Technical protective measures alone are not enough for NIS2 compliance. We explain which policies and documents are mandatory.
Firewalls, encryption and monitoring are necessary — but not sufficient. § 30 BSIG explicitly requires an organisational foundation: documented policies, clear responsibilities, and traceable processes that can be presented in an incident or during a regulatory review.
Important: NIS2 compliance is not an IT topic that can be delegated to the IT department. Risk management and security responsibility must be anchored at the executive management level.
These policies must be maintained, put into practice, and documented under NIS2. Missing or unused documents are a direct compliance risk during a regulatory review.
The overarching document. Defines objectives, principles and scope of information security — the basis for all individual policies.
How risks are identified, assessed and prioritised. Which measures must be taken at which risk level.
Escalation paths, reporting obligations to the BSI, internal communication chains during security incidents.
Backup measures, recovery objectives (RTO/RPO), crisis management and emergency communication.
Requirements for service providers and suppliers, review processes, contract templates with cybersecurity clauses.
Rules on user rights, role concepts, multi-factor authentication, and password standards.
Documentation is not bureaucracy for its own sake — it is the evidence that your security organisation actually works. The BSI can request evidence at any time, without a concrete incident having occurred.
We create or review your mandatory NIS2 documents — practical, audit-ready, and tailored to your organisation.
Request Consultation Now