Fortifying Critical Infrastructure Security

NIS2 Directive - Your Path to Increased Resilience.

Our services

Risk Management and Threat modelling

Our Risk Management and Threat Modeling service identifies potential threats to your critical infrastructure and evaluates vulnerabilities. We develop strategic plans to mitigate these risks, ensuring your operations are safeguarded against current and emerging cyber threats.

Compliancy audit and Certification

We specialize in Compliance Audits and Certification to ensure your critical infrastructure meets all relevant regulatory requirements. Our thorough audits prepare you for certifications, demonstrating your commitment to cybersecurity excellence and regulatory adherence.

Cybersecurity Concept

Our Cybersecurity Concept service offers a strategic framework tailored to protect your critical infrastructure. We design comprehensive security strategies that align with your organizational objectives, enhancing your overall cybersecurity posture.

Integration & implementation

Integration & Implementation services are critical for embedding cybersecurity measures into your existing infrastructure. We ensure seamless incorporation of security strategies, enhancing protection without disrupting operational efficiency.

Our certifications

Certified to support organizations in effectively planning, implementing, managing, monitoring, and maintaining a cybersecurity program

Safeguarding the Foundations of Society

The NIS2 Directive: A New Era of Cybersecurity Begins. From 2023, the European Union sets new standards with the NIS2 Directive to ensure the security of network and information systems. Learn what this means for your business in Germany and how to prepare.

Download the white paper on the NIS2 directive now

Your data will only be used for the purpose of contacting you. And are subject to our privacy policy.

Thank you! Click the download button below.
download whitepaper
Oops! Something went wrong while submitting the form.

Problem

Challenges of the NIS2 Directive: Understand the Risks and Consequences of Non-Compliance. Our expertise shows you the potential dangers that could affect your business and how to effectively protect yourself.

solution

Our Solutions for Your NIS2 Compliance: From impact analysis to establishing an effective incident reporting system - we offer comprehensive services to prepare your business for compliance with the NIS2 Directive and ensure business continuity.

Trusted by Industry Leaders

"Partnering with NORDCS GmbH revolutionized our cybersecurity approach. Their expertise in automotive standards like ISO21434 and TISAX has been invaluable. Highly recommend their team for any cybersecurity needs."

Alex Johnson

CTO, AutoTech Innovations

"NORDCS GmbH's risk management strategies and compliance audits have fortified our critical infrastructure against threats. Their attention to detail and proactive measures are unmatched."

Sam Lee

CEO, GridSecure Solutions

"The cybersecurity engineering services from NORDCS GmbH, including TARA and cybersecurity concept development, have significantly enhanced our product security. Their team is knowledgeable and responsive."

Michael Chen

Product Manager, InfraTech

FAQ on the NIS2 requirements

What is the NIS2 Directive?

The new European Cybersecurity Directive NIS 2 will come into force on 16 January 2023. NIS 2 stands for "Second Directive concerning measures to ensure a high common level of security of network and information systems across the Union". As part of the European Cyber Security Strategy, the NIS Directive aims to strengthen the resilience of critical infrastructure. Operators of critical infrastructure (or KRITIS for short) are now required to meet minimum standards and take proactive measures to minimise risk.

When will the NIS2 directive be implemented in Germany?

NIS 1 has been implemented in Germany through the IT Security Act and the BSI-Act, which cover critical infrastructure. The NIS 2 Directive has yet to be transposed into national law and has an implementation deadline of 17 October 2024. The NIS 2 Implementation and Cyber Security Strengthening Act (NIS2UmsuCG) is expected to be promulgated in March 2024 and come into force in October 2024.

What sectors are affected by NIS2?

Businesses subject to the Civil Protection Regulations, and therefore the NIS2 Directive, are required to comply with information security, risk management and cyber security requirements. This includes regular penetration testing, setting up cyber incident reporting systems and conducting a risk assessment to identify potential IT security threats within the organisation.

The following sectors are affected by the NIS2 Directive:

SECTORS WITH HIGH CRITICALITY (ANNEX I OF THE NIS2-RL): OTHER CRITICAL SECTORS (ANNEX II OF THE NIS2-RL):
Energy Post and courier services
Transport Waste Management
Banking Chemical production, manufacturing and distribution
Financial market infrastructures Food production, processing and distribution
Public Health Manufacturing
Drinking Water Digital service providers
Waste Water Research and Development
Digital infrastructure
ICT services management (B2B)
Public administration
Space

What are essential and important organisations?

The NIS2 Directive generally applies to organisations with at least 50 employees or an annual turnover or balance sheet total of more than EUR 10 million. In certain cases, such as providers of publicly available electronic communications services, the Directive applies regardless of size. The obligations are mainly based on classification as a "essential" or "important" entity. "Essential entities" include Annex I companies above certain thresholds, qualified trust service providers, communications network providers, central government entities, and other entities identified as significant. "Important entities" are those listed in Annex I or II that are not already considered as significant or those that are considered as significant by the Member State.

Essential entity Important entity
Sector in Annex I + Sectors in Annex I and II +
at least 250 employees or at least 50 employees or over EUR 10 million annual turnover or annual balance sheet total
over EUR 50 million annual turnover or
over EUR 43 million annual balance sheet total
certain special cases, e.g., central government, DNS service provider or state categorisation as an essential institution certain size-independent special cases, e.g., state categorisation as an important institution

What are the penalties for non-compliance?

The NIS2 Directive requires EU Member States to introduce provisions on fines for breaches of Article 21 (risk management measures, see above) and Article 23 of the NIS2 Directive (notification of significant security incidents). At the same time, the NIS2 Directive already sets a minimum value for the upper limit of the range of fines:

Essential entity Important entity
Fine of up to: Fine of up to:
EUR 10 million EUR 7 million
or or
2% of the previous year's total worldwide turnover of the company to which the organisation belongs 1.4% of the total worldwide turnover of the previous year of the company to which the organisation belongs

Who is liable for the implementation of the required measures?

A potential fine is only one of many supervisory and enforcement actions that a competent authority can take in the event of a (potential) breach. Managers of significant and important organisations should therefore address the obligation to implement risk management measures early and thoroughly in order to avoid heavy fines. It remains to be seen whether public administration organisations, such as public authorities, will be subject to fines under Art. 34 para. 7 of the NIS2 Directive.

Ready for the future of cybersecurity?

Contact us now for a personalized consultation and learn how we can align your business with the NIS2 Directive. Act now to minimize risks and ensure compliance.

contact us