Stage 1 · Assessment

NIS2 Readiness Workshop

Clarity on applicability, obligations, and priorities in 1–2 days.

Duration:1–2 days
Price from:€2,900 excl. VAT
Enquirekontakt@maplee.de

from €2,900

excl. VAT · 1–2 days

Get in touch
Fixed price, fixed deliverable, fixed duration. Commission an implementation project within six months and we credit this assessment fee in full.

The NIS2 Implementation Act has been in force since December 2025. Around 30,000 companies in 18 sectors are in scope; BSI registration has closed — and for most organisations the real work is yet to begin: the ten required risk-management measures, a functioning incident-reporting process, and evidence that stands up to scrutiny.

In one to two days you get a reliable status assessment and a prioritised roadmap for the next twelve months — in a form your management can actually work with.

Who it's for

  • Executive management and IT leadership at important or particularly important facilities
  • Information security officers who need to push priorities and budgets internally
  • Suppliers of regulated companies who receive security requirements through the supply chain — even without being directly regulated themselves
  • Companies that have registered with the BSI and now need to deliver on what they declared

The situation

NIS2 obligations apply regardless of whether anyone asks. The supervisory authority can audit at any time; fines reach seven figures depending on classification — and the point that changes the mood in board meetings is that management bears personal responsibility: it must approve the risk-management measures, oversee their implementation, and complete regular training. All three must be documented.

Most companies don't fail for lack of intent, but for lack of prioritisation: the ten measure areas feel overwhelming, and without an honest maturity assessment you start at the wrong end.

How it works

  1. 01

    Before the workshop — preparation by us

    You receive a structured questionnaire and a list of documents to review (existing policies, continuity plans, supplier overview, IT documentation). We analyse these in advance so the shared time is not spent gathering facts.

  2. 02

    Block 1 — Applicability and classification

    Sector assignment, thresholds, classification as particularly important or important facility. We also clarify supply-chain applicability: requirements passed down to you by customers apply contractually even if you are not directly regulated.

  3. 03

    Block 2 — Registration and incident-reporting process

    Status of your BSI registration. Then the reporting process along the statutory deadlines: initial notification within 24 hours, follow-up within 72 hours, final report within one month. We examine whether your organisation could actually deliver that on a Friday evening — accountability, availability, escalation path, templates.

  4. 04

    Block 3 — Gap analysis of the ten risk-management measures (core)

    Maturity assessment per area with reasoning and evidence: risk analysis and security policies · incident handling · business continuity · supply-chain security · security in procurement and maintenance · effectiveness assessment · basic cyber hygiene and training · cryptography and encryption · personnel security and asset management · multi-factor authentication.

  5. 05

    Block 4 — Management obligations and liability

    What approval, oversight, and training obligations mean in practice — and how to document them in a way that holds up in an emergency.

  6. 06

    Block 5 — Prioritisation and roadmap

    Joint prioritisation of gaps by risk, effort, and deadline. The output is a 12-month roadmap with owners and effort estimates.

  7. 07

    After the workshop

    Results report within ten working days, followed by a one-hour presentation of findings — on request directly to your management.

What you receive

ErgebnisForm
Results report — applicability, maturity per measure area as traffic light, gaps with reasoning, recommendationsPDF, 15–25 pages
Prioritised 12-month roadmap — measures ranked by risk and effort, with estimatesPDF + Excel
Management summary — the liability-relevant points for executivesPDF, 2 pages
Incident-reporting brief — accountability, escalation, notification templates for 24 h / 72 h / 1 monthWord, editable
Your measures as a task list — importable to Jira; if you use the maplee ISMS mit Jira & Confluence, directly in measure managementCSV / Jira import

Details

Duration1 day compact (remote) or 2 days extended (on-site, with departments)
Participants3–8 people: executive management, IT leadership, CISO, optionally procurement and HR
Preparationapprox. 2 hours on your side (questionnaire, documents)
Price€2,900 excl. VAT compact · €4,900 excl. VAT extended incl. travel within DACH
Lead timetypically 2–3 weeks to schedule

Not included

Honesty saves you disappointment: this workshop assesses and plans — it does not implement. Not included are the implementation of the measures (that is the NIS2 implementation project), the legal assessment of your applicability — that belongs to your legal counsel — and technical testing such as penetration tests or vulnerability scans.

Frequently asked questions

Especially then. Applicability is the first block, and the answer 'You are not directly regulated, but your three largest customers will pass it down contractually' is an answer that creates planning certainty.

Interested? Get in touch.

We typically respond within one working day.

kontakt@maplee.de