Homepage » Robin Data ComplianceOS® » NIS2 Directive

Consulting and implementation of the

NIS2 Directive

Since 13 November 2025, the German NIS2 Implementation Act has been binding without a transition period: make your organisation audit-proof now. Implement the new cybersecurity requirements quickly and seamlessly with Robin Data ComplianceOS® and certified consulting.

Robin Data stands for highest
quality and safety standards
and is TÜV certified.

Secure

Increase your organisation's cyber security and protect yourself against attacks and data loss.

Conscientious

Reduce your liability risks, we keep an eye on your obligations in accordance with the NIS2 directive.

Sustainable

Avoid high fines and penalties for violating safety requirements.

Consistent

Our consultants support you with all NIS2 requirements from risk management to reporting.

The German NIS 2 Implementation Act is now in force: what does this mean for you?

The German NIS 2 Implementation Act was passed on 13 November 2025 and applies without a transition period. The goal: a significantly higher common level of security for business and administration. The new legislation affects more organisations than ever before: its scope now extends to public and private organisations in 18 sectors, starting at 50 employees or €10 million in annual turnover/annual balance sheet total. This includes, for example, healthcare, energy supply, digital infrastructure, manufacturers of goods and all relevant parts of the digital sector (e.g. data centres, cloud and software providers). Even medium-sized organisations that were not previously considered critical infrastructure can now be classified as „important institutions“. You should therefore check immediately whether your organisation falls under the new law.

Prepare your organisation for the requirements; Robin Data will provide you with comprehensive support. A Majority of legal obligations you fulfil with the implementation of a Information Security Management System (ISMS) in accordance with ISO 27001. We explain what additional obligations exist and how you can implement them in a verifiable manner with our Robin Data ComplianceOS software.

The organisational measures for implementing NIS2 are comprehensive. Prepare yourself with the Implementation of an ISMS according to ISO 27001 before!

What do affected organisations need to do?

Requirements of the NIS2 Directive

Affected organisations must Minimum requirements to strengthen organisational cyber security. Significant security incidents must be reported to the BSI - the Federal Office for Information Security be reported. Responsible for the realisation and liable The company management is responsible for any defects. Organisational management will bear responsibility in future for implementing all these measures and must monitor their effectiveness. Our consultants relieve your management team by preparing and reporting on the necessary steps in a structured manner. This allows you to maintain an overview of your compliance at all times.

ISMS & Policies

Establishment of a formal Information Security Management System (ISMS) in accordance with proven standards (ISO 27001 or BSI basic protection). Creation of security guidelines and procedures that are supported by management (security policy).

Risk Management Risk Management

Risk Management

ongoing risk analyses Your IT and processes, as well as appropriate Risk treatment measures. Documentation of all identified cyber risks for reporting to management, because ultimately, management must actively manage the risks.

Incident Management

Establish a incident response process, reporting thresholds and emergency plan. Significant security incidents must within 24 hours Initial reports must be submitted to the authorities (BSI) within 72 hours, followed by detailed reports and a final report within one month at the latest. We can assist you in preparing these processes and coordinating reports.

Business Continuity

Set the business continuity secure, through regular backups, disaster recovery plans and crisis exercises. NIS2 requires concepts for Maintaining business operations in an emergency. Our consultants review your emergency manuals and work with you to set up emergency communication channels so that your organisation remains operational even in the event of an emergency.

supply chain security

Secure your Supply Chain NIS2 requires the systematic integration of IT security at service providers and suppliers. We support you in this endeavour., Analysing risks in the supply chain and control. For example, establish security requirements in contracts, third-party risk management and an up-to-date supplier register.

Secure IT procurement and development

Ensure SSecurity in the procurement, development and maintenance of IT systems. This includes vulnerability management (detection and reporting of vulnerabilities) and requirements for your IT/software developers to work according to secure development standards. ComplianceOS® offers modules for documenting and tracking vulnerabilities.

Training & cyber hygiene

Raise awareness among employees on a regular basis. NIS2 requires Security awareness training and basic cyber hygiene practices within the organisation. With our Academy programme, we train your team in safe behaviour while also meeting the compliance requirements for regular further training for your staff – right up to management level, who must also participate in training courses.

Technical measures

Use strong authentication (e.g. MFA), protect data using cryptography (encryption) and implement protocols for secure network and communication channels.

The majority of NIS2 obligations are in the area of information security

NIS2 consulting by external ISB

One Majority of legal obligations you fulfil with the implementation of a Information security management system (ISMS) in accordance with ISO 27001.

Our certified security experts can assume the role of external ISB in your organisation upon request. They bring in-depth expertise to NIS2 and ISO 27001 and accompany you from risk analysis to the implementation of individual measures. As external ISBs, we ensure that all obligations are continuously fulfilled and documented. This significantly reduces the liability risks for your management.

Our compliance management platform Robin Data ComplianceOS® digitises your ISMS and makes NIS2 implementation easier. Modules for data protection, information security, risk management and supplier management work together seamlessly

Order procedure

Order an external ISB and become NIS2 compliant

  • 1

    Contact

    In a free initial consultation with Robin Data, we will provide you with non-binding advice on the implementation of the NIS2 directive and the appointment of an information security officer by Robin Data.

  • 2

    Needs assessment

    After booking an appointment, we determine the scope of your requirements in an initial meeting. If necessary, we will schedule an audit to document open measures and directly optimise security-relevant deviations from the standards. The initial contact and scheduling are completely free of charge. General questions about Robin Data solutions can be clarified. You can speak directly to a consultant who, based on their experience, can accurately assess the extent to which we can support you in implementing the requirements of the NIS2 directive. Together, we will tailor the solutions in our consulting portfolio to your budget in order to provide you with a customised offer.

  • 3

    Preparation of offers and conclusion of contracts

    In the next step after determining your needs, we will prepare a non-binding offer based on your requirements. You will receive a draft contract that defines the provision of the agreed services. We discuss the details based on this basis for negotiation.

  • 4

    Order

    After successful contract coordination, our information security expert plans the next steps with you. In doing so, we focus on your specific wishes; both regional on-site consulting and digital consulting are possible in many cases.

  • 5

    Assumption of responsibility as external ISB

    Once you have been appointed, you will be named and assume responsibility as an external information security officer (ISO) in your organisation.

"In the audit of our information security management system by Robin Data GmbH, the current maturity level of our ISMS was audited against the standard of the IT-Grundschutz. Internal and external processes and documents were reviewed and open measures were documented."

Marco Voigt, Head of IT at Merseburg Municipality

Robin Data is external information security officer for sachsen.de
Robin Data is external information security officer for the city of Zwickau
Robin Data is external information security officer for Merseburg University of Applied Sciences

Request a quote from an external ISB

We would be happy to provide you with an offer suitable for the implementation of the NIS-2 directive.

Combine your desired products and compliance fields

Robin Data ComplianceOS®

Quality management

Improve processes, increase effectiveness and efficiency

Legal Compliance

Increase legal certainty and reduce liability risks

Reports & Analyses

Keeping an eye on key figures, evaluating performance

Supplier evaluation

Record supplier risk, avoid grievances

Process automation

Optimise workflows and automate processes

API interfaces

Connecting external systems and interacting across the board

Articles, videos and whitepapers can be found here.

Expert knowledge for your success

Link to: NIS2: EU directive for more cyber securityFollow a manual added linkLink to: Customer reference City of Merseburg
© Copyright - Robin Data GmbH
en_GB