secureskies
Cyber Security/Evaluate/NIS2 Maturity Assessment

NIS2: obligations met —
and evidenced.

NIS2 places duties on management personally — risk management, notification paths, supply-chain review and training. We assess your position against the duties of the German NIS2 implementation act and deliver a list of findings from which the order of actions follows directly.

FormatAssessmentinterviews + documents
Duration6–12 weeksscope fixed in the proposal
ReferenceNIS2UmsuCGNIS2 Art. 20–23
OutcomeFindings listplus roadmap and board report
01 · Service

What is included.

An assessment against the duties of the German NIS2 implementation act.

Scope and role

Classification as an important or essential entity; registration duties, deadlines, competent authority.

Risk management under Art. 21

The ten minimum measures assessed one by one: risk analysis, incident handling, backup, supply chain, cryptography, MFA, training — with evidence per item.

Notification and management duties

Early warning within 24 hours, notification within 72, final report; evidence of management accountability and training under Art. 20.

Findings and sequence

Each finding with effort, dependency and owner; a risk heatmap across five dimensions and a board report of 8–12 pages.

Secureskies does not provide legal advice. The applicability review is a technical and organisational reading; the binding assessment is for your legal function or outside counsel to make.

02 · Process

Five steps,
one deliverable.

01

Scoping

Clarify applicability, scope, stakeholders and available documents.

02

Discovery

Interviews with IT, procurement, legal and management; document review.

03

Assessment

Maturity per duty with evidence; heatmap across identity, cloud posture, supply chain, OT and governance.

04

Planning

Prioritise actions, estimate effort, name owners.

05

Report

Board report and roadmap, presented to management.

03 · Who it fits

When this service
applies.

Companies in scope of the German NIS2 implementation act, or testing whether they are
Suppliers to NIS2 entities facing supply-chain requirements
Management teams that want their personal accountability documented
More services · Evaluate

Are you in scope for NIS2 —
and since when?