Your situation

NIS2 consulting and KRITIS audits

You are subject to NIS2 or KRITIS (critical infrastructure) and want to move further into action? You are already actively working on your information security – but are unsure whether your evidence is sufficient for NIS2 or KRITIS?

Map existing ISMS documents, add missing evidence, plan a required KRITIS audit with clear roles.

Free of charge and without obligation.

  • BSI-certified for IS consulting and IS audit
  • Audit procedure competence for Section 8a BSIG
  • BSI-certified IT-Grundschutz Consultants on the team
The secuvera team in discussion at a sand table with the word CYBERSICHERHEIT (cybersecurity) written in it
NIS2 and KRITIS: meeting obligations on time, providing evidence reliably.

Your situation

You are subject to NIS2 or KRITIS and need to provide evidence of your cybersecurity measures?

The German NIS2 Implementation Act (NIS2UmsuCG) is in force and transposes Directive (EU) 2022/2555 into German law. Around 30,000 companies from sectors of high criticality and other critical sectors must provide evidence of robust cybersecurity measures, report security incidents and actively involve their management bodies. Operators of critical infrastructure already provide formal evidence of their IT security measures, generally every two years; the German KRITIS umbrella act (KRITIS-Dachgesetz), based on the CER Directive (EU) 2022/2557, extends this framework.

The questions depend on your starting point: does your company, with at least 50 employees or more than EUR 10 million in turnover in a relevant sector, fall under NIS2 for the first time? Are you already registered as a KRITIS operator and want to avoid duplicate work? Are your existing ISMS documents sufficient as evidence? There is no certification obligation – but there is an obligation to provide evidence.

We start where you are: we compare existing measures with the ten security requirements of Article 21(2) of the NIS2 Directive, add missing evidence and, on request, also carry out your KRITIS audit. We clarify the scope and independence of consulting and audit in advance. If you want to further strengthen your ability to provide evidence, we prepare a certification to ISO 27001 or BSI IT-Grundschutz. For the required continuity of operations in an emergency, we build business continuity management with you.

Services & results

From determining applicability to audit-ready evidence

You know whether NIS2, KRITIS or both apply to your company, what evidence follows from this and where your existing measures stand against the ten NIS2 requirements. As a KRITIS operator, you receive support with the KRITIS audits, without duplicate work between the two legal frameworks; you continue to use your existing ISMS (information security management system) documents.

We ask first: what is already in place, what needs to be added, what really makes sense? For companies that fall only under NIS2 and for KRITIS operators with obligations under both, the steps lead to consistent evidence for both legal frameworks.

Determine whether NIS2 and KRITIS apply

If this has not yet been clarified, we determine whether and how you are affected. Our consulting is aimed at two groups:

  • NIS2 but not KRITIS: at least 50 employees or more than EUR 10 million in turnover in a relevant sector, obliged to implement cybersecurity measures and provide evidence for the first time
  • KRITIS and NIS2: already registered as a KRITIS operator, also meeting the NIS2 criteria, needing consistent evidence for both legal frameworks

Clarified scope

Clarity on whether NIS2, KRITIS or both apply to you and which evidence follows from this.

Compare measures with the ten NIS2 requirements

We compare your existing security measures with the ten basic NIS2 security requirements, such as risk management, ISMS and security concept. We include existing documents based on ISO 27001 or BSI IT-Grundschutz.

A mapping is only a first step: our analysis of the annex to the NIS2 Implementing Regulation shows that requirements for web applications, system hardening and network operations, for example, are hardly specified there.

Add missing evidence

We identify evidence that is still missing and build robust, audit-ready documentation with you.

  • Evidence of the effectiveness of measures
  • Training
  • Maturity level
  • Reporting obligations
  • Optional: preparation for certification to ISO 27001 or BSI IT-Grundschutz

Audit-ready evidence

Audit-ready documentation for the agreed scope.

KRITIS: preparing critical services and evidence

We identify your critical service processes (kDL) and develop and update audit-ready evidence, for example based on your industry-specific security standard (B3S).

Carrying out the KRITIS audit

Our qualified audit team carries out the KRITIS audit. We agree the required external sector expert in accordance with GAiN together with you and involve this person in the audit.

KRITIS audit results

A structured audit process with clear results instead of pages of lists of deviations.

Our expertise

We advise and we audit. secuvera employees have held the additional audit procedure competence for Section 8a(3) BSIG since the KRITIS evidence obligation began in 2018. This audit practice feeds into our NIS2 consulting.

We follow regulation closely: we have compared the annex to the NIS2 Implementing Regulation – 13 sections with 53 requirement aspects – with BSI IT-Grundschutz (Edition 2023) and ISO 27001:2022 and published the results. We have written about the modernisation of IT-Grundschutz in the magazine "IT-Sicherheit" (issue 3/2025).

For ISMS based on BSI IT-Grundschutz and ISO 27001, our company can draw on decades of consulting expertise. Our team includes certified auditors for ISO 27001 on the basis of IT-Grundschutz, IS auditors and ISO 27001 Lead Auditors.

Getting started

Starting with your open questions about evidence

Assessing applicability and existing evidence

Bring a description of your organisation, where applicable the applicability already clarified, and existing ISMS or KRITIS evidence. We discuss which documents can be reused and which questions are open.

Clarify your NIS2/KRITIS starting point
Dividers fixing a position on the world map
Check applicability and close open evidence gaps in a targeted way.

Sector expertise and independent audit

For KRITIS audits, the sector expertise required in the audit procedure must be planned for. We agree with you who can provide it. The scope and independence of consulting and audit are clarified in advance. Security assessment and legal advice are different tasks.

Questions about NIS2 consulting and KRITIS audits

Does secuvera also help if it is still unclear whether NIS2 applies to us?

Assessing open requirements is part of the start of our consulting. To do this, we look at your organisation and any existing assessment. Only once the relevant scope has been clarified can the comparison of measures and evidence be planned in a targeted way.

Can ISO 27001 or IT-Grundschutz documents be used for NIS2?

Yes, an existing ISMS provides key processes and evidence. Our analysis shows that most requirements in the annex to the NIS2 Implementing Regulation can be mapped to elements of the BSI standards, modules of the IT-Grundschutz Compendium or controls of ISO 27001. However, the mapping is not always precise, and areas such as web applications, system hardening or network operations are hardly specified there. A mapping is therefore a first step – what matters is that implementation and effectiveness are demonstrated.

How do NIS2 consulting and a KRITIS audit differ?

In consulting, we work on requirements, measures and documentation. A KRITIS audit assesses the protection of the critical service processes within the defined audit framework. Audit roles and independence are clarified separately for this.

Do we need to be certified for NIS2?

No. There is no certification obligation, but there is a clear obligation to provide evidence. A certification to ISO 27001 or BSI IT-Grundschutz can further strengthen your ability to provide evidence; we offer preparation for it as an option.

Who is affected by NIS2?

Broadly speaking, companies with at least 50 employees or more than EUR 10 million in turnover from a sector listed as relevant in the Directive are affected, such as energy, IT, health, transport, public administration and DNS or TLD operators. If it is still open whether you are affected, we assess this at the start of our consulting.

Articles on this topic (in German)

All 19 articles on the topic (in German)

Older articles reflect the legal situation at the time of publication. The sections above summarise the current situation.

How can we support you with NIS2 and KRITIS?