Skip to content

Neue Cyberresilienz-Anforderungen durch NIS-2 in Kraft: TÜV NORD GROUP empfiehlt Unternehmen zügiges Handeln

Digital & Semiconductor: New EU directive NIS-2 now in force

Ein junger Mann mit Brille und dunklem Polohemd sitzt an einem Schreibtisch in einem modernen Büro. Er arbeitet konzentriert an einem Computer mit zwei Bildschirmen, auf denen Programmiercode zu sehen ist. Vor ihm steht zudem ein aufgeklappter Laptop. Im Hintergrund befinden sich Glaswände und Regale mit Büromaterial. Die Szene wirkt professionell und technologisch geprägt.
15.10.2024

With the entry into force and application of the new EU Directive NIS-2 on October 17, 2024, the European Union is placing increased demands on the cyber resilience of companies. The EU directive is due to be transposed into national law in Germany in spring 2025. TÜVIT, a company in the TÜV NORD GROUP, is ready to support companies in adapting to these new requirements.

The NIS 2 Directive extends the circle of affected companies significantly beyond the previous KRITIS sectors and now also includes medium-sized companies operating in critical sectors. “The threat situation in cyberspace has worsened dramatically. With NIS-2, the EU is responding with a comprehensive package of measures that affects companies of all sizes,” explains Tobias Mielke, cybersecurity expert at TÜVIT.

Companies that employ more than 50 people and have an annual turnover of more than 10 million euros must check whether they fall under the directive. This covers 18 sectors, including new areas such as food production and online retail. “Every company must now actively address the requirements of NIS-2 in order to avoid high fines and potential security risks,” warns Mielke.

TÜVIT offers a free NIS-2 Affectedness Check, which helps companies to determine whether and to what extent they are affected by the directive. This first step helps companies to plan and implement the necessary security measures. It is carried out at your own risk and no guarantee is given for the accuracy, completeness or timeliness of the information provided.

“Our aim is not only to prepare companies for compliance with the directive, but also to make them more resistant to cyber attacks,” emphasizes Mielke. By implementing an information security management system (ISMS) in accordance with ISO/IEC 27001 or BSI IT-Grundschutz, many of the NIS 2 requirements can be effectively covered.

The NIS-2 directive is not only a regulatory challenge, but also an opportunity for companies to raise their cybersecurity to a new level and thus strengthen the trust of their customers and partners, Mielke continued.

For more information on the NIS-2 Affectedness Check and support from TÜVIT, please visit our website at NIS-2 Quick-Check - Check Affectedness Now | TÜVIT (tuvit-consulting.de) and www.tuvit.de/de/leistungen/informationssicherheitsmanagement/

About the TÜV NORD GROUP

(copy 1)

Founded over 150 years ago, we stand for security and trust worldwide. As a knowledge company, we have our sights firmly set on the digital future. Whether engineers, IT security experts or specialists for the mobility of the future: in more than 100 countries, we ensure that our customers become even more successful in the networked world.