NIS2 requires a structured information security management system. If you already have ISO 27001, you're close — but not there yet.
An information security management system (ISMS) is not a product you buy — it is a structured framework of policies, processes, responsibilities and controls that is put into lasting practice. NIS2 explicitly requires this framework.
The greatest effort, but a clear starting point. We guide you from the gap analysis to a working ISMS.
A good starting position — but NIS2 adds requirements that ISO 27001 does not fully cover.
A strong technical foundation; NIS2-specific regulatory elements need to be added.
NIS2 does not prescribe a specific ISMS standard, but § 30 BSIG defines a clear catalogue of requirements. These six areas must be covered in every NIS2-compliant ISMS.
Systematic identification, assessment and treatment of risks to your services and IT systems.
Detection, reporting and response processes for significant security incidents under § 32 BSIG.
Backup concepts, contingency plans and crisis management to maintain service delivery.
Security requirements for external service providers and suppliers, anchored contractually.
Demonstrable training of executive management (§ 38) and security awareness for all employees.
Audit-ready records for regulators — available at any time, not just in an emergency.
Whether starting from scratch or expanding an existing system — we guide you from the gap analysis to an audit-ready ISMS.
Request Consultation Now