Two men are sitting in a conference room, reviewing documents.

NIS2 Assessment for Businesses

Is your organization affected by NIS2? Here's how to get started with implementation.

The deadlines have passed; the obligations are now in effect. Four steps from assessment to robust implementation—with a partner that operates security-critical IT systems itself.

NIS2 in practice

The responsibility is there. The path to fulfilling it doesn't have to be complicated.

As of December 6, 2025 , the NIS2 Implementation Act has been in effect – without a transition period. It covers approximately 29,500 companies across 18 sectors, ranging from energy and healthcare to logistics, food, and manufacturing.

Any company with 50 employees or annual revenue and total assets exceeding 10 million euros may already be affected. This applies to many small and medium-sized enterprises that have never considered themselves critical infrastructure.
The requirements are comprehensive: state-of-the-art risk management , reporting of significant security incidents within 24 hours , tested emergency response plans , and a secure supply chain . Responsibility lies with senior management.

Violations can result in fines of up to 10 million euros or 2 percent of global annual revenue.

Many companies are therefore faced with the same question: Where do we start?

Our answer is clarity over hasty action. Because NIS2 is not an IT project that you can simply check off your list, but rather an ongoing task involving organization, processes and technology.

That’s why we combine consulting with operations. For decades, we have been operating security-critical infrastructures in our data centers in Hanover—for banks, insurance companies, public sector clients, and KRITIS operators.

So we not only know what NIS2 requires, but also how it works in everyday practice. The result: measures that are tailored to your company, pass audits, and hold up in an emergency.

A man sitting in front of a laptop.

Background

"Yes, we're affected—so what now?"

01 The deadlines have passed

NIS2 has been in effect since December 6, 2025. The registration deadline was March 6, 2026, and the BSI’s grace period ended on July 31, 2026. The requirements have been fully in effect since then.

02 Registration is still open

You're not alone in this: By the end of May 2026, only about 18,500 of the estimated 29,500 affected companies had registered. Registration with the BSI is still possible—and strongly recommended.

03 It is unclear exactly what needs to be done

Legislation and guidelines are only of limited help. What really matters is what NIS2 specifically means for your organization, your processes, and your IT.

04 Management bears responsibility

She must approve measures, monitor their implementation, and undergo regular training. Waiting only postpones the risk; it does not eliminate it.

05 The next step is a small one

With the NIS2 Check, you can get an initial assessment in just a few minutes. Everything else builds on that.

Georg Ahlbrand, Holger Sievers, and Jens Ahlbrand in conversation.

From duty to a lead

We'll turn NIS2 into your competitive advantage

Those who implement NIS2 strategically gain more than just compliance: more robust processes, greater customer trust, and better opportunities in competitive bidding.

Here's what you can achieve with us:

  • Certified Data Centers in Hanover – TIER 3+ and Geographically Redundant
  • Consulting and Operations from a Single Source
  • Verifiable security for audits, customers, and bids
  • Measures Taken with a Sense of Proportion Rather Than Over-the-Top Compliance
  • Your data remains in Germany

Your NIS2 Strategy

First clarity, then action

Those who purchase security solutions under time pressure often invest in the wrong areas. A clear process is more effective: Assess the impact, determine the maturity level, prioritize gaps —and only then implement targeted solutions.

This ensures your budget goes where it actually reduces risks.

Our data centers in Hanover are certified to ISO 27001, 27017, and 27018 and are NIS2 Ready—we put into practice every day what we recommend to you.

Georg and Jens Ahlbrand at the meeting.

Getting Started

Your Path to NIS2 Implementation — Tailored to Your Needs

NIS2 Check

Find out in just a few steps whether and how your company is affected.

Initial Consultation

We'll review your results and discuss the next steps.

Assessment of the Current Situation

We assess your level of readiness in the key NIS2 action areas.

Gap Assessment

We assess vulnerabilities based on risk and effort and prioritize actions.

Implementation

From the data center to IT operations—documented in a manner that meets audit requirements.

Dr. Oliver Kunert in a consulting meeting.

From maturity to implementation

Gaps Turn into Actions

These include:

  • Assessment: Ten key questions—ranging from ISMS and risk analysis to incident response, backup, and monitoring, all the way to the supply chain and the role of senior management.
  • Gap Assessment: We compare your current status with the NIS2 requirements and evaluate each gap based on risk and effort.
  • Action Plan: You receive clear priorities, responsibilities, and a realistic timeline.
  • Implementation & Verification: We implement measures in the data center, cloud, network, backup, and security monitoring systems and document them in an audit-ready format.

Contact

Does NIS2 affect you? Let's talk

Let's take your next steps toward NIS2 together.

Direct Line

GRASS-MERKUR GmbH & Co. KG
Rothwiese 5
30559 Hannover

Our sales team will advise you personally — by phone or on site.
Your GRASS-MERKUR contact: Markus Dietz - Head of Business Development & Sales

Markus Dietz

Head of Business Development & Sales