NIS2 Consulting

With the NIS2 Directive of the European Union, the requirements for cybersecurity and information security for companies are being significantly tightened. The objective is to strengthen the resilience of the economy and society against cyberattacks.

In Germany, the directive has been implemented through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) and has been in force since December 2025.

Do TISAX or ISO 27001 already meet the requirements of the NIS2 Directive?

Both TISAX, as the security standard of the automotive industry, and ISO 27001, as the international standard for Information Security Management Systems (ISMS), already cover a large portion of the organizational and technical requirements of the NIS2 Directive.

An analysis by the ENX Association, comparing the TISAX ISA catalog with the requirements of the NIS2 Directive, shows a very high level of overlap. The measures required under Article 21 of NIS2 are already addressed by the TISAX questionnaire.

Companies that have already implemented an ISMS based on TISAX or ISO 27001 therefore have a very strong foundation for complying with NIS2 requirements.

Additional NIS2 requirements beyond TISAX or ISO 27001

In addition to organizational and technical security measures, NIS2 also introduces mandatory reporting processes for cyber incidents.

Companies subject to the directive must report significant security incidents to the competent national authority. In Germany, this authority is the Federal Office for Information Security (BSI).

Personen besprechen Details einer TISAX-Zertifizierung

Reporting of cyber incidents in three stages

within 24 hours

Early warning notification to the BSI

within 72 hours

Detailed report with initial information on cause and impact

within one month

Final report including analysis and corrective measures

NIS2 - Cyber ​​Incidents

These reporting obligations must be embedded within the company’s incident management process.

Which companies are affected?

The NIS2 Directive applies to organizations classified as “essential” or “important entities.” Key factors include industry sector, company size, and relevance for critical services or supply chains.

Category

Affected companies

Essential entities
Energy providers, telecommunications operators, large data centers
Important entities
Larger industrial companies, manufacturers of critical products, digital service providers
Automotive Industry
automotive manufacturers, larger suppliers, engineering and IT service providers
Typical size criteria
often more than 50 employees or more than €10 million in annual revenue

This means that companies within the automotive supply chain may also fall under the scope of the NIS2 Directive.

Steht bei Ihnen ein TISAX-Audit an?

Support by InShield Consulting

InShield Consulting supports companies in efficiently aligning the requirements of NIS2, TISAX, and ISO 27001.

Based on our experience from over 250 TISAX audits worldwide, we work with you to analyze:

This ensures that your company meets both customer requirements of the automotive industry and regulatory obligations.

Thema Ihrer Anfrage:

Subject of your inquiry: