Skip to content
EN
Book a demo
Standards / NIS2

NIS2 software: applicability, implementation and evidence in one system

Complaica brings the requirements of §30 BSIG together with your ISMS, your risks and your evidence — on the same data set as ISO 27001.

Book a demo Check your NIS2 status
01

Applicability

Sector, size and category determine which duties apply.

SectorThresholdCategory
Energy, transport, water, health from 50 employees or €10m turnover important entity
Energy, transport, water, health from 250 employees or €50m turnover essential entity
Digital infrastructure, ICT services size-independent in some segments essential entity
Operators of critical installations (KRITIS) thresholds under BSI-KritisV plus §8a evidence

Legal basis: NIS2 Directive (EU) 2022/2555 · BSIG · BSI

02

The ten requirements of §30 BSIG

The structure of the requirements and the module Complaica covers them with. No normative text — structure and evidence only.

No. Requirement Module Evidence Status
01 Risk analysis and security policies Risk management Risk register, gross/net assessment ● covered
02 Handling of security incidents Incident management Reporting chain, deadlines, logs ● covered
03 Business continuity, backup BCM (BSI 200-4) BIA, contingency plans, drill records ● covered
04 Supply chain security Supplier management Assessment, contracts, evidence ● covered
05 Security in development and maintenance ISMS requirements Controls with review date ● covered
06 Assessment of effectiveness Metrics and reports Maturity level, audit report ● covered
07 Training and cyber hygiene Training management Attendance records ● covered
08 Cryptography and encryption Control catalogue Configuration baselines ● covered
09 Access control and asset management Scope and assets Asset inventory, roles ● covered
10 Authentication, secured communication Control catalogue Technical evidence ● covered
03

Synergies

If you already run ISO 27001, you meet a large part of §30 BSIG — the question is which part.

Complaica maps every requirement to all the standards it touches. Row by row you see what the control counts towards — and which NIS2 requirements are still without evidence.

ISO 27001 → §30 BSIGIT-Grundschutz → §30 BSIGB3S → §8a BSIG
A.5.7 Threat intelligence
implemented 3 pieces of evidence reviewed 04/2026
ISO 27001NIS2 §30TISAXB3S
04

Incident, deadline, log

Reporting duties are activities with deadlines and owners — not a separate mailbox.

Evidence for A.8.16 Generate audit report
SIEM review minutes Q1/2026 PDF 12.03.2026 ✓ valid
Training records, operations XLSX 02.02.2026 ✓ valid
Firewall configuration baseline PDF 28.01.2026 ⚠ expiring
05

Frequently asked questions

Does NIS2 apply to us?

Applicability follows from sector, size and activity. The applicability check takes you to a defensible answer in six to eight questions — no registration.

Is an ISO 27001 certificate enough for NIS2?

It covers a substantial part of the requirements in §30 BSIG, but replaces neither registration nor the reporting and evidence duties. Complaica shows the gap as a list of open requirements.

How are reporting duties supported?

Incidents are recorded with timestamps, deadlines and owners; the reporting chain is held as an activity and logged.

What about registration with the BSI?

The duty to register exists independently of the software. Complaica holds the details you need on entity, sector and contacts.

Is management personally liable?

The BSIG addresses the management level explicitly, including oversight and training duties. That is why the status report is built for a management view.

How long does implementation take?

For a defined scope, the first defensible status reports are typically available after a few weeks. Migrating existing spreadsheets is included in the price.

06

30 minutes, your standards, your scope.

No sales pitch
A demo on your use case, not on sample data
Reply within one business day
Your data is never passed to third parties

By submitting you agree to the privacy policy.

Book a demo