With our NIS2 Check, companies can quickly assess whether they are affected by the new legal requirements. The implementation of the NIS2 Directive is one of the most important regulatory developments in cybersecurity. Many companies are currently grappling with the question of whether they will be subject to the requirements of the BSI Act in the future and what obligations will arise from it. The biggest challenge often lies not in implementing individual measures, but in correctly assessing their own applicability.
This is precisely where the free NIS2 Check from Scheja & Partners comes in. Within a few minutes, companies receive initial guidance on whether they are likely to fall within the scope of the new regulations.
What is NIS2?
With the NIS2 Directive, the European Union has significantly expanded cybersecurity requirements. The goal is to strengthen the resilience of critical and important entities against cyberattacks and IT security incidents.
Compared to the previous legal situation, significantly more companies will be affected by regulatory requirements in the future. In addition to traditional operators of critical infrastructures, numerous other sectors and organizations are coming into focus.
These include, for example, companies from the following sectors:
- Energy
- Healthcare
- Transport and Logistics
- Digital Infrastructure
- Financial Services
- Water and Waste Management
- Manufacturing and Industry
- Digital Services and IT Services
In addition, employee numbers, revenues, and other legal criteria play an important role in classification.
Why the applicability assessment is so important
In practice, many companies find it difficult to assess their own situation. The legal regulations contain numerous definitions, exceptions, and thresholds.
Anyone who mistakenly assumes they are not affected risks overlooking legal obligations. Conversely, some companies invest considerable resources in preparatory measures, even though the requirements may not even apply to them.
A structured applicability assessment should therefore always be the first step in any NIS2 strategy.
The free NIS2 Check from Scheja & Partners
With our free NIS2 Check, companies can quickly and easily get an initial assessment.
Based on targeted questions, the essential criteria of the NIS2 regulations and the BSI Act are taken into account. The check helps to better classify one’s own situation and to identify potential need for action early on.
The NIS2 Check is particularly suitable for:
- Management Boards
- Compliance Officers
- Data Protection Officers
- Information Security Officers
- IT Management
- Legal Departments
What obligations can affected companies expect?
Companies falling under the NIS2 regulations must regularly expect extensive requirements. These include, in particular:
- Establishment of appropriate cybersecurity measures
- Conducting risk analyses
- Documentation of security measures
- Introduction of reporting processes for security incidents
- Governance and control structures
- Training and awareness for employees
- Extended responsibility of Management Boards
However, the specific requirements depend on the respective classification and the particularities of the company.
NIS2 as a Management Task
A key difference from previous regulation is that cybersecurity is increasingly understood as a management and governance issue. Management Boards will have to deal more intensively with risks, responsibilities, and organizational security measures in the future.
Therefore, NIS2 implementation should not be viewed exclusively as an IT project. Rather, legal, organizational, and technical aspects must be evaluated jointly.
Support from Scheja & Partners
Scheja & Partners advises companies, public institutions, and international organizations on NIS2 and regulatory compliance. We are happy to assist you with legal classification and practical implementation. You can contact us directly via our contact page.
Our consulting services include, in particular:
- Applicability analyses
- NIS2 and BSI Act consulting
- Governance and compliance frameworks
- Management and organizational obligations
- Documentation and Verification Processes
- Training and awareness measures
Further information on NIS2 can be found here.