NIS2 in practice
The responsibility is there. The path to fulfilling it doesn't have to be complicated.
As of December 6, 2025 , the NIS2 Implementation Act has been in effect – without a transition period. It covers approximately 29,500 companies across 18 sectors, ranging from energy and healthcare to logistics, food, and manufacturing.
Any company with 50 employees or annual revenue and total assets exceeding 10 million euros may already be affected. This applies to many small and medium-sized enterprises that have never considered themselves critical infrastructure.
The requirements are comprehensive: state-of-the-art risk management , reporting of significant security incidents within 24 hours , tested emergency response plans , and a secure supply chain . Responsibility lies with senior management.
Violations can result in fines of up to 10 million euros or 2 percent of global annual revenue.
Many companies are therefore faced with the same question: Where do we start?
Our answer is clarity over hasty action. Because NIS2 is not an IT project that you can simply check off your list, but rather an ongoing task involving organization, processes and technology.
That’s why we combine consulting with operations. For decades, we have been operating security-critical infrastructures in our data centers in Hanover—for banks, insurance companies, public sector clients, and KRITIS operators.
So we not only know what NIS2 requires, but also how it works in everyday practice. The result: measures that are tailored to your company, pass audits, and hold up in an emergency.
Background
"Yes, we're affected—so what now?"
NIS2 has been in effect since December 6, 2025. The registration deadline was March 6, 2026, and the BSI’s grace period ended on July 31, 2026. The requirements have been fully in effect since then.
You're not alone in this: By the end of May 2026, only about 18,500 of the estimated 29,500 affected companies had registered. Registration with the BSI is still possible—and strongly recommended.
Legislation and guidelines are only of limited help. What really matters is what NIS2 specifically means for your organization, your processes, and your IT.
She must approve measures, monitor their implementation, and undergo regular training. Waiting only postpones the risk; it does not eliminate it.
With the NIS2 Check, you can get an initial assessment in just a few minutes. Everything else builds on that.
Your NIS2 Strategy
First clarity, then action
Those who purchase security solutions under time pressure often invest in the wrong areas. A clear process is more effective: Assess the impact, determine the maturity level, prioritize gaps —and only then implement targeted solutions.
This ensures your budget goes where it actually reduces risks.
Our data centers in Hanover are certified to ISO 27001, 27017, and 27018 and are NIS2 Ready—we put into practice every day what we recommend to you.
Getting Started
Your Path to NIS2 Implementation — Tailored to Your Needs
NIS2 Check
Find out in just a few steps whether and how your company is affected.
Initial Consultation
We'll review your results and discuss the next steps.
Assessment of the Current Situation
We assess your level of readiness in the key NIS2 action areas.
Gap Assessment
We assess vulnerabilities based on risk and effort and prioritize actions.
Implementation
From the data center to IT operations—documented in a manner that meets audit requirements.
Contact
Does NIS2 affect you? Let's talk
Let's take your next steps toward NIS2 together.
Direct Line
GRASS-MERKUR GmbH & Co. KG
Rothwiese 5
30559 Hannover