Risk management
Ten areas of measures, from risk analysis and incident handling to backups, supply chain security, cryptography and access control.
NIS2 compliance
Germany’s NIS2 law has applied since 6 December 2025, with no transition period. Around 29,000 companies are in scope, and management is personally responsible. We check if you are affected, close the real gaps first and give you the evidence to prove it.
In short
NIS2 is the EU directive on cybersecurity for essential and important entities. Germany implemented it with the NIS2 Implementation Act, in force since 6 December 2025. It applies to companies in 18 sectors with at least 50 employees or more than €10 million in turnover and balance sheet total, requires risk-management measures, registration with the BSI and incident reporting within 24 hours, and makes management liable. Zyberum offers NIS2 applicability checks, gap analyses, implementation of the required measures, penetration tests and 24/7 monitoring.
Who is affected
NIS2 covers 18 sectors, including energy, transport, healthcare, water, digital infrastructure, IT service management, manufacturing (machinery, vehicles, electronics, medical devices), chemicals, food, waste and postal services.
As a rule, you are in scope if you work in one of these sectors and have at least 50 employees, or more than €10 million in both annual turnover and balance sheet total. Some entities are covered regardless of size. Suppliers feel it too, because affected customers must secure their supply chain.
Timeline
Member states had to transpose the NIS2 Directive into national law by this date.
The NIS2 Implementation Act applies without a transition period. The obligations are binding.
Affected companies had three months to register with the Federal Office for Information Security (BSI).
Risk management must be implemented and documented. Management has to approve it, oversee it and get trained.
What the law requires
Ten areas of measures, from risk analysis and incident handling to backups, supply chain security, cryptography and access control.
Early warning within 24 hours, incident notification within 72 hours and a final report within one month.
Management must approve and oversee the measures, attend training, and can be held personally liable.
Affected companies register themselves with the BSI. Nobody will tell you that you are in scope.
You must assess the security of your suppliers and service providers, and your customers will assess yours.
Measures must be reviewed for effectiveness. Audits and penetration tests are the way to show it.
How we help
We determine whether you are in scope, in which category, and what that means for you.
Your current security against the required measures, prioritised by real risk, not by chapter number.
We put the missing measures in place with your team: incident process, backups, access control, supplier checks.
We attack your systems to show whether the measures hold, and you get evidence for the effectiveness review.
Penetration testingZyberdome detects and handles incidents around the clock, so the 24-hour reporting deadline is realistic.
ZyberdomeThe training that NIS2 requires for management, hands-on and in plain language.
TrainingFAQ
You are probably affected if you operate in one of the 18 NIS2 sectors and have at least 50 employees, or more than €10 million in both annual turnover and balance sheet total. Some entities, such as certain digital infrastructure providers, are covered regardless of size. Companies must assess this themselves.
The German NIS2 Implementation Act entered into force on 6 December 2025 and applies without a transition period. The deadline for registering with the BSI was 6 March 2026.
Up to €10 million or 2% of worldwide annual turnover for especially important entities, and up to €7 million or 1.4% for important entities. In addition, management can be held personally liable for failing to implement the measures.
Often yes. Companies in scope must secure their supply chain, so they pass security requirements on to suppliers and service providers through contracts and questionnaires.
It covers a large part of the risk-management measures, but not everything. Registration, the reporting deadlines and the management obligations come on top, and the scope of your ISO 27001 certificate must match the services that fall under NIS2.
Get started
One hour with an expert. We check whether NIS2 applies to your company and where your biggest gaps are.

Your call is withTom ZaubermannFounder & CEO, Zyberum
We reply within one business day.
Your privacy
We use cookies and similar technologies to measure our website and the success of our ads. You decide which ones we may use. You can change your choice at any time via "Cookie settings" in the footer. Privacy policy