Cybersecurity is now the law. We get you ready.
NIS2 is in force, and §38 puts the duty on management personally: management must approve the measures, oversee their implementation and attend training regularly. Tasks can be delegated, responsibility cannot. awedit gives leadership the evidence, the approval trail and the reporting paths to carry out the duty traceably. Your IT leads, we ready you.
Orientation, not evidence. Not legal advice.
The clock is already running.
NIS2UmsuCG in force, no transition period. The §30 risk-management measures apply now.
BSI registration deadline (06.03.2026) and grace period (31.07.2026) have passed. The BSI counts 17,945 registered entities (as of 30.06.2026). Around 29,500 are expected; the BSI has announced the next figures for the end of October.
Earliest date the BSI can demand evidence from besonders wichtige Einrichtungen without cause (§61 (3) BSIG). Cause-based audits are possible independently of this.
Austria: The NISG 2026 applies since 01.10.2026. Registration with the Federal Office for Cyber Security by 31.12.2026, self-declaration by 30.09.2027. The self-check asks about it.
Experts lead the review. AI accelerates it. We ready you for oversight.
There is no NIS2 certificate. Our job is defensibility: a §30 documentation with review-ready evidence your personally-liable management can approve.
- STEP · 01Scope
Sector plus size decides whether you are in scope and in which class. Some entities are in scope regardless of size.
- STEP · 02Scan
Your §30 measures are assessed against a real control catalog, cross-referenced to C5:2026 and ISO 27001. Experts review every finding.
- STEP · 03Arm
You get a prioritized gap report and a §38 management-approval pack, ready for self-declaration and for a §39 audit or ISO route later.
Experts lead the review, highly specialized AI tooling accelerates it, we make you handover-ready. No tool alone achieves compliance, and there is no such thing as a NIS2 certificate. One provider to manage, a handover-ready dossier at the end.
What NIS2 actually asks of you.
A plain-English read of the parts most teams get wrong on the first pass.
Scope: automatic by sector and size
NIS2 covers 18 sectors. Absent a special rule, you are in scope at medium size: at least 50 staff, or over €10M turnover and balance-sheet total. Some entities, such as trust service and DNS providers, are in scope regardless of size.
Two classes
Besonders wichtige Einrichtungen face proactive BSI supervision; from late 2028 the BSI can demand evidence from them without cause. The recurring §39 evidence duty applies only to operators of critical facilities. Wichtige Einrichtungen face reactive supervision. Both must implement the same ten §30 measures.
The ten §30 measures
Risk analysis, incident handling, business continuity and backup, supply-chain security, secure development and vulnerability handling, effectiveness review, cyber hygiene and training, cryptography, access control and asset management, and multi-factor and secured communications.
Reporting: 24h, 72h, one month
A significant incident triggers an early warning within 24 hours, a notification within 72 hours, and a final report within one month.
Management liability
Management must approve the measures, oversee their implementation and attend training regularly. Tasks can be delegated, responsibility cannot.
No certificate, watch the claims
There is no NIS2 certificate. Nobody can sell you 'NIS2-zertifiziert'. A self-check is orientation, not evidence and not a Nachweis.
Cloud, data centre, MSP and marketplace get more detail.
For DNS service providers, TLD registries, cloud computing services, data centres, content delivery networks, managed service providers, managed security service providers, online marketplaces, search engines, social networks and trust services, Implementing Regulation (EU) 2024/2690 applies directly alongside the BSI Act.
Rules from specification to testing, including outsourced development.
risk-based, documented, with handling of critical findings.
in reasonable time, tested, from a trusted source. Deferral only with justification.
monitor, close critical gaps without undue delay, coordinated disclosure.
For cloud and MSP services, a complete outage of more than 30 minutes already counts as a significant incident. Early warning to the BSI within 24 hours.
For modern teams, much of this evidence already exists in the pipeline, monitoring and tickets. Often only the mapping is missing.
From scope to steady: four steps.
- 01Self-Check
Free, instant. Buys you clarity: which duties apply, how urgent, where the first gaps are.
- 02Scanner + Report
Buys you the map: an expert-reviewed scan of your real product, a prioritized report the next step can use as-is.
Expert Check from €990 · one-off, fixed price - 03Remediation
Buys you the shortest path: we close the gaps with you until handover.
- 04Annual cycle
Buys you steadiness: the specifying ordinance is pending, BSI guidance keeps growing, and from late 2028 the BSI can demand evidence without cause. The cycle keeps your §30 file current before supervision asks.
Two minutes to see where you stand.
Check your scope and class, then run the §30 readiness pass. No account, no sales call. The self-check also detects whether you operate a critical facility (KRITIS) and what that adds.
A self-check result is orientation, not evidence, and does not by itself demonstrate NIS2 compliance.
Last checked: 1 Oct 2026
This page relies on primary sources. Figures and deadlines can change · we review them continuously.