NIS2 Compliance · Essential & Important Entities
NIS2: turn the obligation into a resilient architecture
NIS2 extends cybersecurity duties to tens of thousands of companies — with personal liability for management and reporting within 24 hours. KAEMI translates the requirements into technology and runs it as a managed service.
What NIS2 demands — and who it applies to
The NIS2 Directive (EU 2022/2555) raises the European cybersecurity baseline substantially and is currently being transposed into national law (in Germany via the NIS2 implementation act). A few thousand obliged companies become tens of thousands — and the responsibility lands explicitly with management.
The directive distinguishes between "essential" and "important" entities depending on sector and company size — from energy, healthcare and finance through public administration to manufacturing, logistics and digital services. The core is the risk management measures of Article 21 and the staged reporting duty of Article 23. Both are above all a technical and operational task — and that is exactly what we take on.
The core areas
From regulation to architecture
Governance & liability
Management must approve the risk measures, oversee their implementation and undergo training — and is personally liable for failures.
KAEMI: KAEMI delivers clear responsibilities, ongoing reporting and auditable evidence the leadership level can rely on.
Risk management measures
Ten minimum measures — from risk analysis through access control, cryptography and multi-factor authentication to incident handling.
KAEMI: Zero Trust access, microsegmentation, encryption, MFA and continuous monitoring map these measures technically — as a managed service.
Detection & reporting duty
Significant incidents must be reported in stages: early warning within 24 hours, report within 72 hours, final report within one month.
KAEMI: Our managed service detects and classifies incidents and provides the evidence so the deadlines are met.
Continuity & crisis management
Backup, recovery and emergency plans must ensure the business survives an incident — not just that it is detected.
KAEMI: A segmented architecture limits the damage: one compromised system does not drag down the whole company, and recovery stays manageable.
Supply chain security
NIS2 explicitly targets the security of suppliers and service providers — including the access third parties have to your systems.
KAEMI: Provider access runs through verified Zero Trust access instead of blanket VPN. KAEMI itself works contractually secured and transparent.
Reporting deadlines for significant incidents
Staged — and tight
24 hours is short — too short to only start detecting an incident then. Our managed service delivers detection, classification and evidence before the deadline becomes a problem.
How KAEMI takes on the implementation
At the centre is Cloudflare One: on this SASE/SSE platform we implement the measures of Article 21 — Zero Trust access, Secure Web Gateway, WAF, CASB, encryption, MFA and data loss prevention, plus the continuous detection for the reporting duty of Article 23. For containment inside the network we add microsegmentation with Illumio — all as one continuous managed service, not a toolbox.
As a Cloudflare Authorized Service Delivery Partner we have a direct line into Cloudflare engineering; Illumio has named us EMEA Partner of the Year. Management and support work from Germany, contracts follow German law. Instead of an ISO 27001 claim we deliver verifiable technology and evidence your management can rely on.
As a managed service
How we deliver — managed service on Cloudflare One
Establish visibility
We map applications, data flows and access — the basis for every policy and every piece of evidence.
Set up Cloudflare One
Zero Trust Access, Secure Web Gateway, WAF, CASB and DLP on the Cloudflare platform, complemented by microsegmentation with Illumio — phased, with validation at every step.
Managed service
We monitor, configure and enforce policies — with reporting instead of a black box.
Direct line to Cloudflare
As an Authorized Service Delivery Partner we escalate straight into Cloudflare engineering when needed.
Incident response
If an incident occurs, we react fast and deliver the evidence for the reporting obligation.
Assess your NIS2 readiness together
In a no-obligation conversation we map your current state along the core areas and show which technical gaps can be closed with what effort.
Book a conversationGo deeper