ISMS & Risk

NIS2 file

One file per entity, ordered by the sections of the act

NIS2 is implemented in Germany through the BSIG, which sets out seven obligations that in practice tend to blur into one. This file keeps them apart, because they have different addressees and different deadlines. The anchor is the scope determination under Section 28: registration, obligations catalogue, evidence cycle, management body and supervisory correspondence all hang off it. The catalogue of entity types from Annexes 1 and 2 BSIG is included with its official three-level numbering, so that a classification points to a legal reference rather than to an opinion.

NIS2BSIGISO 27001BSI IT-Grundschutz
Features

Your benefits

1

A missing metric is not an all-clear

The rule evaluation under Section 28 knows a third state besides in scope and out of scope: unclear. Where a metric is missing, the file says so rather than quietly computing the entity out of scope. The category stays a human decision, and the rule trace shows how it was reached.

2

Registration and evidence stay separate

Sections 33 and 34 apply to every entity in scope, Section 39 only to operators of critical installations. Being registered does not make you subject to evidence duties, and holding evidence does not replace registration. The two strands therefore run side by side.

3

What was submitted stays readable

The particulars of a registration are never overwritten. Every version remains in place, and a change notification creates a new one. The same applies to management approval: the implementation state is frozen as at the approval date.

4

Two deadlines that are not flattened

A change notification is due within two weeks under Section 33(5) and within three months under Section 34. The difference is derived from the type of registration and kept on the record. Flatten it and you shorten or extend a statutory deadline.

Capabilities

All capabilities at a glance

  • Scope determination under Section 28(1) and (2) with rule trace and follow-up date
  • Catalogue of entity types from Annexes 1 and 2 BSIG with official numbering
  • Re-assessment with successor and superseded predecessor, history chain per entity
  • Several entities subject to registration per tenant, for group structures
  • Registration file under Section 33 with versioned particulars and contacts
  • Special registration under Section 34 with the eleven entity types of Section 60(1)
  • Change notification as a scheduled task, deadline derived from the type of registration
  • Obligations catalogue under Sections 30 and 31 with pre-check and statement of applicability
  • Evidence cycle under Section 39: first within three years of classification, then every three years
  • Conformity assessment bodies with route to eligibility and field of competence, defect list per Annex PE.A in four levels
  • Management body per entity with role and period, not as an attribute on the person
  • Approval and oversight under Section 38(1) with a frozen implementation state
  • Training status of the management body as a target-versus-actual comparison against existing qualifications
  • Supervisory correspondence under Sections 61 and 62 with orders, deadlines and completion
  • Reporting under Section 32: early warning within 24 hours, notification within 72 hours, interim and final report
  • Cockpit, reporting view and a printable file for the supervisory authority
  • Daily checks for classifications due, outstanding training evidence and oversight dates
Result

A file that answers the question "on what basis are you in scope, and what follows from that" with a legal reference rather than an assessment.

Experience NIS2 file live

Schedule a no-obligation demo – we will show you the module with your own use cases.