NIS2Compass
Use CasesBlogPricingFAQ
Sign In
Sign Up
NIS2Compass

Your Navigator Through NIS2 Compliance

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Imprint

Resources

  • Blog
  • Use Cases
  • Pricing
  • FAQ

Connect

Contact

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

Β© Copyright 2026 NIS2Compass. All Rights Reserved.

πŸ‡©πŸ‡ͺMade in Germany
NIS2Compass
Use CasesBlogPricingFAQ
Sign In
Sign Up

FAQ

Common questions about NIS2 compliance and NIS2Compass

What is the NIS2 Directive?

NIS2 (Network and Information Security Directive 2) is an EU directive that sets cybersecurity requirements for organizations in critical sectors. In Germany, it has been in force since December 6, 2025 as the NIS2UmsuCG, affecting over 29,000 companies. NIS2Compass guides you through all requirements as a structured companion.

Is my organization affected by NIS2?

NIS2 applies to medium and large organizations with 50+ employees or €10M+ annual revenue in 18 critical sectors. The NIS2Compass Vor-Check helps you determine in under 5 minutes whether your organization is affected and which obligations apply.

What are the penalties for non-compliance?

Essential entities face fines of up to €10 million or 2% of global annual turnover. Important entities can be fined up to €7 million or 1.4%. Additionally, management can be held personally liable. The NIS2Compass Knowledge Hub explains all penalty provisions in detail.

How long does NIS2 implementation take?

Implementation timelines vary by organization size and current security maturity, but typically range from 6 to 18 months. NIS2Compass provides a clear roadmap with prioritized actions to help you reduce the time to compliance.

What is the NIS2UmsuCG?

The NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) is the German transposition of the EU NIS2 Directive. It was passed by the German Parliament on November 13, 2025 and entered into force on December 6, 2025 β€” without any transition period.

What is the difference between NIS2 and ISO 27001?

ISO 27001 is a voluntary international standard for information security management systems. NIS2 is a legal obligation with specific reporting duties and penalties. An ISO 27001 certification covers approximately 60–70% of NIS2 requirements β€” the NIS2Compass Guide shows you exactly which gaps remain.

What are the reporting obligations under NIS2?

For significant security incidents, affected companies must submit an initial notification to the BSI within 24 hours, followed by a full report within 72 hours. The NIS2Compass Knowledge Hub explains the reporting process step by step.

Who is liable for NIS2 violations β€” the company or management?

Both. Companies face fines of up to €10 million. Additionally, management can be held personally liable if they neglect their supervisory duties. Under Β§ 38 BSIG, executives must actively oversee the implementation of cybersecurity measures.

Do I need to register with the BSI?

Yes, all companies affected by NIS2 must register with the BSI. The BSI portal has been available since January 6, 2026, and the registration deadline expired on March 6, 2026. Companies that missed the deadline should register immediately.

Do I need an ISMS for NIS2?

NIS2 does not mandate a formal ISMS, but requires measures across 10 areas β€” from risk management to incident handling to supply chain security β€” that effectively correspond to one. NIS2Compass guides you through all required measures as a structured companion, even without an existing ISMS.

What technical measures does NIS2 require?

NIS2 requires access control, encryption, network security, vulnerability management, and multi-factor authentication, among others. The NIS2Compass Template Library contains over 20 templates for policies and documentation of these measures.

What does NIS2 compliance cost?

External NIS2 consultants typically charge €700–1,200 per day β€” a full project ranges from €10,000–30,000. NIS2Compass offers the Pro plan at €29/month as a structured alternative with all articles, templates, and the NIS2 Guide.

What is the NIS2Compass Vor-Check?

The Vor-Check is a free gap analysis that assesses your current compliance status in under 5 minutes. Based on 16 questions about your existing security measures, it shows you which NIS2 requirements are already met and where action is needed.

Can I cancel my subscription at any time?

Yes, you can cancel your subscription at any time from your account settings. You will retain access until the end of your current billing period.

Does NIS2Compass support smaller organizations?

Yes. NIS2Compass was designed specifically for SMBs with 30–250 employees β€” as a structured alternative to expensive consultants and complex enterprise tools. The Pro plan at €29/month provides everything you need for NIS2 compliance.
Still have questions? Contact us