Socwise logo
Expert at SOCWISE
07/16/2026

NIS2 preparation in practice: beyond compliance, with real lessons learned

Expert at SOCWISE
Real NIS2 readiness starts with knowing your systems, risks and responsibilities. See the lessons learned from practical preparation projects.

For many organizations, preparing for NIS2 is not simply a matter of documentation, but rather a comprehensive operational review. Following its implementation in Germany, the BSI’s supervisory role has expanded significantly, and numerous organizations now face new obligations in the areas of cybersecurity risk management, incident reporting, management responsibility, and auditability. According to the BSI, the regulation affects approximately 29,500 organizations in Germany that fall into the “wichtige” and “besonders wichtige Einrichtungen” categories.

Practical preparation, therefore, cannot stop at simply drafting policies. Organizations must have a clear understanding of their own systems, processes, responsible parties, supplier relationships, and risks. The foundation of successful NIS2 compliance is not whether a company “puts together the documentation,” but whether it can demonstrably implement the necessary controls.

Experience clearly shows that successful NIS2 preparation does not begin when an organization prepares its compliance documentation. Rather, it begins with the organization’s ability to clearly understand its own operations, systems, processes, areas of responsibility, and risks.

The biggest challenge: a lack of funds

A recurring issue in nearly every project was that the necessary prerequisites were only partially in place. In many cases, the system inventory was incomplete or outdated, there was no up-to-date process inventory, a comprehensive data asset inventory was not available, or it was unclear which systems fell within the scope of the preparation.

This is critical because many of the deliverables of NIS2 compliance build on one another. A risk assessment requires an accurate picture of systems and processes. Defining risk management measures requires transparency regarding business processes, IT systems, data handling, supplier relationships, and areas of responsibility. The BSI Act requires organizations classified as important or particularly important to implement appropriate, proportionate, and effective technical and organizational risk management measures.

The lesson is simple: preparation does not begin with producing documents, but with making operations transparent.

Factors determining the success of the project

During the preparatory phase, it became clear that the project’s effectiveness is determined not primarily by the professional methodology, but by the extent to which the necessary basic information is available on the client side.

The basic prerequisites for successful implementation are:

  • accurate identification of systems,
  • clear designation of responsible parties,
  • clarification of operational processes,
  • review of supplier relationships and dependencies,
  • timely provision of necessary inputs,
  • and ensuring management support and decision-making.

Where these were available, the preparatory work proceeded efficiently and predictably. Where they were not, making up for these shortcomings during the project required significant additional effort.

Another important lesson is that preparatory work is not linear: different tasks build on one another, often proceed in parallel, and individual results require continuous fine-tuning.

Expenses: more than just documentation

During the projects, it became clear that the effort is concentrated in two main areas:

  • the preparation of documents (particularly in the case of policies and procedures, due to multi-stage review and approval processes),
  • and the gathering and organization of the background information required for these.

In many cases, these two areas require resources of roughly the same magnitude.

Methodology: a solid foundation, tailored to the client

For many organizations, the NIS2 preparation period is complicated by the fact that the regulatory and supervisory environment is gradually becoming more specific in several areas, and not all requirements can be interpreted immediately and unambiguously at the level of day-to-day operations. In Germany, the supervisory role of the BSI, registration and incident reporting obligations, and the definition of organizational categories are all factors that must be taken into account during the preparation process.

The methodology must therefore be based on a solid technical foundation, but it must always be tailored to the specific organization’s operations, level of maturity, and risk profile.

There can be significant differences among various organizations in terms of:

  • in terms of size,
  • the complexity of IT operations,
  • the outsourcing ratio,
  • supplier exposure,
  • the level of regulation,
  • and cybersecurity maturity.

Preparation works well when there is a balance between best practices and the organization’s specific characteristics. Documentation that is too general does not support operations, while a system that is overly detailed but unsustainable can easily become an administrative burden.

Verifiability and audit readiness: the key to compliance

In Germany, one of the most important practical issues regarding NIS2 compliance is demonstrability. Affected organizations must not only demonstrate that they have policies and procedures in place, but also that these controls are actually enforced in day-to-day operations.

Within the BSI’s supervisory framework, up-to-date documentation, records related to controls, the functioning of incident management processes, and the organization’s ability to demonstrate how it manages cybersecurity risks therefore play a key role. The BSIG dedicates a separate chapter to regulating, among other things, obligations related to risk management, reporting, registration, evidence, and disclosure.

In many cases, the greatest difficulty does not stem from the complete absence of a given control, but rather from the fact that its operation is not properly documented, cannot be traced, or is not clearly linked to the relevant requirement. Anything that is not properly documented and supported is difficult to defend during an inspection or audit.

Evidence must therefore not exist in isolation but must be linked to a requirement, control, system, or process. A well-structured evidence base:

  • demonstrates specific operational solutions,
  • clearly indicates where the evidence is located,
  • links it to the relevant requirements,
  • and helps make the actual functioning of controls transparent.

An important principle: even controls that are not fully effective can be managed if the deviation is known, documented, assessed as a risk, and accompanied by an action plan. Often, the greatest risk is not the deficiency itself, but rather the organization’s failure to recognize, manage, or demonstrate it.

The role of artificial intelligence

During the preparation process, artificial intelligence proved to be an effective support tool, for example, in drafting and structuring tasks.

At the same time, the use of AI is only effective under professional supervision. In the case of audit materials, responses must always align with:

  • the organization’s actual operations
  • existing documentation
  • and available evidence

AI can therefore speed up the work, but it cannot replace expertise in GRC, IT security, and operations.

Management attention is a result in and of itself

One of the key benefits of NIS2 is that it elevates the issue of information security to a higher management level in many organizations. The BSI also emphasizes that NIS2 places cybersecurity at the executive level: the management of affected organizations is responsible for implementing and overseeing risk management measures, as well as for providing training related to managing cyber risks.

Of course, organizations vary in their level of maturity. The best results are achieved where there is a strong technical sponsor, an active IT or security manager, and executive support. After all, preparing for NIS2 is not just a matter for experts: it also requires organizational cooperation, decision-making, and ongoing attention.

Compliance is not a one-time project

NIS2 compliance does not end with the completion of the audit. The following are necessary for long-term operation:

  • ongoing maintenance of documentation
  • regular updates to the risk analysis
  • addressing deficiencies and risks in accordance with a development plan
  • keeping records up to date
  • operating an internal security assessment (audit) program in a risk-proportionate manner

Organizations that will be successful in the long term are those that do not rush to take action every two years just before the audit but rather integrate the requirements into their day-to-day operations. NIS2 compliance is thus not a one-time sprint, but a continuous operational and development framework.

What can organizations learn from this?

The most important message regarding NIS2 preparedness is not that it is complex, but that it requires thorough preparation.

The key to success lies in defining the exact scope, maintaining up-to-date inventories, conducting realistic risk assessments, maintaining well-structured documentation, keeping proper records, and securing management commitment—all of which, together, enable effective preparedness. An organization can truly meet these expectations effectively if it:

  • understands its own operations,
  • maintains up-to-date records,
  • establishes a clear chain of command,
  • and secures the necessary resources.

An important lesson is that the success of the preparation process is fundamentally determined by how deeply the client understands its own operations: without this understanding, the process requires significant additional work that even an external expert cannot fully compensate for. At the same time, compliance is not an end in itself, but a means to an end: the true result is when, by the end of the preparation process, the organization has a better understanding of its operations, can identify its risks more clearly, and is better equipped to develop its cybersecurity resilience.

Based on our hands-on experience with NIS2 preparation projects, our GRC team is ready to support organizations across the DACH region that fall under NIS2 obligations.

Whether your organization is just starting its readiness journey, prepare to comply with the directive, or looking to turn compliance into a sustainable security framework, we can help you assess gaps, structure the required documentation, and build a practical roadmap for long-term compliance.

Get in touch with us to discuss how we can support your NIS2 preparation.

Contact form for blog articles

Are you interested in this solution?

Fill out the form and we will contact you soon.

crossmenu
SOCWISE
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.