Clarity on applicability, obligations, and priorities in 1–2 days.
from €2,900
excl. VAT · 1–2 days
The NIS2 Implementation Act has been in force since December 2025. Around 30,000 companies in 18 sectors are in scope; BSI registration has closed — and for most organisations the real work is yet to begin: the ten required risk-management measures, a functioning incident-reporting process, and evidence that stands up to scrutiny.
In one to two days you get a reliable status assessment and a prioritised roadmap for the next twelve months — in a form your management can actually work with.
NIS2 obligations apply regardless of whether anyone asks. The supervisory authority can audit at any time; fines reach seven figures depending on classification — and the point that changes the mood in board meetings is that management bears personal responsibility: it must approve the risk-management measures, oversee their implementation, and complete regular training. All three must be documented.
Most companies don't fail for lack of intent, but for lack of prioritisation: the ten measure areas feel overwhelming, and without an honest maturity assessment you start at the wrong end.
You receive a structured questionnaire and a list of documents to review (existing policies, continuity plans, supplier overview, IT documentation). We analyse these in advance so the shared time is not spent gathering facts.
Sector assignment, thresholds, classification as particularly important or important facility. We also clarify supply-chain applicability: requirements passed down to you by customers apply contractually even if you are not directly regulated.
Status of your BSI registration. Then the reporting process along the statutory deadlines: initial notification within 24 hours, follow-up within 72 hours, final report within one month. We examine whether your organisation could actually deliver that on a Friday evening — accountability, availability, escalation path, templates.
Maturity assessment per area with reasoning and evidence: risk analysis and security policies · incident handling · business continuity · supply-chain security · security in procurement and maintenance · effectiveness assessment · basic cyber hygiene and training · cryptography and encryption · personnel security and asset management · multi-factor authentication.
What approval, oversight, and training obligations mean in practice — and how to document them in a way that holds up in an emergency.
Joint prioritisation of gaps by risk, effort, and deadline. The output is a 12-month roadmap with owners and effort estimates.
Results report within ten working days, followed by a one-hour presentation of findings — on request directly to your management.
| Ergebnis | Form |
|---|---|
| Results report — applicability, maturity per measure area as traffic light, gaps with reasoning, recommendations | PDF, 15–25 pages |
| Prioritised 12-month roadmap — measures ranked by risk and effort, with estimates | PDF + Excel |
| Management summary — the liability-relevant points for executives | PDF, 2 pages |
| Incident-reporting brief — accountability, escalation, notification templates for 24 h / 72 h / 1 month | Word, editable |
| Your measures as a task list — importable to Jira; if you use the maplee ISMS mit Jira & Confluence, directly in measure management | CSV / Jira import |
| Duration | 1 day compact (remote) or 2 days extended (on-site, with departments) |
| Participants | 3–8 people: executive management, IT leadership, CISO, optionally procurement and HR |
| Preparation | approx. 2 hours on your side (questionnaire, documents) |
| Price | €2,900 excl. VAT compact · €4,900 excl. VAT extended incl. travel within DACH |
| Lead time | typically 2–3 weeks to schedule |
We typically respond within one working day.