NIS2 is an EU directive that applies through national law. It asks you to check whether you are in scope, register with the authority, put risk management measures in place, report significant incidents in stages and make management accountable. Teddy's agents run each step on the controls you already have.

NIS2 is Directive (EU) 2022/2555. Member states apply it through national law, Germany for example through the NIS2UmsuCG and the revised BSI Act. The core duties are the same everywhere. Here they are, and where they live in Teddy.
Sector, size and in some cases your role decide whether you are in scope, and whether you are an essential or an important entity.
Entities in scope submit their name, contact details, sector and the member states where they provide services to the national authority.
Ten measures, from risk analysis and incident handling to supply chain security, cryptography, access control and multi-factor authentication.
For significant incidents: an early warning within 24 hours, a notification within 72 hours and a final report within one month, to the CSIRT or competent authority (the BSI in Germany).
The management body approves the measures, oversees their implementation, takes part in training and can be held liable.
Authorities can audit and order measures. Maximum fines are at least €10 million or 2% of worldwide turnover for essential entities, €7 million or 1.4% for important ones.
NIS2 applies by law once you are in scope. There is no certificate to show, but the authority can audit you, and the management body answers for the measures.
Teddy checks your sector, size and each legal entity and writes down the result.
Who reports what, and by when, is agreed before anything happens.
Your management approves the measures. Teddy keeps the status and the records ready.
Legal is unsure whether you are an important entity, the incident playbook only knows internal escalation, and the board asks what it is liable for. ChatGPT can summarize the directive, but it does not know your sector, your size or your controls. Teddy checks applicability from your company model and builds the reporting process on what you already run.
Petra · LegalAre we essential or important? Our logistics unit is in Annex I.
Thomas · CFOAre we personally liable for this?
Selin · EngineeringIf we get hit on Friday night, who reports to the authority?
Andrea · CEOThe supervisory board wants a NIS2 status on Thursday.
Granite Mutual · ProcurementPlease confirm your NIS2 measures for our supplier review.
Teddy's agents check scope, map the measures and build the reporting process. Management decides, and a compliance engineer is there when the authority asks.
Sector, size and group structure decide. Teddy checks each entity from your company model and explains the result, so Legal can confirm it.
Teddy collects what the authority asks for: contact points, sector and subsector and the member states where you provide services. You review it and submit.
Each of the ten measures is mapped onto the controls you already run. You see what is covered, what is partial and what is missing, with owners.
The Policy Agent drafts the staged reporting process with roles, criteria for a significant incident and templates, linked to your existing incident response.
Controls you already run for ISO 27001, SOC 2 or TISAX® count for NIS2 too. Teddy maps every framework onto one control set and shows only what is new.
Ask in plain language whether something is reportable or what management has to decide. Teddy answers from your live program. For scope questions and supervisory audits, our compliance engineers are at your side.
Ask TeddyAre we in scope? Is this incident reportable? Teddy knows the directive and your setup.
Agents do the workApplicability, registration data, measure mapping and reporting templates, each with its source.
Our team backs you upCompliance engineers help with scope questions, registration and audits by the authority.
No. NIS2 is a legal obligation, not a certification. Authorities supervise compliance and can audit you. An ISO 27001 certificate helps you show many of the Art. 21 measures, but it does not replace duties such as registration and incident reporting.
It depends on your sector, your size and sometimes your role. Large entities in Annex I sectors are generally essential. Medium-sized entities in Annex I and entities in Annex II are generally important. National law can add cases, and Teddy checks each entity in your group.
Usually the staged reporting process, management approval and training, and parts of supply chain security. The gap audit shows it measure by measure.
Generally those of the member state where you are established, with special rules for some digital service providers. Teddy maps each entity to its national law.
Start with an applicability check and a gap audit against Art. 21.
Reviewed by Sven Moritz, former CISO · October 2026
Reporting and management processes take one to four months each. Building the security management behind them takes longest.
Applicability per entity, registration data, Art. 21 mapped onto your existing controls and a tested reporting process.
The BSI portal entry is the starting point. What the authority will look at later are the measures, the reporting process and the role of management.
If the responsible person and the portal access are only sorted out during the incident, the 24-hour window is usually gone. About half of companies have no clear cybersecurity responsibilities.
A CISO can run the program, but approval, oversight and liability stay with management. Every managing director takes the training, not just one.