Skip to content
REF · NIS2 · BSIG 2025

Cybersecurity is now the law. We get you ready.

NIS2 is in force, and §38 puts the duty on management personally: management must approve the measures, oversee their implementation and attend training regularly. Tasks can be delegated, responsibility cannot. awedit gives leadership the evidence, the approval trail and the reporting paths to carry out the duty traceably. Your IT leads, we ready you.

Orientation, not evidence. Not legal advice.

TIMELINE

The clock is already running.

Since 06.12.2025

NIS2UmsuCG in force, no transition period. The §30 risk-management measures apply now.

Since 06.03.2026

BSI registration deadline (06.03.2026) and grace period (31.07.2026) have passed. The BSI counts 17,945 registered entities (as of 30.06.2026). Around 29,500 are expected; the BSI has announced the next figures for the end of October.

From 06.12.2028

Earliest date the BSI can demand evidence from besonders wichtige Einrichtungen without cause (§61 (3) BSIG). Cause-based audits are possible independently of this.

Austria: The NISG 2026 applies since 01.10.2026. Registration with the Federal Office for Cyber Security by 31.12.2026, self-declaration by 30.09.2027. The self-check asks about it.

METHODOLOGY

Experts lead the review. AI accelerates it. We ready you for oversight.

There is no NIS2 certificate. Our job is defensibility: a §30 documentation with review-ready evidence your personally-liable management can approve.

  1. STEP · 01
    Scope

    Sector plus size decides whether you are in scope and in which class. Some entities are in scope regardless of size.

  2. STEP · 02
    Scan

    Your §30 measures are assessed against a real control catalog, cross-referenced to C5:2026 and ISO 27001. Experts review every finding.

  3. STEP · 03
    Arm

    You get a prioritized gap report and a §38 management-approval pack, ready for self-declaration and for a §39 audit or ISO route later.

Experts lead the review, highly specialized AI tooling accelerates it, we make you handover-ready. No tool alone achieves compliance, and there is no such thing as a NIS2 certificate. One provider to manage, a handover-ready dossier at the end.

THE SHORT GUIDE

What NIS2 actually asks of you.

A plain-English read of the parts most teams get wrong on the first pass.

Scope: automatic by sector and size

NIS2 covers 18 sectors. Absent a special rule, you are in scope at medium size: at least 50 staff, or over €10M turnover and balance-sheet total. Some entities, such as trust service and DNS providers, are in scope regardless of size.

Two classes

Besonders wichtige Einrichtungen face proactive BSI supervision; from late 2028 the BSI can demand evidence from them without cause. The recurring §39 evidence duty applies only to operators of critical facilities. Wichtige Einrichtungen face reactive supervision. Both must implement the same ten §30 measures.

The ten §30 measures

Risk analysis, incident handling, business continuity and backup, supply-chain security, secure development and vulnerability handling, effectiveness review, cyber hygiene and training, cryptography, access control and asset management, and multi-factor and secured communications.

Reporting: 24h, 72h, one month

A significant incident triggers an early warning within 24 hours, a notification within 72 hours, and a final report within one month.

Management liability

Management must approve the measures, oversee their implementation and attend training regularly. Tasks can be delegated, responsibility cannot.

No certificate, watch the claims

There is no NIS2 certificate. Nobody can sell you 'NIS2-zertifiziert'. A self-check is orientation, not evidence and not a Nachweis.

IMPLEMENTING REGULATION (EU) 2024/2690

Cloud, data centre, MSP and marketplace get more detail.

For DNS service providers, TLD registries, cloud computing services, data centres, content delivery networks, managed service providers, managed security service providers, online marketplaces, search engines, social networks and trust services, Implementing Regulation (EU) 2024/2690 applies directly alongside the BSI Act.

6.2
Secure development

Rules from specification to testing, including outsourced development.

6.5
Security testing

risk-based, documented, with handling of critical findings.

6.6
Patch management

in reasonable time, tested, from a trusted source. Deferral only with justification.

6.10
Vulnerability handling

monitor, close critical gaps without undue delay, coordinated disclosure.

30 minutes

For cloud and MSP services, a complete outage of more than 30 minutes already counts as a significant incident. Early warning to the BSI within 24 hours.

For modern teams, much of this evidence already exists in the pipeline, monitoring and tickets. Often only the mapping is missing.

From scope to steady: four steps.

  1. 01
    Self-Check

    Free, instant. Buys you clarity: which duties apply, how urgent, where the first gaps are.

  2. 02
    Scanner + Report

    Buys you the map: an expert-reviewed scan of your real product, a prioritized report the next step can use as-is.

    Expert Check from €990 · one-off, fixed price
  3. 03
    Remediation

    Buys you the shortest path: we close the gaps with you until handover.

  4. 04
    Annual cycle

    Buys you steadiness: the specifying ordinance is pending, BSI guidance keeps growing, and from late 2028 the BSI can demand evidence without cause. The cycle keeps your §30 file current before supervision asks.

READY?

Two minutes to see where you stand.

Check your scope and class, then run the §30 readiness pass. No account, no sales call. The self-check also detects whether you operate a critical facility (KRITIS) and what that adds.

A self-check result is orientation, not evidence, and does not by itself demonstrate NIS2 compliance.

Critical facility? The KRITIS path in detail →

Last checked: 1 Oct 2026

This page relies on primary sources. Figures and deadlines can change · we review them continuously.

Sources