NIS-2 Compliance Services
The German NIS2UmsuCG is in force. The BSI registration window has closed. We help mid-market and enterprise entities catch up to scope, run a defensible gap analysis, and reach a state where an audit is something to walk into rather than around.
Free scan
A grounded first read on where you stand. Seven yes/no questions, mapped to the core controls of Section 30 BSIG. No email gate to see the result.
Engagement options
Fixed scopes. Each engagement starts with a 30-minute call to confirm fit.
A grounded first read on scope and urgency. No paid engagement required, no email gate to see the result.
A structured gap analysis against the ten obligation areas of Section 30 BSIG, with an actionable closure plan and management briefing pack.
Board-level advisory session on NIS-2 obligations, personal liability under Section 38 BSIG, and decision points the management body actually has to take.
A focused implementation sprint that closes the high-priority gaps from the Readiness Assessment. Slim ISMS, working playbooks, evidence trail.
Cortavion runs the operational substance month over month. You keep governance and accountability; we keep the evidence current and the controls operating.
If you are not sure which engagement fits, start with the free scan or just send us a few lines about where you stand. We will reply with a short recommendation.
Depending on your federal state, up to 50–80 % of the cost may be eligible for public funding (BAFA/state programmes) — we handle the funding navigation. Important: the application must be submitted before the engagement starts.
Implementation pathway
Six phases. Most mid-market engagements complete phases 1 to 4 inside the first three months. Phases 5 and 6 are ongoing once the foundation is set.
Run the BSI Betroffenheitspruefung. Document the classification. Establish the legal entity in scope.
Submit registration via the BSI portal. Designate incident contact points. Catch up if the window was missed.
Map current controls against the ten Section 30 obligations. Risk-weight every finding. Output is a closure plan, not a slide deck.
Close the exploitable gaps first. MFA, EDR, backup verification, asset inventory, incident playbook. Measurable inside 60 days.
Stand up the ISMS at a scope that fits your business. Document policies. Run a first formal risk assessment. Brief management.
Ongoing supplier reviews, evidence collection, internal audits, regulatory reporting. Audit-defence becomes routine.
Why Cortavion
We advise from the position of running real cyber defence operations. The deliverables map to the law. The recommendations are testable.
The same team that writes the gap analysis runs the response. Recommendations are the ones we would implement on our own networks.
Detection engineering, incident response, threat hunting. Tools and playbooks that exist outside the engagement, refined across many environments.
Every output mapped to Section 30 BSIG obligations. Evidence packs that hold up in BSI audit conditions, not in a vendor pitch.
Where the law requires legal counsel or sectoral expertise, we say so. Cortavion is not a one-stop shop. It is a defence operator with clear scope.
Next step
If we are the right fit, we will say so. If not, we will point you to someone closer to your situation. Either way, you walk out with a clearer view than you walked in.
Request a briefing