Skip to main content

Securely Implement the NIS2 Directive

Meet cybersecurity requirements, report incidents and document technical measures without gaps.

Meet NIS2 Requirements

NIS2 software for mid-sized companies

preeco | information security supports mid-sized companies in implementing NIS2: technical and organizational measures (TOMs) are documented continuously and linked to assets and risk analyses, NIS2 relevance can be flagged per asset, and cyber incidents are recorded and reported in a structured way. The software thus maps the three core NIS2 duties — risk management, reporting obligations and evidence — in one system.

  • Nine ready-to-use reporting templates: early warning, notification and final report to the BSI (NIS-2, § 32 BSIG) plus the KRITIS disruption notification (§ 25 BSIG).

  • Automatic deadline monitoring: early warning within 24 hours, notification within 72 hours, final report within one month.

  • NIS2 training for management as an included e-learning — as proof of the training obligation for management bodies.

  • The CISIS12 SME standard as a ready-made audit catalog with all 12 modules available immediately.

  • Cloud and Private Cloud instances typically provisioned within 48 hours (on working days) — without long lead times.

The software does not replace a legal assessment of whether your organization falls within the scope of the NIS2 Directive; it supports you in implementing the obligations in a documented way once applicability is established.

FAQ

Frequently asked questions

preeco | information security covers three core NIS2 duties: you document technical and organizational measures (TOMs) continuously and link them to assets and risk analyses, record NIS2 relevance per system, and report incidents in a structured way. Nine reporting templates are included — early warning, notification and final report to the BSI (NIS-2, § 32 BSIG) plus KRITIS disruption notification (§ 25 BSIG) — and the NIS2 deadlines (24-hour early warning, 72-hour notification, 1-month final report) are monitored. An included NIS2 training for management serves as proof of the training obligation for management bodies. The software does not replace a legal assessment of whether your organization is in scope.

For the mid-market, NIS2 software should connect three things: documentation of TOMs, linking them to assets and risk analyses, and structured incident management with deadline monitoring. preeco | information security combines all of this in one system, flags NIS2 relevance per asset, ships with nine reporting templates for the BSI (NIS-2, § 32 BSIG and § 25 BSIG) and includes an NIS2 training for management. The CISIS12 catalog also provides a practice-oriented SME standard ready to use immediately; Cloud instances are typically provisioned within 48 hours.

An ISO 27001-conformant ISMS covers many organizational requirements of the NIS2 Directive, but it does not replace the NIS2-specific duties: these include in particular reporting cyber incidents to the BSI within 24 hours (early warning), 72 hours (notification) and one month (final report) under § 32 BSIG, as well as the training obligation for management bodies. preeco | information security covers both: requirement catalogs for ISO/IEC 27001 including the Statement of Applicability, and reporting templates with automatic deadline monitoring for the NIS2 reports.

Implement NIS2 with preeco

Discover how preeco | information security supports you with NIS2 compliance.