Leading Through Knowledge and Experience
News
Sindelfingen, Germany, August 11, 2026

Eight Months into NIS2: Multiple Studies Reveal the Same Implementation Hurdles – CONSUVATION Delivers the Practical Answers

Documentation, incident reporting, risk management, applicability assessments and supply chain security remain the biggest stumbling blocks according to several recent studies. CONSUVATION addresses them with an end-to-end IT solution – and supports companies on an ongoing basis as an external officer.

Eight months after the EU's NIS2 cybersecurity regulation took effect, several independent studies are painting the same picture: NIS2 has arrived in the business world, but for many companies practical implementation remains a real challenge. A recent short survey by eco – the Association of the Internet Industry – among 38 companies from the security community shows this just as clearly as Schwarz Digits' "Cyber Security Report 2026," based on more than 1,000 German companies, and a Europe-wide survey by CyberSmart among 670 executives.

In CONSUVATION's experience, the reason is rarely a lack of willingness but a lack of in-house expertise: many companies, particularly in the small and mid-sized segment, simply do not have permanent access to the compliance and information security know-how they need. Rather than offering isolated consulting projects, CONSUVATION takes on the role of external officer itself, bringing the missing expertise permanently into the company.

NIS2 Doesn't Stop at Germany's Border

A common misconception is that NIS2 is a purely domestic matter for companies headquartered in Germany or the EU. In reality, the territorial scope of the NIS2 Directive is triggered as soon as a company provides a service or carries out activities within the EU – regardless of where its headquarters are located. Under Sections 59 and 60 of Germany's BSIG, what matters is whether a company is established in Germany or has designated a representative there – not where the underlying IT services are technically performed. For companies headquartered outside the EU that provide certain digital infrastructure or ICT services into Germany or the EU (e.g. DNS providers, cloud services, data centre services, content delivery networks, managed service providers, online marketplaces or social networking platforms), Article 26 of the NIS2 Directive requires the designation of a representative established in an EU member state.

The Grace Period Has Ended

What was often understood publicly as a "deadline extension" was legally never an implementation grace period: the statutory registration obligation under Section 33 BSIG already ended on March 6, 2026, three months after the NIS2 Implementation and Cybersecurity Strengthening Act took effect. Because only a fraction of the roughly 29,500 affected companies had registered by then, the BSI merely granted an enforcement grace period until July 31, 2026. That grace period has since expired.

18,845of roughly 29,500 expected entities currently registered
€500,000possible fine for registration violations
18%of companies fully implemented, per eco

Failure to register remains an administrative offence, and with the end of the tolerance phase, stricter enforcement by the BSI is to be expected. For many companies this means the time they treated as a de facto preparation phase has, formally, long since run out.

A Pattern Across Multiple Studies

According to eco, the companies surveyed named four central problem areas: evidence and audit obligations (around 26 percent of mentions), reporting processes with their 24-/72-hour deadlines (around 25 percent), risk analysis and risk management (around 21 percent), and a registration process itself perceived as complex. Other surveys paint a similar picture: according to Schwarz Digits, nearly one in two companies (48 percent) misjudges its own NIS2 applicability. A Europe-wide survey by CyberSmart shows that only 16 percent of executives feel fully prepared for NIS2.

"Companies don't need abstract lists of obligations – they need clear priorities and workable implementation support." Ulrich Plate, Head of eco's KRITIS Competence Group

CONSUVATION Turns Lists of Obligations into Processes

For every hurdle identified in these studies, CONSUVATION has a proven, immediately deployable solution in its portfolio:

More Than Consulting: An End-to-End IT Solution

The decisive difference from classic case-by-case consulting: CONSUVATION delivers implementation as an end-to-end, immediately usable platform built from five interlocking components: a proven process model, supporting software for ongoing evidence management, ready-made policies, a proprietary e-learning portal for mandatory employee training, and a management dashboard with continuous visibility into implementation status, deadlines and open evidence items.

On request, CONSUVATION goes a step further: companies report security incidents directly through the platform, and CONSUVATION, acting as external NIS2 officer, handles the timely filing of reports with the authorities – turning NIS2 into a managed process rather than a permanent construction site, and noticeably faster than going it alone.

"Companies don't fail because they lack the will, but because they struggle to translate the regulation into workable processes. That's why we hand our clients more than advice – we give them a complete IT solution. With software, policies, an e-learning portal and a dashboard, NIS2 runs quietly in the background instead of causing headaches." Peter Rentschler, Managing Director, CONSUVATION GmbH – information security expert with more than 25 years of experience

Learn More

Further information on NIS2 – from applicability assessments to the legal background and practical insights – is available on an ongoing basis at nis2-richtlinie.de (German-language), CONSUVATION's NIS2 information portal.

Not sure whether NIS2 applies to your company – or where you stand?

CONSUVATION clarifies your NIS2 applicability and shows the fastest path to implementation.

Get in Touch Now
Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com