An Edge Built on Knowledge and Experience
NIS2 / BSIG § 30 (2)

NIS2 Policies, Processes and Documentation

Technical protective measures alone are not enough for NIS2 compliance. We explain which policies and documents are mandatory.

Technical & Legal Expertise Experience From Numerous NIS2 Projects Based in Sindelfingen
Organisational Foundation

Why Technical Measures Alone Are Not Enough

Firewalls, encryption and monitoring are necessary — but not sufficient. § 30 BSIG explicitly requires an organisational foundation: documented policies, clear responsibilities, and traceable processes that can be presented in an incident or during a regulatory review.

Important: NIS2 compliance is not an IT topic that can be delegated to the IT department. Risk management and security responsibility must be anchored at the executive management level.

§ 30 (2) BSIG

Overview of the Mandatory Documents

These policies must be maintained, put into practice, and documented under NIS2. Missing or unused documents are a direct compliance risk during a regulatory review.

Information Security Policy

The overarching document. Defines objectives, principles and scope of information security — the basis for all individual policies.

Risk Management Policy

How risks are identified, assessed and prioritised. Which measures must be taken at which risk level.

Incident Response Policy

Escalation paths, reporting obligations to the BSI, internal communication chains during security incidents.

Business Continuity Policy

Backup measures, recovery objectives (RTO/RPO), crisis management and emergency communication.

Supply Chain Policy

Requirements for service providers and suppliers, review processes, contract templates with cybersecurity clauses.

Access and Identity Policy

Rules on user rights, role concepts, multi-factor authentication, and password standards.

Duty of Evidence

What Documentation Really Means Under NIS2

Documentation is not bureaucracy for its own sake — it is the evidence that your security organisation actually works. The BSI can request evidence at any time, without a concrete incident having occurred.

Related Topics

Further NIS2 Topics

Develop Policies That Actually Hold Up

We create or review your mandatory NIS2 documents — practical, audit-ready, and tailored to your organisation.

Request Consultation Now
Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com