
NIS2 asks for evidence. We
deliver it technically.
NIS2 has applied in Germany since 6 December 2025 — with no transition period. §30 BSIG requires not only measures but an assessment of their effectiveness. A penetration test is the most defensible way to provide it. We deliver it in audit-ready form, from €3,500.
The binder is full. The effectiveness is untested.
Most NIS2 programmes stop where it hurts least: policies, procedures and a management system on paper. That work is necessary — but it does not answer the question the law actually asks. §30 (2) no. 6 BSIG requires concepts for assessing the effectiveness of risk management measures. Translated: does what you documented hold up against a real attacker? No document answers that — only a test does. That is where we come in: technical, evidenced, repeatable.
Where things stand
NIS2 in Germany — the hard facts
Not a forecast, not a draft. The law is in force and the registration deadlines have passed.
- In force since
6 December 2025 — no transition period
The German NIS2 implementation act (NIS2UmsuCG) was passed on 13 November 2025 and entered into force the day after promulgation. The obligations have applied since then.
- Entities affected
Around 29,500 organisations in Germany
Membership of one of the sectors listed in the BSIG plus, as a rule, at least 50 employees or more than €10m annual turnover or balance sheet total.
- BSI registration
Deadline 6 March 2026, grace period 31 July 2026 — both passed
A missed registration can be penalised in its own right. If you are still not registered, fix that first — before booking a pentest.
- Incident reporting
24 hours early warning · 72 hours report · 1 month final report
Applies to significant security incidents. The 24-hour clock starts when you become aware — not when analysis is complete.
- Fines
Up to €10m or 2% of global annual turnover
For essential entities; the range is lower for important entities. A missed registration carries up to €500,000.
- Supervision
BSI — unannounced audits possible for essential entities
The BSI can request evidence, run audits and order security assessments. Having nothing to show at that point is the weakest possible position.
- Accountability
Management approves, oversees and is liable
Implementing risk management measures is a management duty and cannot be fully delegated. Mandatory training for the management level included.
This page places NIS2 in technical context and describes which of our services address which requirement. It is not legal advice. Whether and in which category your company is in scope is a question for your legal counsel.
Are you in scope?
The second question often matters more: are you pulled in through your customers?
Essential entities
Larger organisations in particularly critical sectors — energy, transport, health, water, digital infrastructure, IT service providers. Unannounced BSI audits are explicitly foreseen here.
Important entities
As a rule from 50 employees or €10m turnover — including mechanical and automotive engineering, medical devices, electronics, chemicals, food, postal services, waste management and research. Supervision is triggered by cause.
Suppliers and service providers
The most underestimated point: §30 (2) no. 4 BSIG obliges in-scope companies to manage the security of their supply chain. That requirement is passed on contractually — including to companies not themselves in scope.
Software and product manufacturers
In scope twice: as an entity under NIS2 and as a manufacturer under the Cyber Resilience Act. Both require working vulnerability management — the technical basis is the same.
Management personally
Approval of measures, oversight of implementation, mandatory training. NIS2 makes information security explicitly a leadership duty — not an IT topic.
Not sure whether you qualify?
You are in good company — classification is the most common point of dispute. We clarify the technical side in the intro call and will tell you plainly if you need legal advice before a pentest.
§30 BSIG in practice
Which requirement we answer with what
All ten measure areas in §30 (2) BSIG are mandatory. These are the ones that can be tested technically — and that is what we do.
Requirement under §30 (2) BSIG
What we deliver
Policies on risk analysis and information system security
No. 1
The penetration test shows which risks are actually exploitable — not just which ones appear in the risk matrix. The result is a CVSS-prioritised list with a real attack path instead of an estimate.
Incident handling
No. 2
The assumed-breach assessment tests the real case: we start from an assumed foothold and measure how far we get — and whether your detection fires before we reach the objective.
Supply chain security
No. 4
External interfaces, third-party integrations and exposed supplier access belong in the pentest scope. Attack surface monitoring keeps that picture current afterwards.
Security in acquisition, development and maintenance — including vulnerability handling
No. 5
Secure SDLC review: how do vulnerabilities enter your software, and what catches them? Pipeline, dependencies, secrets, review practice — with measures your team can actually implement.
Policies to assess the effectiveness of risk management measures
No. 6
The core of this page: a recurring penetration test with a re-test after remediation is a dated, traceable proof of effectiveness. Planned as a retainer instead of improvised once a year.
Cyber hygiene practices and security training
No. 7
Developer workshop based on your own findings. In our experience one real vulnerability from your own code lands harder than any generic awareness deck.
Cryptography and encryption
No. 8
TLS configuration, certificate management, transport security and handling of keys and secrets — a standard part of the security audit and of attack surface monitoring.
Access control and personnel security
No. 9
Role and permission testing in every pentest: horizontal and vertical privilege escalation, insecure direct object references, forgotten administrative accounts.
Multi-factor authentication and secured communications
No. 10
MFA bypass testing, review of recovery and emergency access paths and of session handling — the point where MFA most often fails in practice.
From obligation to evidence
A plannable path instead of a compliance fire drill
Intro call (30 minutes, free)
We clarify your technical starting point, the trigger — audit, customer requirement, supervision, incident — and what realistically comes first.
NIS2 readiness check (2 days)
Assessment against the technically testable requirements of §30 (2) BSIG. Output: gap list, prioritised action plan, management summary — for €2,900.
Scope and test plan
We agree which systems are tested, with which methodology and in which window. Written test authorisation included.
Penetration test
Manual testing to OWASP, PTES and BSI standards. Critical findings are reported immediately, not held back for the final report.
Report in evidence form
Management summary for leadership, technical section for your team, CVSS scoring, reproduction steps, remediation guidance — ready to present to an auditor or supervisor.
Remediation — with or without us
Your team implements, or we take it on. As a software company that is not a foreign body for us but day-to-day work.
Re-test and documentation
Verification of remediated findings plus a closing document. The proof of effectiveness is then not only produced but evidenced.
What we do — and what we don't
NIS2 compliance is more than technology. We cover the technical part, and we tell you where our role ends.
We take this on
- Technical readiness check against the testable requirements of §30 BSIG
- Penetration tests as proof of effectiveness, repeatable and dated
- Assumed-breach assessment to test detection and response
- Attack surface monitoring as ongoing evidence between tests
- Secure SDLC review and developer workshop
- Reports in audit-ready form including remediation tracking
- Technical support for your ISMS consultant or auditor
We do not take this on
- Legal advice on whether and how you are in scope
- Registering with the BSI on your behalf
- ISO 27001 certification — we are not a certification body
- Building a full ISMS including the policy framework
- Reporting security incidents to authorities on your behalf
- 24/7 monitoring in the sense of a SOC
For the items on the right we work with specialist partners — law firms, ISMS consultants, certification bodies. Tell us what is missing and we will refer you rather than improvise it ourselves.
Pricing for your NIS2 evidence
Transparently calculated — without a compliance surcharge
NIS2 readiness check
The fast entry point
- Assessment against §30 (2) BSIG (technical scope)
- Prioritised gap list
- Action plan with effort estimates
- Management summary for leadership
- Recommendation for the testing scope
Penetration test
The actual proof of effectiveness
- Web, API, cloud or infrastructure
- Testing to OWASP, PTES and BSI
- CVSS-prioritised findings
- Management summary and technical report
- Re-test after remediation included
- Price verifiable upfront in the calculator
Security Cycle retainer
Evidence that does not expire
- Attack surface monitoring included
- One penetration test per year
- Two consulting days per year
- Re-tests after remediation
- Ongoing evidence documentation
- Priority scheduling around audits
Frequently asked questions on NIS2 and penetration testing
Technical context — not legal advice
Not in those words. §30 (2) no. 6 BSIG requires concepts for assessing the effectiveness of risk management measures without prescribing a specific method. In practice the penetration test is the most common and most defensible way to demonstrate that effectiveness to auditors, customers and supervisors. Pointing only to internal vulnerability scans is the weaker position.
Get the evidence before somebody asks for it
A 30-minute intro call: we place your current state, name the technical gaps and tell you honestly whether a readiness check or a penetration test is the right next step.