Compliance

Preparing for NIS2 technically

31 July 2026

NIS2 raises the requirements for cybersecurity, risk management and reporting capability. We show which technical foundations companies should prepare in a structured way.

As the European NIS2 directive is implemented, the requirements for cybersecurity, risk management and organizational responsibility rise significantly. For many companies this means: information security has to become more traceable, better documented and more operationally robust.

The good news: those who proceed in a structured way don't need to fall into hectic activism. Many requirements can be prepared cleanly on the technical side if inventory, access control, logging, incident response and documentation are organized early.

Who should assess NIS2?

NIS2 affects far more organizations than the previous regulation. Whether a company is in scope depends, among other things, on sector, size, role in the supply chain and the type of services provided.

IT service providers, digital infrastructure, energy, health, transport, water, waste management and other regulated sectors in particular should assess their scope early. What matters is not only your own size, but also your role as a service provider or supplier.

Assess scope first

The first step is not tool selection, but a clean scope assessment. If you are unsure whether NIS2 applies, clarify this early and in a documented way.

The core obligations

Registration

Affected entities must record and keep their classification and contact details traceable and up to date

Risk management

Technical and organizational measures must reduce risks systematically

Reporting obligations

Security incidents must be detectable, assessable and reportable within defined deadlines

Management accountability

Cybersecurity becomes a leadership responsibility and must be monitored in a traceable way

What has to be prepared technically

NIS2 is not purely a documentation project. Companies must be able to show that security measures work in operation. This includes current asset information, clear responsibilities, traceable access, resilient backups, effective logging and defined reporting channels.

Without technical transparency, compliance quickly becomes theoretical. Anyone who doesn't know which systems, data, service providers and interfaces are in play can neither assess risks properly nor classify incidents in time.

Ten areas of risk management

1

Risk analysis & InfoSec

2

Incident response

3

Business continuity

4

Supply chain & providers

5

Procurement & maintenance

6

Effectiveness review

7

Cyber hygiene & training

8

Cryptography & encryption

9

Access control & assets

10

MFA & secure communication

Deadlines, reporting and responsibility

NIS2 provides for a staged reporting procedure for significant security incidents. Companies therefore need not only to detect technically that something has happened, but also to quickly assess whether a reportable incident exists.

In practice this means: logs, responsibilities, escalation paths and decision processes must be defined before the emergency. A 24-hour deadline is not a documentation problem, but an operational one.

Technical preparation without the rush

1

Take inventory

Make systems, data, sites, service providers, interfaces and responsibilities visible

2

Assess gaps

Compare existing measures with the requirements and derive priorities

3

Strengthen the basics

Set up MFA, access control, segmentation, backup and patch processes robustly

4

Build logging

Capture relevant security events centrally and make them analyzable

5

Practice the incident process

Test reporting paths, roles, escalations and decision routes before an incident happens

6

Include the supply chain

Bring service providers, contracts, technical access and evidence into the security scope

No compliance without operations

NIS2 preparation doesn't work with documents alone. What matters is whether technical measures are implemented, monitored and improved in a traceable way in everyday operations.

Prepare for NIS2 in a structured, technical way
To IT Security