NIS2 Consulting: What to expect from a senior advisor in 2026
Germany's NIS-2 transposition is expected in 2026. Roughly 29,500 entities will need an information security officer, documented controls and a 24/72-hour reporting path. This article explains what mature NIS2 consulting looks like and how to choose the right delivery model.
Directive (EU) 2022/2555, known as NIS2, replaced the original NIS Directive on 17 January 2023 and was supposed to be transposed into national law by 17 October 2024. Germany missed the deadline. The current draft of the NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG) is expected to enter into force in 2026, after the federal cabinet adopted a revised version in late 2025. Around 29,500 German entities will fall into scope as essential or important entities.
For most affected organisations, the gap to a fully documented information security management system is too wide to close with internal resources alone. NIS2 consulting fills that gap. This article explains what a credible engagement looks like in 2026, which delivery models exist on the market, and how CIVAC delivers compliance platform and Officer-as-a-Service in a single subscription. Bestellurkunde, unterschrieben, abgelegt, belegbar.
Auf einen Blick
- NIS2 consulting in Germany in 2026 covers four phases: scope assessment, gap analysis against Art. 21 NIS2 measures, remediation plan and ongoing officer function.
- Market prices range from EUR 350 to EUR 1,200 per consultant day; fractional officer retainers start around EUR 2,500 per month for small entities.
- The German transposition adds personal liability for managing directors under § 38 BSIG-E, making the choice of advisor a board-level decision.
Scope: Who needs NIS2 consulting in 2026
The German draft NIS2UmsuCG mirrors Annex I and II of Directive (EU) 2022/2555. Eighteen sectors are covered, from energy, transport, banking and digital infrastructure to manufacturing of medical devices, waste management and postal services. The size-cap rule applies: medium-sized entities with at least 50 employees or EUR 10 million annual turnover qualify automatically.
Essential entities (wesentliche Einrichtungen) face stricter supervision, on-site inspections and fines up to EUR 10 million or 2 percent of global group turnover. Important entities (wichtige Einrichtungen) face ex-post supervision and fines up to EUR 7 million or 1.4 percent. The classification is made by the BSI and notified individually.
Entities outside the size-cap can still fall in scope. Annex I includes sole providers of a service in Germany, providers whose disruption could have a significant impact, and entities identified as critical for member states under Art. 6 NIS2.
For groups with subsidiaries, each legal entity is assessed separately. A holding may fall under DORA while a manufacturing subsidiary falls under NIS2. A consolidated view across the group is essential to avoid both gaps and duplication.
Consulting begins with a documented scope assessment. CIVAC delivers this assessment within two business days, mapping legal entities, sectors, sizes and applicable annexes to NIS2 status. The output is signed off by the management board and stored in the workspace audit trail.
Without a clean scope assessment, every later step risks being misaligned. Skipping this phase is the most common and most expensive mistake.
Phase one: Gap assessment against Art. 21 NIS2
Art. 21 NIS2 lists ten minimum cybersecurity risk-management measures. They cover risk policies, incident handling, business continuity, supply-chain security, security in network and information systems acquisition, vulnerability handling, effectiveness assessment, cyber hygiene practices, cryptography and access control.
The gap assessment compares the existing control environment with these ten measures. A mature assessment uses an evidence-based approach: not only policies, but actual implementation, monitoring and review. Interviews, document review, technical checks and a sample-based evidence test.
The output is a heat map per measure, an issue log with severity, and a remediation roadmap with owners, deadlines and effort estimates. The roadmap must be realistic. NIS2 enforcement does not begin on transposition day for every measure equally; the BSI is expected to prioritise reporting obligations and registration first.
Linking the gap assessment to ISO/IEC 27001:2022 avoids parallel control universes. Annex A of ISO 27001:2022 contains 93 controls that cover most of the Art. 21 measures. Mapping each Art. 21 requirement to existing ISO controls reduces redundancy.
A typical gap assessment for a medium-sized entity takes between four and eight consulting days. CIVAC accelerates it to two business days through pre-built templates and structured interviews, while preserving the depth of analysis.
Deliverables include a board-ready summary, a technical findings report and a prioritised remediation plan. Audit-fest, dokumentiert, Art. 21-fest.
Phase two: The reporting path (24/72 hours)
Art. 23 NIS2, transposed in the draft § 32 BSIG-E, sets a three-stage reporting obligation for significant incidents. An early warning must reach the BSI within 24 hours of becoming aware. An incident notification follows within 72 hours, including an initial assessment of severity and impact. A final report must be delivered within one month of the notification, covering root cause, scope and mitigation measures.
Frist läuft ab Kenntnis. The clock starts the moment an authorised person within the entity becomes aware of the incident, not at the moment it is formally classified. Consulting engagements that fail to design this trigger precisely create legal exposure for the management board.
The 24/72 reporting path requires three components: a detection mechanism (SIEM, EDR or managed detection), a classification procedure with clear thresholds, and a workflow that produces the notification within the legal time frame. All three need owners and substitutes.
CIVAC operates a pre-built 24/72 reporting workflow that consolidates NIS2, DORA and Art. 33 GDPR obligations in a single tool. The information security officer orchestrates the workflow and produces the reports for the BSI in the standardised format.
The reporting path needs to be tested. A tabletop exercise at least annually is good practice; the BSI is expected to make this mandatory. Bestellurkunde, unterschrieben, abgelegt, belegbar.
License the workspace for your internal officers, or let our officers be appointed. The dual model reduces dependence on a single consultant.
Phase three: Supply-chain due diligence
Art. 21(2)(d) NIS2 introduces an explicit supply-chain security requirement. Entities must assess the security of direct suppliers and service providers, in particular those of critical importance. The German draft extends this to ICT service providers, software vendors, managed service providers and cloud platforms.
Consulting engagements typically structure this work in three steps. First, a tiered supplier inventory, mapping every contracted vendor by criticality, type of service and access to systems or data. Second, due diligence questionnaires aligned with the BSI minimum requirements. Third, contractual updates with security clauses, audit rights and incident notification obligations.
For groups with hundreds of suppliers, the workload is significant. A medium-sized manufacturing entity typically has 80 to 150 critical suppliers requiring assessment. At one consulting day per ten suppliers, the effort reaches eight to fifteen days for the first cycle.
CIVAC accelerates this through the lieferanten-auditor role and the 490 ready-to-use audit templates. The workflow includes automated questionnaire dispatch, evidence collection, scoring and renewal reminders.
The link to DORA is important for entities in the financial sector. DORA Art. 28 requires an annual third-party information register submitted to the BaFin. Entities subject to both DORA and NIS2 can use a single consolidated register.
For pure NIS2 entities, the requirements are less prescriptive but still mandatory. The BSI is expected to issue guidance on supply-chain assessment depth in 2026.
Phase four: Officer function and governance
The German NIS2 draft introduces a mandatory information security officer (Informationssicherheitsbeauftragter, ISB) for essential and important entities. The officer reports directly to the management board and is responsible for the implementation of Art. 21 measures, incident reporting and supplier oversight.
Three delivery models exist. Internal hire: a full-time ISB on the payroll, market salary EUR 90,000 to EUR 140,000 plus social charges, recruitment time three to six months. Project consultant: external advisor on a daily rate, EUR 850 to EUR 1,400 per day, suitable for short engagements but not for the ongoing officer function. Officer-as-a-Service: a named external officer with formal appointment, monthly retainer, escalation hotline.
For medium-sized entities, Officer-as-a-Service is often the most cost-effective option. The monthly retainer covers governance, reporting, incident response support and supplier review. Costs range from EUR 2,500 to EUR 8,000 per month depending on complexity.
The Bestellurkunde (appointment deed) is the legal foundation. It names the officer, defines tasks and authority, specifies the reporting line and confirms the resources made available. Without a written appointment, the function is not legally effective.
CIVAC provides the Bestellurkunde, the task catalogue, the reporting line to the board and an escalation hotline within two business days. License the workspace for your internal officers, or let our officers be appointed.
Andere führen Compliance wie einen Aktenschrank. Wir führen sie wie Software.
What to ask a NIS2 consultant
The market for NIS2 consulting in Germany is crowded. Audit firms, law firms, system integrators, boutiques and platform providers all sell variations of the same scope. Asking the right questions sorts depth from sales pitch.
First: Which Art. 21 measures will be covered in detail, and which only at policy level? A credible consultant will be specific about depth, evidence collection and technical testing.
Second: How is the gap assessment evidenced? Document review without technical verification produces a paper trail, not a compliance posture. Ask for sample evidence tests, interviews and configuration reviews.
Third: Is the deliverable mapped to ISO/IEC 27001:2022 controls? If not, the entity will duplicate effort when pursuing certification.
Fourth: Who signs the appointment as ISB after the project? A consulting firm that finishes the project and leaves creates a governance gap. Ask explicitly about the ongoing officer function.
Fifth: Where does the data sit? EU data residency is increasingly a board requirement, especially for sensitive risk reports.
Sixth: How is the 24/72 reporting workflow tested? A consultant who cannot describe a tabletop exercise has not delivered the obligation end-to-end. Der Prüfer ruft an, der Nachweis liegt bereit.
Cost ranges and procurement timelines
Cost transparency is rare in NIS2 consulting. Most providers quote on enquiry. The following ranges reflect public RFPs and CIVAC market observations as of mid-2026.
Scope assessment: EUR 4,000 to EUR 12,000 fixed price, two to five days. The output is a board memo with classification, evidence and immediate next steps.
Gap assessment: EUR 20,000 to EUR 60,000 for a medium-sized entity, four to eight weeks. Larger groups with multiple legal entities can exceed EUR 150,000.
Remediation programme: EUR 80,000 to EUR 400,000 over six to twelve months, depending on the number of measures requiring new tooling, processes or training.
Officer-as-a-Service: EUR 2,500 to EUR 8,000 per month on a 12 to 24-month retainer. Includes governance, reporting, incident support and supplier review.
Platform licence (CIVAC workspace): from EUR 990 per month for a small entity with up to 250 employees. Includes 490 audit templates, 24/72 reporting workflow, supplier register and ISMS documentation.
Procurement should start at least nine months before the entity expects to be classified by the BSI. Tendering, contracting and gap assessment alone consume three to four months before remediation begins. Aus dem Lesen einen Auftrag machen.
Personal liability and board reporting
The German NIS2 draft introduces explicit personal liability for managing directors under § 38 BSIG-E. Members of the management board can be held liable for damages caused by a breach of the cybersecurity risk-management duties. The duty cannot be delegated.
This shifts the dynamic of NIS2 consulting. The board is not only the buyer, it is the legal addressee. A consulting engagement that fails to produce evidence of board involvement leaves the entity exposed.
Concretely, the board must approve the cybersecurity risk-management framework, review the gap assessment, sign off the remediation roadmap and receive at least annual reports from the ISB. Each step should be documented in board minutes.
Training is also a board duty. Art. 20(2) NIS2 requires management bodies to follow training to gain sufficient knowledge to identify risks and assess cybersecurity management practices. The draft § 38 BSIG-E confirms this obligation.
CIVAC provides board-level reporting templates, training records and the audit trail required to demonstrate compliance with these duties. The workspace includes a board dashboard that consolidates risk posture, incident statistics, supplier review status and training completion.
For supervisory boards under § 111 AktG, the obligation to monitor extends to NIS2 compliance. A documented information flow from the ISB through the management board to the supervisory board is part of a defensible governance model.
The CIVAC route: platform and officer in two business days
CIVAC is compliance platform and Officer-as-a-Service in a single subscription. We deliver the scope assessment, the gap analysis against Art. 21 NIS2, the 24/72 reporting workflow, the supplier register and the appointed information security officer within two business days, instead of the two to six weeks typical of classical consulting.
License the workspace for your internal officers, or let our officers be appointed. The workspace includes 490 ready-to-use audit templates, EU data residency, an ISO/IEC 27001:2022-certified ISMS, role-based access and a tamper-evident audit log.
In the Officer-as-a-Service model, a named ISB takes formal appointment, maintains the risk-management framework, prepares board reports and acts as the escalation contact for the BSI. You retain ultimate accountability; we deliver the operational work.
The engagement starts with a 30-minute scoping call. We assess sector, size, group structure and existing documentation. Within two business days, you receive a fixed-price proposal with deliverables, timeline and contractual terms.
Once signed, the workspace is provisioned, existing documents are migrated, the Bestellurkunde is issued, and the reporting line to the board is established. From day three onwards, the platform is productive.
Aus dem Lesen einen Auftrag machen. Write to info@civac.de or use the contact form on civac.de. We respond within two business days with a concrete proposal.
FAQ
When does the German NIS2 transposition enter into force?
The current federal government draft is expected to enter into force during 2026. The original EU deadline of 17 October 2024 was missed. Entities should not wait for the act, since the BSI registration window and the operational obligations begin shortly after publication.
Who falls in scope of NIS2 in Germany?
Approximately 29,500 entities across 18 sectors listed in Annex I and II of Directive (EU) 2022/2555. Medium-sized entities with 50 employees or EUR 10 million turnover qualify automatically. Some smaller providers can be brought into scope if they are critical to a service.
What does a NIS2 gap assessment cost?
EUR 20,000 to EUR 60,000 for a medium-sized entity, four to eight weeks of effort. Larger groups with multiple legal entities can exceed EUR 150,000. CIVAC delivers a structured gap assessment in two business days through pre-built templates and the workspace platform.
What is the difference between project consulting and Officer-as-a-Service?
Project consulting ends with delivery of the gap assessment and remediation roadmap. Officer-as-a-Service includes the formal appointment of an information security officer, ongoing governance, board reporting and incident response support under a monthly retainer.
Are managing directors personally liable under NIS2?
Yes. The draft § 38 BSIG-E introduces personal liability of managing directors for damages caused by a breach of the cybersecurity risk-management duties. The duty cannot be delegated to subordinates and includes board-level training and approval of the risk framework.
How does NIS2 consulting interact with ISO/IEC 27001 certification?
Annex A of ISO 27001:2022 with its 93 controls covers most of the Art. 21 NIS2 measures. A consolidated control model avoids duplication. Entities pursuing both should map every NIS2 measure to one or more ISO controls and reuse evidence across audits.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.