European flag with icons related to regulation and safety.

NIS2 & KRITIS

Are You Affected? The Most Important Question First.

With NIS2, the requirements for cybersecurity, risk management and management accountability are rising considerably. We help you clarify whether you are affected — and which concrete steps are needed now.

CLARITY BEFORE ACTION

Know Where You Stand — Before You Act

Not every company is affected to the same extent by the NIS2 Directive or the KRITIS requirements. At the same time, many organizations underestimate their regulatory obligations or overestimate the actual need for action—both of which lead to misplaced priorities and unnecessary effort.

While previous KRITIS regulations were primarily aimed at operators of critical infrastructure, NIS2 significantly expands the scope of affected companies. Depending on the industry, company size, and importance of the services provided, significantly more organizations may fall under the legal requirements in the future.

Through a structured NIS2 impact analysis, we provide clarity on your current status and identify which cybersecurity and risk management requirements are already met and where specific action is needed.

Even companies that are not directly subject to the NIS2 Directive may be indirectly affected through customers, suppliers, or regulatory requirements imposed by their clients. An early assessment provides planning certainty and minimizes risks.

Our Approach

How We Support You

GRASS-MERKUR does not view NIS2 and KRITIS compliance as a one-time project, but rather as an ongoing process to strengthen your cyber resilience. Together, we assess your exposure, analyze existing security measures, and identify areas where regulatory action is needed.

Based on this, we develop a prioritized action plan that meets legal requirements while also aligning with your organization and budget.

Your Benefits

  • Clarity on NIS2 and KRITIS reporting requirements and deadlines
  • A structured impact assessment for your organization
  • Prioritized measures based on cost-benefit analysis
  • Preparation for audits and compliance documentation requirements
  • A standardized documentation framework for government agencies and regulatory authorities
  • Implementation support rather than merely preparing expert reports

Our Framework Model

Our NIS2 Readiness Assessment & GAP Analysis

These include:

  • Scope assessment
    We assess whether and to what extent NIS2 applies to your company.
  • Governance & responsibilities
    We define clear responsibilities and involve senior management in the implementation.
  • Risk & supply chain management
    We identify cyber risks and assess the security of service providers and partners.
  • Business continuity
    We prepare you for security incidents, operational disruptions and crisis situations.
GRASS-MERKUR Employees
Jens and Georg Ahlbrand

Target Audiences

Who NIS2 and KRITIS Are Particularly Relevant For

This is particularly relevant for industries such as:

  • Energy utilities
  • Healthcare
  • Industrial companies
  • Transport and logistics
  • Digital services
  • Public institutions
  • IT and technology companies
  • Operators of critical supply chains

Get Started Now

NIS2 Compliance Starts with the Right Strategy

Technologies change. Regulatory requirements change. Anyone looking to future-proof their IT organization needs more than a one-off audit — they need a continuous process for strengthening cyber resilience.

GRASS-MERKUR helps you make the right decisions for a secure and regulatory-compliant IT organization.

Georg and Jens Ahlbrand in a personal conversation.

Contact

Request NIS2 Consulting Services

Tell us about your project — we will get back to you with a concrete assessment.

Direct Line

GRASS-MERKUR GmbH & Co. KG
Rothwiese 5
30559 Hannover

Your contact will advise you personally — by phone or on site.
Your GRASS-MERKUR contact: Markus Dietz - Head of Business Development & Sales

Markus Dietz

Head of Business Development & Sales