NIS-2 Compliance Services

NIS-2 readiness, delivered by operators.

The German NIS2UmsuCG is in force. The BSI registration window has closed. We help mid-market and enterprise entities catch up to scope, run a defensible gap analysis, and reach a state where an audit is something to walk into rather than around.

In force
6 Dec 2025
Registration window
Closed (6 Mar 2026)
Entities in scope
~29,500 in Germany

Free scan

90-second NIS-2 self-check.

A grounded first read on where you stand. Seven yes/no questions, mapped to the core controls of Section 30 BSIG. No email gate to see the result.

FREE

NIS-2 Quick-Scan

Seven yes/no questions mapped to the core controls of Section 30 BSIG. Result on screen in 90 seconds. No email gate.

Engagement options

Five ways to engage.

Fixed scopes. Each engagement starts with a 30-minute call to confirm fit.

Entry

Free Quick-Scan

A grounded first read on scope and urgency. No paid engagement required, no email gate to see the result.

  • 7-question self-check
  • Scope orientation (bwE, wE, out of scope)
  • Three priority actions
  • Optional 30-minute scoping call
No cost
Launch the scan
Advisory

Management Advisory

Board-level advisory session on NIS-2 obligations, personal liability under Section 38 BSIG, and decision points the management body actually has to take.

  • Personal liability briefing
  • Strategic decision matrix
  • Risk-appetite alignment
  • Documented advisory record (fulfils training expectation)
Fixed scope. Fixed price after a free scoping call.
Request a quote
Implementation

Compliance Sprint

A focused implementation sprint that closes the high-priority gaps from the Readiness Assessment. Slim ISMS, working playbooks, evidence trail.

  • Quick-win control deployment (MFA, EDR, backup)
  • ISMS lite documentation set
  • Incident-response playbook
  • Supplier-security baseline
  • Internal review and handover
Project-based. Fixed price after a free scoping call.
Request a quote
Ongoing

Managed Compliance

Cortavion runs the operational substance month over month. You keep governance and accountability; we keep the evidence current and the controls operating.

  • 24/7 monitoring and response
  • Threat hunting cadence
  • Quarterly evidence packs
  • BSI reporting playbook
  • Annual ISMS review and uplift
Monthly retainer. Fixed price after a free scoping call.
Request a quote
Not sure which fits?

Tell us about your situation.

If you are not sure which engagement fits, start with the free scan or just send us a few lines about where you stand. We will reply with a short recommendation.

  • 30-minute scoping call
  • No sales pitch
  • Honest fit assessment
 
Send a short brief

Depending on your federal state, up to 50–80 % of the cost may be eligible for public funding (BAFA/state programmes) — we handle the funding navigation. Important: the application must be submitted before the engagement starts.

Implementation pathway

From unaware to audit-ready.

Six phases. Most mid-market engagements complete phases 1 to 4 inside the first three months. Phases 5 and 6 are ongoing once the foundation is set.

01

Confirm scope

Run the BSI Betroffenheitspruefung. Document the classification. Establish the legal entity in scope.

02

Register and notify

Submit registration via the BSI portal. Designate incident contact points. Catch up if the window was missed.

03

Gap analysis

Map current controls against the ten Section 30 obligations. Risk-weight every finding. Output is a closure plan, not a slide deck.

04

Quick wins

Close the exploitable gaps first. MFA, EDR, backup verification, asset inventory, incident playbook. Measurable inside 60 days.

05

Foundation

Stand up the ISMS at a scope that fits your business. Document policies. Run a first formal risk assessment. Brief management.

06

Assurance

Ongoing supplier reviews, evidence collection, internal audits, regulatory reporting. Audit-defence becomes routine.

Why Cortavion

How we work.

We advise from the position of running real cyber defence operations. The deliverables map to the law. The recommendations are testable.

01

Operator-led methodology

The same team that writes the gap analysis runs the response. Recommendations are the ones we would implement on our own networks.

02

Established SOC practice

Detection engineering, incident response, threat hunting. Tools and playbooks that exist outside the engagement, refined across many environments.

03

NIS-2 specific deliverables

Every output mapped to Section 30 BSIG obligations. Evidence packs that hold up in BSI audit conditions, not in a vendor pitch.

04

Honest about limits

Where the law requires legal counsel or sectoral expertise, we say so. Cortavion is not a one-stop shop. It is a defence operator with clear scope.

Next step

A 30-minute call. No pitch.

If we are the right fit, we will say so. If not, we will point you to someone closer to your situation. Either way, you walk out with a clearer view than you walked in.

Request a briefing