Eyes looking at data
Understand Your NIS2 Readiness and Strengthen Compliance Confidence

NIS2 Compliance Assessments

NIS2 imposes higher cybersecurity and accountability requirements on many organizations. The challenge is not only to implement these measures, but also to understand where action is needed and how to demonstrate readiness. Unclear responsibilities, supplier dependencies, operational risks, and sector-specific requirements can complicate preparation. DEKRA offers NIS2 compliance assessments to help you identify gaps, evaluate readiness, and define a clearer path toward compliance.
Your Benefits
Compliance Readiness:

Identify and address compliance gaps before they create regulatory or operational risks.

Risk Transparency:

Gain clarity on risks, responsibilities and dependencies across your supply chain.

Process Confidence:

Understand how well risk management, incident response and reporting processes support NIS2 requirements.

Stakeholder Trust:

Demonstrate proactive compliance while strengthening credibility and reducing legal, financial and reputational risks.

Structured Assessments for Cybersecurity Compliance

The NIS2 Directive introduces stricter cybersecurity requirements for organizations in critical and regulated sectors. It requires a more systematic approach to cybersecurity risk management, incident reporting, supply chain security, and operational resilience. The first challenge for many organizations is understanding which requirements are relevant, identifying where gaps exist, and structuring their preparation.
With our NIS2 Compliance Assessments, you will receive a thorough review of your current cybersecurity setup. Our experts will assess your existing processes, responsibilities, and security measures against the relevant NIS2 requirements. Depending on your organization's context and service scope, this may also include testing and certification services for OT IEC 62443 standards. The result helps identify compliance gaps, clarify improvement areas, and support the structured implementation of NIS2-related measures.
FAQ`s: NIS2 Directive
Large and medium-sized organizations in critical and regulated sectors, as well as public authorities, must comply. Indirectly, companies that are part of a NIS2-relevant supply chain are also affected.
NIS2 mainly applies to public and private entities in Annex I and Annex II sectors that are at least medium-sized, normally 50 or more employees and annual turnover and/or a balance-sheet total above €10 million; certain entity types are in scope regardless of size. Suppliers are not automatically subject to NIS2 solely because of a customer relationship, but in-scope entities must manage supply-chain risk and may impose security requirements by contract.
NIS2 calls them “sectors of high criticality”:
  • Energy: Electricity, district heating, petroleum/crude oil, natural gas, and hydrogen
  • Transport: Air, rail, road, and water transport
  • Banking: Credit institutions
  • Financial Market Infrastructure: Trading venues and central counterparties
  • Health: Hospitals, medical laboratories, pharmaceutical research, and manufacturing of medical devices
  • Drinking Water: Water supply and distribution
  • Waste Water: Wastewater collection and treatment
  • Digital Infrastructure: Cloud providers, data centers, DNS service providers, TLD registries, and telecommunications networks
  • ICT Service Management: Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs)
  • Public Administration: Central government and regional authorities
  • Space: Operators of ground-based infrastructure supporting space services
Annex I defines the entity types covered in each sector; Annex II also covers other critical sectors, including postal and courier services, waste, chemicals, food, certain manufacturing, digital providers and research.
Classification depends on the entity type; sector and size, not simply on whether a sector is “essential.” Essential entities include qualifying Annex I entities and certain named types regardless of size; other in-scope entities are important entities.
Essential entities face proactive supervision, while important entities are generally supervised after evidence of non-compliance. National implementing law should be checked for the final classification.
Entities must implement proportionate cybersecurity risk-management measures, including risk analysis, incident handling, business continuity, supply-chain security, secure system development and maintenance, effectiveness testing, training, access control and, where appropriate, encryption and multi-factor authentication. Management bodies must approve and oversee these measures and undertake cybersecurity training.
Significant incidents must be reported in stages: an early warning within 24 hours, incident notification within 72 hours and a final report generally within one month.
Member States must provide for maximum fines of at least €10 million or 2% of worldwide annual turnover, whichever is higher for essential entities, and €7 million or 1.4% for important entities. Other measures can include binding instructions, audits and remediation orders.
Management bodies must approve and oversee cybersecurity measures and may be held liable under national law for failures in those duties.The exact sanctions and liability rules depend on national implementation.
NIS2 entered into force at EU level on 16 January 2023, and Member States were required to transpose it by 17 October 2024. Germany did not meet that deadline. Its implementation legislation entered into force in December 2025.
Yes, for specified providers that offer services in the EU, including certain DNS, cloud, data-centre, content-delivery, managed-service, marketplace, search-engine and social-network providers. Where required, a non-EU provider must designate an EU representative.
A third-party supplier is not automatically in scope merely because it serves an EU customer, but it may face contractual cybersecurity requirements due to the customer’s supply-chain obligations.
The GDPR regulates personal-data processing and protection, while NIS2 requires cybersecurity risk management and incident resilience for entities in scope. A cyber incident may trigger duties under both regimes, but their scope, reporting tests, deadlines and authorities differ.
NIS2 reporting does not replace GDPR obligations, and GDPR compliance alone does not demonstrate NIS2 compliance.
Yes. The Commission must review NIS2 by 17 October 2027 and at least every 36 months thereafter and may adopt or update implementing rules for defined areas.
Companies should monitor EU and national measures, competent-authority guidance and sector-specific rules. Commission Implementing Regulation (EU) 2024/2690 already sets detailed requirements for certain digital entities.
Definitely! DEKRA supports organizations globally with cybersecurity assessments, testing, training and compliance-oriented services. For multinational organizations, DEKRA can help assess NIS2-related cybersecurity requirements alongside applicable local and sector-specific obligations.
Why DEKRA?
  • Independent cybersecurity expertise: We provide objective evaluations that help you understand your NIS2 readiness, identify gaps and define clear priorities.
  • Integrated cybersecurity and testing competence : Our experts connect NIS2 requirements with operational cybersecurity challenges, including risk management, incident response, supply chain security and OT IEC 62443 related testing and certification services.
  • Confidence for next steps: We help you turn assessment results into a clearer path toward implementation readiness, stronger governance and reduced exposure.
People with Laptop
Whitepaper: Build a Strategic Approach to NIS2 Compliance
Discover who must comply with NIS2, its key requirements, common gaps, relevant standards, and practical preparation steps.
Share page :