About me
Blog
Europe/Berlin
--:--:--
NIS-2 in force — German transposition in progress. Build the buffer now.

Pass NIS2 on time — without the consultant overhead.

NIS2 readiness audit for mid-sized manufacturers. Technical review, clear recommendations, report in two weeks — from a single source.
Book a 30-minute intro call

Are you actually in scope?

The NIS-2 directive targets medium and large entities in critical sectors — energy, transport, health, digital infrastructure, food, manufacturing and more. The three indicators below give you a first orientation. They don't replace a case-by-case legal assessment, but they help you start the conversation inside your own company.
The following is a technical assessment and does not constitute legal advice under the German Legal Services Act (RDG).
1.
SectorYour company would potentially be in scope if it operates in one of the sectors listed in Annex I or II of the NIS-2 directive (e.g. energy, transport, health, drinking water, digital infrastructure, manufacturing from certain sub-industries onward).
2.
SizeThresholds apply to medium-sized entities from 50 employees or €10M annual revenue. Larger entities from 250 employees or €50M can be classified as “essential.”
3.
Key datesThe EU deadline of 17 October 2024 has passed. The German NIS2UmsuCG transposition is in progress — the current status should be verified before the audit starts.
Suppliers to entities in scope, and EU activities of non-EU operators, can also fall into scope. If two or more of the three points apply, a technical assessment is worthwhile — that's exactly what the readiness audit exists for.

How the NIS2 readiness audit runs.

Four steps, clearly paced. No consultant theatre, no slideware overhead. You get a technical report that holds up before a supervisory review — and an action plan your team can work with immediately.

What makes this audit different.

Two differences from traditional NIS2 consultancies.

From real projects.

A mid-sized mechanical engineering company commissioned an Azure security audit with a Zero Trust roadmap in early 2026. Duration: two weeks. Result: three high-impact findings with a concrete remediation path, handed over to internal DevOps and management.Reference available on request
For a legal-protection insurer in the DACH region I owned the backend and security portions of customer-facing claims-process flows — including secure API integration, session handling, and stability under production load.Reference available on request

What you hold in your hand at the end.

Four phases, two weeks of net processing time.

Artefacts (what you get)

Audit report (PDF, 30–60 pages depending on scope) with executive summary, methodology, findings, and an Art. 21 maturity matrix.
Findings list with impact, effort, priority, and an ownership suggestion.
Action plan as an editable document (Markdown or Excel — your choice).
Mapping table: Art. 21 NIS-2 ↔ current state ↔ recommendation.
Optional: two-page management summary for internal reporting.
All artefacts are yours. No lock-in tooling, no platform dependency.

What it costs.

A NIS2 readiness audit lands between €3,000 and €5,000 net, depending on scope (sites, OT share, cloud footprint). The range is fixed before the contract is signed — no hourly-billing surprise at the end.Optional retainer from €800 net per month. For companies that want continuous support after the audit: monthly security report, configuration drift check, availability for incident questions. Cancellable at the end of each month.Intro call is free and non-binding. 30 minutes, video or phone. By the end you'll know whether the audit makes sense and what it would concretely cost in your case.

Frequently asked questions.

Book a 30-minute intro call

Free, non-binding, directly with the person who will then also run the audit.

Deeper security work — backend, cloud, embedded

If the audit surfaces concrete fixes, I take them on from a single source. Methodology background: Embedded Security Audit for IoT & OT and Backend Security Audit — API, cloud & secure code.
The content on this page is not legal advice under the German Legal Services Act (RDG).The content on this page serves as technical orientation for people responsible inside affected companies. It does not constitute legal advice and does not replace a case-by-case legal review. Büngener Software provides technical audits and implementation only.