Have you already fully implemented the NIS-2 Directive?
If not, you're not alone. In many companies, it is unclear exactly what needs to be done or how urgent the need for action really is. It's worth taking a closer look at what's in store for you now.
Why NIS-2 is to be taken so much more seriously than previous safety requirements
With the NIS-2 Directive, the European Union is pursuing a clear goal: critical and important companies in the EU should become more resilient to cyber threats. The Directive completely replaces the previous NIS Directive and drastically expands the scope of application. Not only large corporations and traditional KRITIS companies are affected, but many medium-sized companies in sectors such as mechanical engineering, energy, healthcare and financial services are now also subject to the regulation.
What makes NIS-2 special:
- It is not just about technical safety measures.
- It is about structured processes, clearly documented responsibilities and auditable evidence.
- It is about responsibility at management level.
Current developments in Germany
Although the NIS -2 Directive came into force on January 16, 2023 and should be implemented into national law by October 18, 2024, Germany did not meet this deadline. As a result of the federal election in February 2025, all new bills must be introduced and negotiated. Implementation is therefore expected in the second quarter of 2025 at the earliest.
Despite the delay in implementation, the urgency remains. Companies should use the time to adapt their processes and security measures to the requirements of the NIS-2 Directive.
A realistic scenario — and it might sound familiar to you
You work for a company that is considered reliable in its sector. IT security? Is “thought through.” Processes? Are there. But more historically grown than clearly modeled. Documentation? A lot is in Excel, some is in SharePoint, the rest is in your head.
With the introduction of NIS-2, the rules of the game are changing:
- You must prove that risk assessments are carried out regularly.
- You need to show how to respond to security incidents.
- And you'll be liable with fines of up to 10 million euros if you don't.
Register now: Free webinar on the NIS-2 Directive
Many companies are currently facing a decisive challenge: How can the requirements of the NIS-2 Directive be implemented concretely, efficiently and comprehensibly — during operation, with limited resources and under increasing pressure to act?
There is often a missing link between regulatory requirements and operational reality: a consistent, process-oriented approach that creates structure, clarifies responsibilities and keeps all relevant information available centrally. This is exactly where our BPM and GRC software Aeneis comes in.
In our free webinar, we'll show you how to not only keep track of things with Aeneis, but also use NIS-2 as an opportunity to sustainably strengthen your security and compliance structures.
Webinar title:
Prioritize NIS-2 correctly and confidently implement it | Webinar for executives and IT managers
Appointment:
29.04.2025 from 11:30 AM to 12:30 PM
Webinar content:
- Which companies are affected by NIS-2?
- An overview of the measures of the NIS 2 Directive
- What happens if companies do not comply with the measures? What penalties are imminent?
- How a process-oriented approach helps you reduce effort and keep processes under better control
- Live demo: How the Aeneid software solution helps you implement
- Practical tips on how to be heard internally and receive appreciation as a NIS 2 manager or responsible person (instead of annoying reactions)
Bonus for participants:
At the end of the webinar, you will receive an exclusive NIS 2 guide with a clear roadmap for implementation.
Register for the webinar now ➔
NIS-2 as an opportunity for modern governance and security
The NIS 2 Directive forces companies to act and that is exactly where the opportunity lies: Anyone who today creates clear processes, systematically assesses risks and documents evidence in a structured manner is not only compliant, but also prepared for upcoming challenges in terms of information security and digitization.
With Aeneid, the start is pragmatic, comprehensible and with strategic added value.
The good news is that NIS-2 is not a threat. It is an opportunity.
Because anyone who acts today not only creates legal certainty. Instead, it gains clarity, efficiency and trust — both internally and externally.
More information about the webinar and registration.

