NIS2 & compliance

From an initial scope assessment to a practical action plan.

TM-Connect helps organisations structure their potential NIS2 relevance, clarify responsibilities and prepare the next organisational and technical steps.

Current position

NIS2 has been implemented in German law.

The German NIS2 implementation act entered into force on 6 December 2025. The revised BSI Act distinguishes particularly important and important entities and links classification to factors such as sector, activity, size and special rules.

Assessment

Headcount is not the only factor

Sector, specific activity, entity type and group or special rules all influence the assessment.

  • Sector and activity
  • Size thresholds
  • Special and exemption rules
Duties

Organisation and technology work together

Risk management, reporting, registration, supply chain, training and documentation need to be considered as one system.

  • Risk-management measures
  • Reporting and registration processes
  • Documented responsibilities
Management

Management bodies are explicitly involved

The BSI Act assigns implementation, monitoring and training duties to management. Qualified legal advice remains necessary for individual legal assessment.

  • Direction
  • Monitoring
  • Regular training

Scope orientation

Six questions for an initial scope assessment

These questions create a structured basis for discussion. They do not produce an automatic legal determination.

  1. Which sector does your organisation operate in?

    Review the sectors and entity types in Annexes 1 and 2 of the BSI Act as well as possible special categories.

  2. Which specific activity or service do you provide?

    The legally defined activity, not just the industry label, is relevant to classification.

  3. Which size thresholds are reached?

    Employee numbers, annual turnover and balance-sheet totals are combined differently depending on the entity type.

  4. Are there partner or linked enterprises?

    Group aggregation follows specific rules and may require individual assessment.

  5. Do sector-specific rules or exemptions apply?

    Telecommunications, trust services, public administration and DORA-related entities may be treated differently.

  6. What is your role in critical supply chains?

    Even organisations outside the formal scope may receive security, evidence and incident-communication requirements from customers.

This orientation does not replace individual legal review. A reliable classification requires the current legal text, the specific activity and the organisational structure to be assessed together.

Organisation

What organisations should prepare

NIS2 is not a single IT product. It requires a traceable combination of governance, processes, technology and documentation.

Governance and responsibilities

Define decision paths, roles, escalation and reporting lines.

Risk management

Identify, assess and treat risks to network and information systems systematically.

Technical and organisational measures

Plan safeguards proportionate to risk, size, state of the art and implementation effort.

Reporting and incident management

Prepare detection, internal escalation, external reporting, recovery and crisis communication.

Supply-chain security

Document dependencies, providers and security requirements across the supply chain.

Documentation and training

Keep decisions, measures, effectiveness checks and regular training auditable.

Continuous improvement

Establish security as a reviewable operating process rather than a one-off project.

Approach

An approach that makes decisions and outcomes visible

Every phase clarifies who is involved, what happens and which result supports the next decision.

Scope and initial assessment

The organisation, activities, sites and open classification questions are bounded.

Participants
Management, compliance, IT and legal counsel where required
Outcome
Documented scope and a list of open legal questions
Your benefit
Clarity on what is being assessed and which expertise is still needed

Current-state review

Systems, services, responsibilities, providers and existing security processes are captured.

Participants
IT, information security, business functions and procurement
Outcome
A landscape of systems, roles, dependencies and existing evidence
Your benefit
One shared fact base instead of fragmented information

Gap and risk analysis

The documented current state is compared with relevant requirements and risks.

Participants
IT, information security, compliance and affected functions
Outcome
Prioritised gaps, risks and clarification needs
Your benefit
Urgency becomes traceable rather than generic

Measures roadmap

Organisational and technical measures are ordered by impact, urgency, dependency and effort.

Participants
Decision-makers, IT, procurement and project owners
Outcome
An agreed roadmap with owners and decision points
Your benefit
Investment and internal capacity become easier to plan

Coordinate implementation

Internal teams, specialist providers and suitable security and connectivity solutions are coordinated.

Participants
Project lead, IT, providers and vendors
Outcome
Coordinated work packages with documented progress
Your benefit
Less friction across organisation, technology and suppliers

Evidence, operations and improvement

Evidence, effectiveness checks, training, reporting paths and recurring reviews move into operations.

Participants
Management, information security, IT and process owners
Outcome
A maintainable evidence and improvement process
Your benefit
The achieved state remains reviewable and can evolve

TM-Connect

How TM-Connect can support you

The service framework connects orientation, project structure and technical infrastructure. Legal advice and compliance guarantees are expressly excluded.

Orientation

Structure the current situation and action areas

We bring systems, responsibilities, dependencies and open questions into one shared landscape.

Project

Coordinate measures and participants

We structure work packages, support the selection of suitable solutions and coordinate implementation partners.

Infrastructure

Connect security and connectivity

Network security, endpoints, sites, resilience and communications are treated as connected infrastructure topics.

Support

From first discussion to development path

We support decisions, implementation and subsequent development steps in a personal and understandable way.

Solution fields

Technical fields for the measures roadmap

Suitable solutions depend on risk, existing infrastructure, the operating model and the confirmed service scope. No single product creates NIS2 compliance.

Network security and firewalls

Assess access, segmentation, traffic and safeguards in the context of the infrastructure.

Endpoint and mobile security

Include devices, identities, patching and secure mobile use in the protection model.

SD-WAN and site networking

Connect distributed sites securely, controllably and with transparent dependencies.

Backup and recovery

Plan backups, restoration, redundancy and emergency procedures as one process.

Cloud and Microsoft 365 security

Review identities, permissions, configuration, data and recovery systematically.

Managed security

Select operating and monitoring models only after availability and scope have been confirmed.

Governance

Management: make responsibility governable

Section 38 of the German BSI Act requires management bodies of particularly important and important entities to implement and monitor risk-management measures; regular training is also required. The individual legal effect needs qualified legal assessment. In practice, management needs reliable reporting, documented decisions and a clear view of material risks and measures.

Sectors

Typical starting points by sector

Healthcare

Care delivery, telematics and sensitive data

Healthcare organisations need to consider regulatory, technical and operational dependencies together.

Care

Distributed operations and limited resources

Multiple facilities, mobile work and providers require clear ownership and practical reporting and recovery paths.

Mid-market

Evolved systems and many interfaces

The first task is often to make responsibilities, suppliers and priority risks visible across sites.

Housing

Sites, providers and digital processes

Administration, technical infrastructure and external partners form a delivery chain with different protection needs.

Critical supply chains

High expectations for resilience and evidence

Even outside formal classification, customers or sponsors may expect robust security evidence.

Trust

Personal support with established telecommunications experience

TM-Connect combines security and compliance orientation with experience in telecommunications and digital infrastructure. Vendor relationships are stated factually while TM-Connect remains clearly identifiable as an independent consulting and implementation company.

  • Vodafone Business Partner for 17 years
  • Telekom Partner
  • 1&1 Versatel Partner

These approved statements describe partner relationships. They do not imply exclusivity, certification, a mandate or a compliance guarantee.

Questions & answers

Frequently asked questions about NIS2 and next steps

Is my organisation automatically in scope?

No. Classification depends on entity type, activity, sector, size and special or group rules. Individual review remains necessary.

When did the German NIS2 rules enter into force?

The German NIS2 implementation act entered into force on 6 December 2025. Decisions should always use the current legal text.

What are particularly important and important entities?

The BSI Act classifies entities through statutory categories and thresholds, which lead to different supervisory and sanction frameworks.

Which size thresholds matter?

Depending on the category, employee numbers, annual turnover and balance-sheet totals are considered. Some entity types are covered independently or under different thresholds.

Which measures does the BSI Act require?

Section 30 lists proportionate technical and organisational risk-management measures, including risk analysis, incident handling, continuity, supply-chain security, effectiveness review, training, cryptography and access security.

Which reporting deadlines apply?

Section 32 generally provides for an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. Details and the start of the obligation need current review.

Do entities need to register?

In-scope entities have registration duties. The BSI provides its portal for this purpose; deadlines and special routes depend on entity type.

What is management's role?

The BSI Act assigns implementation, monitoring and training duties to management. Individual liability and legal effects require legal advice.

Does a firewall make an organisation compliant?

No. NIS2 covers governance, processes, people, supply chains, documentation and technology. Individual products can only be elements of a proportionate measures package.

Does TM-Connect provide legal advice?

No. TM-Connect supports orientation, project structure, technical assessment and implementation. Legal classification and legal questions require qualified counsel.

What is a sensible first step?

A scoped initial discussion covering activity, size, sites, systems, responsibilities and open questions provides a practical basis for further assessment.

Related solutions

Initial consultation

Discuss your NIS2 action needs in a structured way.

In the initial consultation we clarify your situation, open classification questions and the most useful next work step. The consultation is not legal advice.