NIS2: obligations met —
and evidenced.
NIS2 places duties on management personally — risk management, notification paths, supply-chain review and training. We assess your position against the duties of the German NIS2 implementation act and deliver a list of findings from which the order of actions follows directly.
What is included.
An assessment against the duties of the German NIS2 implementation act.
Scope and role
Classification as an important or essential entity; registration duties, deadlines, competent authority.
Risk management under Art. 21
The ten minimum measures assessed one by one: risk analysis, incident handling, backup, supply chain, cryptography, MFA, training — with evidence per item.
Notification and management duties
Early warning within 24 hours, notification within 72, final report; evidence of management accountability and training under Art. 20.
Findings and sequence
Each finding with effort, dependency and owner; a risk heatmap across five dimensions and a board report of 8–12 pages.
Secureskies does not provide legal advice. The applicability review is a technical and organisational reading; the binding assessment is for your legal function or outside counsel to make.
Five steps,
one deliverable.
Scoping
Clarify applicability, scope, stakeholders and available documents.
Discovery
Interviews with IT, procurement, legal and management; document review.
Assessment
Maturity per duty with evidence; heatmap across identity, cloud posture, supply chain, OT and governance.
Planning
Prioritise actions, estimate effort, name owners.
Report
Board report and roadmap, presented to management.