← All solutions

NIS2 Readiness in 10 Days — Clarity Instead of Uncertainty

Are you in scope for NIS2? And if so, what exactly do you need to do? We tell you — with a clear roadmap instead of a jungle of legal clauses.

Request NIS2 Readiness → Check for free first: NIS2 Check →

NIS2 affects an estimated 30,000 companies in Germany — many of them without knowing it. Instead of leaving you alone with the legal text, we deliver a solid status assessment in about two weeks: are you in scope, where do you stand, and what comes next.

The Problem

NIS2 is mandatory, the deadlines are running, and management is personally liable. Most mid-sized companies don’t know whether they fall within its scope — let alone how their compliance actually stands.

How We Work

  1. Scope & Applicability We determine, based on sector, company size and supply chain, whether and how NIS2 applies to you — directly or as a supplier to an affected company.
  2. Gap & Risk Analysis We compare your current state against the NIS2 requirements and assess the risks of your critical systems — prioritised by impact, not by effort.
  3. Action Roadmap You get a prioritised plan: what comes first, roughly what it costs, what is feasible in-house and what should be supported externally.
  4. Management Briefing We summarise everything in a clear report and brief the management — including the liability NIS2 places on the leadership level.

Your Outcome

You know exactly where you stand and what to do — robust, prioritised, actionable. From a soon-to-be certified NIS2 auditor.

Who It’s For

For mid-sized companies in essential or important sectors (or their suppliers) that need clarity before deadlines and liability become real. Especially useful when no one internally has the time or specialist knowledge to translate the NIS2 text onto their own company.

Why citilan

Your analysis doesn’t come from a consultant who has never run a network, but from a practitioner with hands-on experience from numerous projects — and a soon-to-be certified NIS2 auditor. No compliance theatre, just an assessment that holds up when it matters. And you talk directly to the person who produces it.

Frequently Asked Questions

Am I even in scope for NIS2?

We clarify that in the applicability and scope analysis — directly via sector and company size, or indirectly as a supplier. You get a solid assessment instead of guesswork.

How long does the NIS2 readiness assessment take?

The core runs in about 10 working days: scope and gap analysis, a risk assessment of your critical systems, and a prioritised action roadmap including a board briefing.

Is management really personally liable under NIS2?

Yes. NIS2 obliges the management level to implement risk-management measures and holds them personally liable for failures — which is why a management report is part of the delivery.

Ready for the next step?

No call center, no sales team — you talk directly to the person who builds it.

Request NIS2 Readiness →