Agentic compliance for NIS2

NIS2, from scope check to a reporting process that holds.

NIS2 is an EU directive that applies through national law. It asks you to check whether you are in scope, register with the authority, put risk management measures in place, report significant incidents in stages and make management accountable. Teddy's agents run each step on the controls you already have.

10 measuresMatched against what you already do
24 hoursEarly warning to the CSIRT or authority, prepared
ManagementApprovals and training documented
What NIS2 asks for

Six obligations.
Each one has a home in Teddy.

NIS2 is Directive (EU) 2022/2555. Member states apply it through national law, Germany for example through the NIS2UmsuCG and the revised BSI Act. The core duties are the same everywhere. Here they are, and where they live in Teddy.

Art. 2 and 3Scope and entity type

Sector, size and in some cases your role decide whether you are in scope, and whether you are an essential or an important entity.

In TeddyApplicability check from your company model
Art. 3(4)Registration

Entities in scope submit their name, contact details, sector and the member states where they provide services to the national authority.

In TeddyRegistration data prepared for your approval
Art. 21Risk management measures

Ten measures, from risk analysis and incident handling to supply chain security, cryptography, access control and multi-factor authentication.

In TeddyMapped onto your existing controls
Art. 23Staged incident reporting

For significant incidents: an early warning within 24 hours, a notification within 72 hours and a final report within one month, to the CSIRT or competent authority (the BSI in Germany).

In TeddyReporting process and templates, ready to use
Art. 20Management accountability

The management body approves the measures, oversees their implementation, takes part in training and can be held liable.

In TeddyDecisions and training records for management
Art. 32 to 34Supervision and fines

Authorities can audit and order measures. Maximum fines are at least €10 million or 2% of worldwide turnover for essential entities, €7 million or 1.4% for important ones.

In TeddyEvidence ready when the authority asks
Step 1Scope checkEssential, important or out of scope
Step 2RegistrationWith the national authority
Step 3MeasuresArt. 21, proportionate to your risk
OngoingReporting and oversightIncidents, supervision, management review
The problem

A law, not a certificate.
And management is accountable.

NIS2 applies by law once you are in scope. There is no certificate to show, but the authority can audit you, and the management body answers for the measures.

01Does NIS2 apply to you

Teddy checks your sector, size and each legal entity and writes down the result.

02Reporting an incident

Who reports what, and by when, is agreed before anything happens.

03Management responsibility

Your management approves the measures. Teddy keeps the status and the records ready.

04Unclear scope, a ticking clock and a board asking. Still no process.

Legal is unsure whether you are an important entity, the incident playbook only knows internal escalation, and the board asks what it is liable for. ChatGPT can summarize the directive, but it does not know your sector, your size or your controls. Teddy checks applicability from your company model and builds the reporting process on what you already run.

How it works

From “does this apply to us?” to a program you can show

Teddy's agents check scope, map the measures and build the reporting process. Management decides, and a compliance engineer is there when the authority asks.

01 Gap Audit Agent

Check applicability for every entity

Sector, size and group structure decide. Teddy checks each entity from your company model and explains the result, so Legal can confirm it.

Applicability · Acme GroupDraft
Acme Logistics · transport, Annex IImportant entity
Acme Software · no listed sectorOut of scope
Size · medium-sized enterprise180 employees
Teddy: Acme Software stays out of scope unless it provides a service listed in the annexes. I noted the reasoning for Legal.
02 Teddy

Registration data, ready to submit

Teddy collects what the authority asks for: contact points, sector and subsector and the member states where you provide services. You review it and submit.

Registration · Acme LogisticsReady
Contact pointNamed
Sector and subsectorTransport · road
Member statesDE, AT
Teddy: In Germany, registration runs through the BSI portal. Austria has its own procedure. I prepared both.
03 Gap Audit Agent

Art. 21 measures on your existing controls

Each of the ten measures is mapped onto the controls you already run. You see what is covered, what is partial and what is missing, with owners.

Art. 21(2)10 measures
Covered by existing controls8
(c) Business continuity and crisis managementPartial
(d) Supply chain securityPartial
04 Policy Agent

A reporting process that works at night

The Policy Agent drafts the staged reporting process with roles, criteria for a significant incident and templates, linked to your existing incident response.

Incident reportingArt. 23
Early warning · 24 hoursTemplate ready
Incident notification · 72 hoursTemplate ready
Final report · one monthTemplate ready
Teddy: On-call decides on significance with a checklist. Legal submits the report. Both roles are named.
05 Gap Audit Agent

Map once, comply many

Controls you already run for ISO 27001, SOC 2 or TISAX® count for NIS2 too. Teddy maps every framework onto one control set and shows only what is new.

Shared controlsOne control set
Art. 21 measures covered by ISO 270018 of 10
Evidence reused142 items
New for NIS2 onlyReporting, training
Teddy: Registration, staged reporting and management training are new for you. Most of your ISO 27001 evidence counts.
Never stuck

Is this reportable? Ask Teddy while the clock runs.

Ask in plain language whether something is reportable or what management has to decide. Teddy answers from your live program. For scope questions and supervisory audits, our compliance engineers are at your side.

1

Ask TeddyAre we in scope? Is this incident reportable? Teddy knows the directive and your setup.

2

Agents do the workApplicability, registration data, measure mapping and reporting templates, each with its source.

3

Our team backs you upCompliance engineers help with scope questions, registration and audits by the authority.

TeddyAcme Group · NIS2
Ransomware hit one depot. Do we have to report?
Likely yes. Under Art. 23(3), an incident is significant if it causes severe operational disruption or financial loss, or considerable damage to others.
  • Early warning to the CSIRT or authority (BSI in Germany)Within 24 hours
  • Incident notificationWithin 72 hours
  • Final reportWithin one month
Shall I open the early warning template and alert Legal?
Open templateAsk our team
CEYour compliance engineer helps with scope questions and supervisory audits.
FAQ

Questions about NIS2

Is there a NIS2 certificate?

No. NIS2 is a legal obligation, not a certification. Authorities supervise compliance and can audit you. An ISO 27001 certificate helps you show many of the Art. 21 measures, but it does not replace duties such as registration and incident reporting.

Are we an essential or an important entity?

It depends on your sector, your size and sometimes your role. Large entities in Annex I sectors are generally essential. Medium-sized entities in Annex I and entities in Annex II are generally important. National law can add cases, and Teddy checks each entity in your group.

We already have ISO 27001. What is missing?

Usually the staged reporting process, management approval and training, and parts of supply chain security. The gap audit shows it measure by measure.

Which country's rules apply?

Generally those of the member state where you are established, with special rules for some digital service providers. Teddy maps each entity to its national law.

Know where you stand on NIS2. Before the authority asks.

Start with an applicability check and a gap audit against Art. 21.

Reviewed by Sven Moritz, former CISO · October 2026

What to expect

How long NIS2 takes in Germany, and how Teddy cuts it to weeks

Typical6 to 18 months

Reporting and management processes take one to four months each. Building the security management behind them takes longest.

With TeddyWithin weeks

Applicability per entity, registration data, Art. 21 mapped onto your existing controls and a tested reporting process.

  • In force since 6 December 2025: registration was due by 6 March 2026, and the BSI tolerated late registrations until 31 July 2026. By the end of May 2026, about 18,500 of an estimated 29,500 entities had registered.
  • Registration: through the BSI portal with an ELSTER organization certificate. Missing or incorrect registration is an administrative offense, and changes to company data must be reported within two weeks.
  • Management training: required under §38 BSIG for every member of management. The BSI recommends yearly training.
SMSven MoritzCo-founder of Teddy, former CISOLast reviewed: October 2026
From the audit room

Where NIS2 programs fall short

  1. Registration is treated as the finish line.

    The BSI portal entry is the starting point. What the authority will look at later are the measures, the reporting process and the role of management.

  2. Nobody decided who reports at 2 a.m.

    If the responsible person and the portal access are only sorted out during the incident, the 24-hour window is usually gone. About half of companies have no clear cybersecurity responsibilities.

  3. Management delegates what it cannot delegate.

    A CISO can run the program, but approval, oversight and liability stay with management. Every managing director takes the training, not just one.