, (4) supply chain security, (5) security in development, (6) assessment of effectiveness, (7) cyber hygiene & training, (8) cryptography, (9) personnel security & access control, (10) multi-factor authentication. We implement all 10.

03How does NIS2 implementation work?+

Weeks 1–2: applicability check and gap analysis. Weeks 3–8: implementation of technical and organizational measures by priority. Weeks 9–11: documentation, ISMS completion, incident reporting setup. Week 12: final presentation and proof of compliance. The timeline is binding — and we stick to it.

04How much does NIS2 compliance cost?+

For SMEs (50–200 employees), we estimate a project price of €15,000–35,000 for the complete initial implementation. Ongoing NIS2 compliance management from €1,200/month. Compared with a potential fine of €10 million, that is a manageable investment.

05Do we have to report cyberattacks?+

Yes. NIS2 Art. 23: for significant security incidents, you must submit an early warning to the competent authority (the BSI, Germany's Federal Office for Information Security) within 24 hours, a full notification within 72 hours, and a final report within one month. We build this process for you.

06What happens if we do not implement NIS2?+

Essential entities: up to €10 million or 2% of global annual revenue. Important entities: up to €7 million or 1.4% of revenue. On top of that comes personal liability for management. The German authorities have announced that they will actively carry out inspections.

Free assessment workshop — no obligation

In 60 minutes, we analyze your current situation and show you exactly which solution makes sense for your business — with a binding quote within 5 business days.

Free applicability check
NIS2 compliance in 12 weeks
Complete documentation for the authorities
Bad Homburg vor der Höhe · Rhine-Main Region