NIS2 software: applicability, implementation and evidence in one system
Complaica brings the requirements of §30 BSIG together with your ISMS, your risks and your evidence — on the same data set as ISO 27001.
Applicability
Sector, size and category determine which duties apply.
| Sector | Threshold | Category |
|---|---|---|
| Energy, transport, water, health | from 50 employees or €10m turnover | important entity |
| Energy, transport, water, health | from 250 employees or €50m turnover | essential entity |
| Digital infrastructure, ICT services | size-independent in some segments | essential entity |
| Operators of critical installations (KRITIS) | thresholds under BSI-KritisV | plus §8a evidence |
Legal basis: NIS2 Directive (EU) 2022/2555 · BSIG · BSI
The ten requirements of §30 BSIG
The structure of the requirements and the module Complaica covers them with. No normative text — structure and evidence only.
| No. | Requirement | Module | Evidence | Status |
|---|---|---|---|---|
| 01 | Risk analysis and security policies | Risk management | Risk register, gross/net assessment | ● covered |
| 02 | Handling of security incidents | Incident management | Reporting chain, deadlines, logs | ● covered |
| 03 | Business continuity, backup | BCM (BSI 200-4) | BIA, contingency plans, drill records | ● covered |
| 04 | Supply chain security | Supplier management | Assessment, contracts, evidence | ● covered |
| 05 | Security in development and maintenance | ISMS requirements | Controls with review date | ● covered |
| 06 | Assessment of effectiveness | Metrics and reports | Maturity level, audit report | ● covered |
| 07 | Training and cyber hygiene | Training management | Attendance records | ● covered |
| 08 | Cryptography and encryption | Control catalogue | Configuration baselines | ● covered |
| 09 | Access control and asset management | Scope and assets | Asset inventory, roles | ● covered |
| 10 | Authentication, secured communication | Control catalogue | Technical evidence | ● covered |
Synergies
If you already run ISO 27001, you meet a large part of §30 BSIG — the question is which part.
Complaica maps every requirement to all the standards it touches. Row by row you see what the control counts towards — and which NIS2 requirements are still without evidence.
Incident, deadline, log
Reporting duties are activities with deadlines and owners — not a separate mailbox.
| SIEM review minutes Q1/2026 | 12.03.2026 | ✓ valid | |
| Training records, operations | XLSX | 02.02.2026 | ✓ valid |
| Firewall configuration baseline | 28.01.2026 | ⚠ expiring |
Frequently asked questions
Does NIS2 apply to us?
Applicability follows from sector, size and activity. The applicability check takes you to a defensible answer in six to eight questions — no registration.
Is an ISO 27001 certificate enough for NIS2?
It covers a substantial part of the requirements in §30 BSIG, but replaces neither registration nor the reporting and evidence duties. Complaica shows the gap as a list of open requirements.
How are reporting duties supported?
Incidents are recorded with timestamps, deadlines and owners; the reporting chain is held as an activity and logged.
What about registration with the BSI?
The duty to register exists independently of the software. Complaica holds the details you need on entity, sector and contacts.
Is management personally liable?
The BSIG addresses the management level explicitly, including oversight and training duties. That is why the status report is built for a management view.
How long does implementation take?
For a defined scope, the first defensible status reports are typically available after a few weeks. Migrating existing spreadsheets is included in the price.