FNLY IT

FNLY IT — NIS2

The NIS2 deadlinehas passed.

Germany's NIS2 implementation act has applied since 6 December 2025 — with no transition period. If you are in scope and have done nothing, you are already overdue. We get you back on track, methodically.

  • Gap analysis in 5 working days
  • Reachable 24/7
  • ITIL v4 · GDPR
  • A fixed contact person

Scope

Are you in scope?

Around 29,500 companies in Germany now fall under NIS2 — up from roughly 4,500. Many do not realise they are among them. Three points settle it:

01

Size

At least 50 employees or €10M annual turnover. Either one is enough.

02

Sector

Your industry appears on the list of important or particularly important entities — from energy, health and transport through to manufacturing and IT services.

03

Registration

The deadline to register with the BSI expired on 6 March 2026. Not registered means overdue.

Unsure whether your sector is covered? That is exactly what the initial consultation is for — free and without obligation.

The risk

What is at stake.

€10M

Fine

Up to 10 million euros or 2% of global annual turnover — whichever is higher.

Personal

Liability

Management must approve and monitor the measures — and is personally liable with private assets in the event of breaches.

24 hrs

Reporting

Significant security incidents must be reported within 24 hours, followed by 72 hours and one month.

The path

Compliant in four steps.

  1. 01

    Gap analysis

    We assess whether you are in scope and capture the current state: infrastructure, processes, documentation. The result is a solid list of gaps rather than a hunch.

  2. 02

    Action plan

    Prioritised by risk and effort, with owners and dates. You know what has to happen first and what can wait.

  3. 03

    Delivery

    We implement rather than hand you a report: firewall and endpoint protection, permission concepts, 3-2-1 backup, incident and reporting processes.

  4. 04

    Operation & evidence

    Monitoring, documented restore tests and the evidence you need for the BSI. On request we take on ongoing operations entirely.

Why FNLY

Advice and operations.

Many providers deliver a report and move on. But NIS2 is not a project with an end date — it is a state that has to be maintained, including a reporting duty that applies around the clock.

Not just a consultancy

We analyse, implement and then keep running your IT. One point of contact instead of handovers between advice and operations.

Reachable 24/7

365 days a year, from the first call down to the deepest system layer. The 24-hour reporting deadline cannot be met any other way.

A fixed contact person

No call-centre roulette. You get a technical contact who knows your environment, with an individual SLA.

Transparent pricing

A monthly flat rate instead of surprises. You know up front what NIS2 compliance costs.

FAQ

Frequently asked questions about NIS2

We're a mid-sized company — does NIS2 even apply to us?

Probably yes, if you have at least 50 employees or €10M annual turnover and operate in one of the listed sectors. The number of entities in scope has grown from roughly 4,500 to about 29,500 — many of them ordinary mid-sized businesses that previously had nothing to do with critical-infrastructure rules. We establish your status definitively in the initial consultation.

The registration deadline has passed. What now?

Act rather than wait. The obligation stands regardless of whether the deadline has lapsed, and registering late with a documented action plan is far better than continuing to do nothing. We prioritise so the points that matter to the regulator come first.

What does NIS2 compliance cost?

That depends on your starting point — a company with a sound backup concept and permission management already needs far less than one starting from scratch. That is why the gap analysis comes first: only then can anyone quote seriously. The initial consultation itself is free.

How long does it take?

The gap analysis delivers a result within five working days. How long delivery takes follows from that — typically several weeks to months, depending on size and starting point. What matters to the regulator is that a documented plan exists and is being worked through.

Is management really personally liable?

Yes. Management must approve the risk-management measures and monitor their implementation. Breaching those duties creates personal liability that cannot be excluded by contract. The risk can be reduced to a reasonable level through documented diligence — which is precisely what the action plan is for.

Can you also take over from our current IT provider?

Yes. Our transition management takes over in a structured way, with complete knowledge documentation and a defined handover protocol. Legacy systems are migrated with a rollback concept, parallel operation and a controlled cutover — without losing critical know-how along the way.

Do we have to rebuild our IT from scratch?

Usually not. NIS2 requires appropriate measures reflecting the state of the art, not a rebuild. Often the gaps are in documentation, permission concepts, backup testing and reporting processes — structure rather than new hardware. The gap analysis shows what is actually needed.

Consultation

Let's establish your status.

Free, without obligation and with no sales pressure. We tell you openly whether you are in scope and what to do first.

Or call us directly:

05682 7369200

We use your details solely to process your enquiry.