CLARITY BEFORE ACTION
Know Where You Stand — Before You Act
Not every company is affected to the same extent by the NIS2 Directive or the KRITIS requirements. At the same time, many organizations underestimate their regulatory obligations or overestimate the actual need for action—both of which lead to misplaced priorities and unnecessary effort.
While previous KRITIS regulations were primarily aimed at operators of critical infrastructure, NIS2 significantly expands the scope of affected companies. Depending on the industry, company size, and importance of the services provided, significantly more organizations may fall under the legal requirements in the future.
Through a structured NIS2 impact analysis, we provide clarity on your current status and identify which cybersecurity and risk management requirements are already met and where specific action is needed.
Even companies that are not directly subject to the NIS2 Directive may be indirectly affected through customers, suppliers, or regulatory requirements imposed by their clients. An early assessment provides planning certainty and minimizes risks.
Our Approach
How We Support You
GRASS-MERKUR does not view NIS2 and KRITIS compliance as a one-time project, but rather as an ongoing process to strengthen your cyber resilience. Together, we assess your exposure, analyze existing security measures, and identify areas where regulatory action is needed.
Based on this, we develop a prioritized action plan that meets legal requirements while also aligning with your organization and budget.
Your Benefits
- Clarity on NIS2 and KRITIS reporting requirements and deadlines
- A structured impact assessment for your organization
- Prioritized measures based on cost-benefit analysis
- Preparation for audits and compliance documentation requirements
- A standardized documentation framework for government agencies and regulatory authorities
- Implementation support rather than merely preparing expert reports
Our Framework Model
Our NIS2 Readiness Assessment & GAP Analysis
These include:
- Scope assessment
We assess whether and to what extent NIS2 applies to your company. - Governance & responsibilities
We define clear responsibilities and involve senior management in the implementation. - Risk & supply chain management
We identify cyber risks and assess the security of service providers and partners. - Business continuity
We prepare you for security incidents, operational disruptions and crisis situations.
Get Started Now
NIS2 Compliance Starts with the Right Strategy
Technologies change. Regulatory requirements change. Anyone looking to future-proof their IT organization needs more than a one-off audit — they need a continuous process for strengthening cyber resilience.
GRASS-MERKUR helps you make the right decisions for a secure and regulatory-compliant IT organization.
Contact
Request NIS2 Consulting Services
Tell us about your project — we will get back to you with a concrete assessment.
Direct Line
GRASS-MERKUR GmbH & Co. KG
Rothwiese 5
30559 Hannover