Solution · NIS2 & compliance

NIS2 is in force. Is your security something you can prove?

Around 30,000 companies in Germany fall under NIS2 – and executive management is personally liable. “We’re basically secure” will not satisfy any regulator. We take you from gut feeling to documented evidence.

What is at stake

Personal liability

NIS2 explicitly holds executive management responsible – delegation alone does not discharge that duty. What is required is demonstrable implementation.

Fines running into millions

Depending on your category, substantial penalties apply – on top of the reputational damage when an incident becomes public.

Customers demand evidence

Even suppliers outside the scope of NIS2 are increasingly asked by their customers for security evidence – compliance is becoming a competitive factor.

Free quick check

Where do you stand? 8 questions, 2 minutes.

An honest rapid test against the core requirements of Art. 21 NIS2 – anonymous until you see your result.

The solution

The route to NIS2 readiness – in five building blocks

Not a mammoth project but a structured roadmap. Each building block delivers verifiable progress.

1 · Establish asset transparency

NIS2 starts with your inventory: you can only protect – and prove – what you know about. Our own Deskcenter software records every asset automatically, creating the data foundation for everything that follows.

Our product: Deskcenter Asset Management →

2 · Establish where you stand

A cyber security assessment workshop or a compact IT health check: scope, risks and gaps – documented with a prioritised action plan.

Technical details: assessment →

3 · Implement the technical obligations

Firewall, endpoint protection, email security, MFA and tested backups – operated as managed services rather than installed once and forgotten.

Technical details: security services →

4 · Be able to detect & report

Proactive monitoring and SIEM & SOAR with use cases derived directly from NIS2 – including a reporting process that meets the deadlines.

Technical details: SIEM & SOAR →

5 · Provide ongoing evidence

Audit-ready reports, documented configuration baselines and quarterly reviews – the evidence comes from day-to-day operations, not from night shifts before the audit.

Technical details: managed services →

Why mosaic IT?

Honest advice

We also tell you what is NOT mandatory. No scaremongering, no certificate myths – just a plan that stands up to auditors.

Everything from a single provider

Assessment, implementation, operations and evidence: one contract, one dedicated contact, 200+ person-years of experience.

Evidence included

Every one of our managed services comes with the documentation built in – reports, logs and reviews that auditors accept.

In practice

What the outcome looks like

Reference project: automotive dealership group, 5 sites, approximately 450 users

Starting point: Flat networks secured differently at each site – no uniform, demonstrable security level across the five sites.

Solution: Network segmentation, WatchGuard clusters at all five sites, multi-factor authentication plus MDR and NDR for detection – operated as a managed service.

Result: A uniform, documented security level: segmented networks limit spread in the event of an attack, proactive detection, operations monitored, patched and documented audit-ready.

The numbers that make the case

Cyberattacks cause around €202 billion in damage in Germany every year – part of €289.2 billion in total economic damage (Bitkom 2025) – and a third of companies have already been hit by ransomware. Set against that: a predictable monthly amount:

Without managed security With mosaic IT
Costs Unpredictable – potentially existential in the event of an incident Fixed package price per month
Evidence for the audit Night shifts and nail-biting Reports at the touch of a button, generated continuously
Response in an emergency During office hours, when someone is free Defined response times per SLA
IT team Tied up in day-to-day operations Free for value-adding projects

Frequently asked questions

Are certified training courses or specific products mandatory?
No. NIS2 requires appropriate, demonstrable measures – not a specific product or a certificate. Anyone claiming otherwise is trying to sell you something. What counts is the documentation.

When does NIS2 apply to us?
The directive is in force and is being transposed into national law. Whether you are in scope depends on sector and size (roughly: from 50 employees or €10 million in revenue in one of the 18 sectors). Determining your scope is part of our assessment.

How long does the road to readiness take?
From assessment to a solid security baseline typically takes weeks, not years – the building blocks are managed services that we bring into operation quickly.

What does it cost?
Each building block has transparent package pricing (published on the service pages). After the health check you receive a specific calculation for your environment.

We already run security products – isn’t that enough?
Installed software is not the same as protection. NIS2 asks about operations: who monitors, patches, tests and documents? That is exactly the gap we close.

Further reading

Excel tool

NIS2 Self-Assessment

30 questions · live scoring · action plan

The detailed status assessment against the 10 NIS2 requirements – including a benchmark comparison.

Request the tool free of charge
Blog article

NIS2 checklist for mid-sized businesses

6 min read · freely available

Am I in scope – and what needs to be done? The two screening questions and 8 preparation steps.

Read the article

From gut feeling to evidence – let’s get started

In a free initial consultation we clarify your scope, your priorities and the fastest route to readiness.

Free IT health check

Where does your IT really stand? Our structured IT health check reveals risks, gaps and opportunities – concise, clear and with no strings attached.

Go to the IT health check →