We'll determine whether you're affected, identify any gaps, implement the necessary measures, and provide documentation that will stand up to scrutiny.
Certified NIS2 Consultants · NIS2, CRA, and ISO 27001
NIS2 is now law and applies not only to critical infrastructure. Starting in 2027, the Cyber Resilience Act will also apply to all manufacturers of products with digital components.
It also affects medium-sized companies in the energy, healthcare, IT, transportation, food, and manufacturing sectors—as well as suppliers who aren't even active in any of those sectors themselves.
If you only meet the requirements on paper, you have a document but no security. This becomes apparent during an audit—or, at the very latest, after an incident.
Responsibility for implementation lies explicitly with management. This is not a theoretical risk, but is enshrined in law.
or 2% of global annual revenue: the range for fines imposed on significant entities.
NIS 2 Directive, Article 34
Deadline for reporting the incident to the appropriate authority; an early warning is issued after just 24 hours.
NIS 2 Directive, Article 23
Six questions, two minutes, instant results. The quick check tells you whether NIS2 applies to your company.
We’re with you every step of the way: determining whether you’re affected, identifying gaps, implementing measures, and providing proof.
Assess the impact, identify gaps, implement measures, and document them.
For manufacturers and retailers of products with digital components.
Establish an information security management system and prepare for certification.
Requirements, processes, and documentation, right through to reporting to the authorities.
In an emergency, what matters isn't
what you've done, but what you can prove.
That is why we create the documentation at the same time as implementation, rather than after the audit date.
Every step is verifiable and builds on the previous one. As a result, the end result is not a pile of paper, but a traceable chain.
We will determine whether and to what extent you are subject to NIS2 or the Cyber Resilience Act. Your industry, size, revenue, and business activities determine your classification.
We assess your situation against all the requirements that apply to you. Every gap is identified, evaluated, and prioritized based on urgency.
Based on the analysis, a plan is developed that includes a sequence of steps, realistic deadlines, responsibilities, and an estimate of the effort required.
On the organizational side, this includes guidelines, processes, and training; on the technical side, it involves measures implemented on the systems. We handle both aspects with the same team.
All implemented measures are documented in a verifiable manner, including the emergency plan and reporting procedures. This ensures you are prepared for inspections by regulatory authorities, auditors, and customer audits.
Detection, response, maintenance status, and access are explicitly required. Anyone who only provides documents is only halfway there.
Both managing directors hold the WKO incite certification. Philipp Trummer also serves as a lecturer in the field of cybersecurity.
Attack detection, maintenance status, emergency response: These are legal requirements, and we handle them ourselves rather than passing them on to your IT department.
The documentation is structured in such a way that it can withstand an inspection by regulatory authorities and a customer audit. That is exactly what matters when it comes to personal liability.
Implementation is governed by national law. We are familiar with the relevant authorities, the deadlines, and the procedures—not just the text of the directive.
The key factors are sector and size. The sectors affected include energy, healthcare, water, IT, transportation, and finance; organizations with 50 or more employees or 10 million euros in revenue are considered “important entities,” while those with 250 or more employees or 50 million euros in revenue are considered “significant entities.” Suppliers may also be affected. We’ll clarify the specifics during our initial consultation.
Fines of up to ten million euros or two percent of global annual revenue may be imposed, and management may be held personally liable in cases of proven negligence. The regulatory authority may also order restrictions on operations.
That depends on the starting point. Companies with an established security culture often need three to six months; those starting from scratch should plan for six to twelve months. After the gap analysis, we’ll provide a realistic timeline.
The organizational side—including policies, processes, and training—yes. The technical side requires specialized knowledge, such as in attack detection, maintenance status, backups, and network isolation. We support both areas and take the load off your team where it makes sense.
An EU regulation that will apply starting in 2027 to manufacturers, distributors, and importers of products with digital components—that is, software, connected hardware, and devices. It requires security by design, the management of vulnerabilities, and documentation throughout the entire lifecycle.
NIS2 applies to companies that provide certain services and requires operational security. The Cyber Resilience Act applies to products and requires security built into the product itself. A company may be subject to both.
It is filled with real-life risk management that actually takes place in everyday life.
We assess your compliance status, identify any gaps, and guide you through the process until you have provided proof.
We use cookies to operate this website and analyze its usage. You decide which categories to allow. You can adjust your settings at any time.