Size
At least 50 employees or €10M annual turnover. Either one is enough.

FNLY IT — NIS2
Germany's NIS2 implementation act has applied since 6 December 2025 — with no transition period. If you are in scope and have done nothing, you are already overdue. We get you back on track, methodically.
Scope
Around 29,500 companies in Germany now fall under NIS2 — up from roughly 4,500. Many do not realise they are among them. Three points settle it:
At least 50 employees or €10M annual turnover. Either one is enough.
Your industry appears on the list of important or particularly important entities — from energy, health and transport through to manufacturing and IT services.
The deadline to register with the BSI expired on 6 March 2026. Not registered means overdue.
Unsure whether your sector is covered? That is exactly what the initial consultation is for — free and without obligation.
The risk
€10M
Fine
Up to 10 million euros or 2% of global annual turnover — whichever is higher.
Personal
Liability
Management must approve and monitor the measures — and is personally liable with private assets in the event of breaches.
24 hrs
Reporting
Significant security incidents must be reported within 24 hours, followed by 72 hours and one month.
The path

We assess whether you are in scope and capture the current state: infrastructure, processes, documentation. The result is a solid list of gaps rather than a hunch.
Prioritised by risk and effort, with owners and dates. You know what has to happen first and what can wait.
We implement rather than hand you a report: firewall and endpoint protection, permission concepts, 3-2-1 backup, incident and reporting processes.
Monitoring, documented restore tests and the evidence you need for the BSI. On request we take on ongoing operations entirely.
Why FNLY
Many providers deliver a report and move on. But NIS2 is not a project with an end date — it is a state that has to be maintained, including a reporting duty that applies around the clock.
We analyse, implement and then keep running your IT. One point of contact instead of handovers between advice and operations.
365 days a year, from the first call down to the deepest system layer. The 24-hour reporting deadline cannot be met any other way.
No call-centre roulette. You get a technical contact who knows your environment, with an individual SLA.
A monthly flat rate instead of surprises. You know up front what NIS2 compliance costs.
FAQ
Probably yes, if you have at least 50 employees or €10M annual turnover and operate in one of the listed sectors. The number of entities in scope has grown from roughly 4,500 to about 29,500 — many of them ordinary mid-sized businesses that previously had nothing to do with critical-infrastructure rules. We establish your status definitively in the initial consultation.
Act rather than wait. The obligation stands regardless of whether the deadline has lapsed, and registering late with a documented action plan is far better than continuing to do nothing. We prioritise so the points that matter to the regulator come first.
That depends on your starting point — a company with a sound backup concept and permission management already needs far less than one starting from scratch. That is why the gap analysis comes first: only then can anyone quote seriously. The initial consultation itself is free.
The gap analysis delivers a result within five working days. How long delivery takes follows from that — typically several weeks to months, depending on size and starting point. What matters to the regulator is that a documented plan exists and is being worked through.
Yes. Management must approve the risk-management measures and monitor their implementation. Breaching those duties creates personal liability that cannot be excluded by contract. The risk can be reduced to a reasonable level through documented diligence — which is precisely what the action plan is for.
Yes. Our transition management takes over in a structured way, with complete knowledge documentation and a defined handover protocol. Legacy systems are migrated with a rollback concept, parallel operation and a controlled cutover — without losing critical know-how along the way.
Usually not. NIS2 requires appropriate measures reflecting the state of the art, not a rebuild. Often the gaps are in documentation, permission concepts, backup testing and reporting processes — structure rather than new hardware. The gap analysis shows what is actually needed.
Consultation
Free, without obligation and with no sales pressure. We tell you openly whether you are in scope and what to do first.
Or call us directly:
05682 7369200