An Edge Built on Knowledge and Experience
NIS2 / BSIG § 30

Building and Expanding an ISMS for NIS2

NIS2 requires a structured information security management system. If you already have ISO 27001, you're close — but not there yet.

Technical & Legal Expertise Experience From Numerous NIS2 Projects Based in Sindelfingen
What Is an ISMS?

The ISMS as the Foundation of NIS2 Compliance

An information security management system (ISMS) is not a product you buy — it is a structured framework of policies, processes, responsibilities and controls that is put into lasting practice. NIS2 explicitly requires this framework.

No ISMS in Place

The greatest effort, but a clear starting point. We guide you from the gap analysis to a working ISMS.

  • Create an asset inventory
  • Build a risk analysis under § 30 BSIG
  • Develop mandatory policies
  • Define roles and responsibilities

ISO 27001 Already in Place

A good starting position — but NIS2 adds requirements that ISO 27001 does not fully cover.

  • Executive training obligation (§ 38 BSIG)
  • Integrate BSI reporting obligations
  • Expand supply chain security
  • Review the BSI registration obligation

BSI IT-Grundschutz Already in Place

A strong technical foundation; NIS2-specific regulatory elements need to be added.

  • Integrate NIS2 reporting channels and deadlines
  • Add management training and liability framework
  • Document evidence obligations
  • Review scope against NIS2 services
ISMS Core

The Six Building Blocks of an NIS2-Compliant ISMS

NIS2 does not prescribe a specific ISMS standard, but § 30 BSIG defines a clear catalogue of requirements. These six areas must be covered in every NIS2-compliant ISMS.

Risk Analysis

Systematic identification, assessment and treatment of risks to your services and IT systems.

Incident Management

Detection, reporting and response processes for significant security incidents under § 32 BSIG.

Business Continuity

Backup concepts, contingency plans and crisis management to maintain service delivery.

Supply Chain Security

Security requirements for external service providers and suppliers, anchored contractually.

Training

Demonstrable training of executive management (§ 38) and security awareness for all employees.

Documentation & Evidence

Audit-ready records for regulators — available at any time, not just in an emergency.

Frequently Asked Questions

ISMS and NIS2 — What Companies Really Want to Know

Do I have to have my ISMS certified to ISO 27001?
NIS2 does not require ISO 27001 certification. However, it can serve as evidence for the BSI and reduce audit effort. For companies that are already certified, or that operate in industries where certification is expected, the effort is worthwhile. For everyone else, a documented, functioning ISMS is sufficient.
How long does it take to build an NIS2-compliant ISMS?
This depends on the starting point and company size: 3–6 months for a structured basic build with external support, 12–18 months to full maturity including lived processes. The key is to start quickly with quick wins rather than waiting for perfection.
Who is internally responsible for the ISMS?
Under § 38 BSIG, ultimate responsibility lies with executive management. Operational management is handled by a CISO or information security officer — internal or as an external service. Important: executive management can delegate tasks, but not the responsibility.
Related Topics

Further NIS2 Topics

Build Your ISMS With Experienced Guidance

Whether starting from scratch or expanding an existing system — we guide you from the gap analysis to an audit-ready ISMS.

Request Consultation Now
Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com