NIS2 Compliance · Essential & Important Entities

NIS2: turn the obligation into a resilient architecture

NIS2 extends cybersecurity duties to tens of thousands of companies — with personal liability for management and reporting within 24 hours. KAEMI translates the requirements into technology and runs it as a managed service.

up to €10 m or 2% of annual turnover in fines
24 h early warning after awareness
Management personally liable

What NIS2 demands — and who it applies to

The NIS2 Directive (EU 2022/2555) raises the European cybersecurity baseline substantially and is currently being transposed into national law (in Germany via the NIS2 implementation act). A few thousand obliged companies become tens of thousands — and the responsibility lands explicitly with management.

The directive distinguishes between "essential" and "important" entities depending on sector and company size — from energy, healthcare and finance through public administration to manufacturing, logistics and digital services. The core is the risk management measures of Article 21 and the staged reporting duty of Article 23. Both are above all a technical and operational task — and that is exactly what we take on.

The core areas

From regulation to architecture

01 Article 20

Governance & liability

Management must approve the risk measures, oversee their implementation and undergo training — and is personally liable for failures.

KAEMI: KAEMI delivers clear responsibilities, ongoing reporting and auditable evidence the leadership level can rely on.

02 Article 21

Risk management measures

Ten minimum measures — from risk analysis through access control, cryptography and multi-factor authentication to incident handling.

KAEMI: Zero Trust access, microsegmentation, encryption, MFA and continuous monitoring map these measures technically — as a managed service.

03 Article 23

Detection & reporting duty

Significant incidents must be reported in stages: early warning within 24 hours, report within 72 hours, final report within one month.

KAEMI: Our managed service detects and classifies incidents and provides the evidence so the deadlines are met.

04 Business continuity

Continuity & crisis management

Backup, recovery and emergency plans must ensure the business survives an incident — not just that it is detected.

KAEMI: A segmented architecture limits the damage: one compromised system does not drag down the whole company, and recovery stays manageable.

05 Supply chain

Supply chain security

NIS2 explicitly targets the security of suppliers and service providers — including the access third parties have to your systems.

KAEMI: Provider access runs through verified Zero Trust access instead of blanket VPN. KAEMI itself works contractually secured and transparent.

Reporting deadlines for significant incidents

Staged — and tight

T + 0 Detection The significant incident is noticed.
24 h Early warning First notification to the competent authority / CSIRT.
72 h Report Assessment, severity and first findings.
1 month Final report Causes, impact and countermeasures.

24 hours is short — too short to only start detecting an incident then. Our managed service delivers detection, classification and evidence before the deadline becomes a problem.

How KAEMI takes on the implementation

At the centre is Cloudflare One: on this SASE/SSE platform we implement the measures of Article 21 — Zero Trust access, Secure Web Gateway, WAF, CASB, encryption, MFA and data loss prevention, plus the continuous detection for the reporting duty of Article 23. For containment inside the network we add microsegmentation with Illumio — all as one continuous managed service, not a toolbox.

As a Cloudflare Authorized Service Delivery Partner we have a direct line into Cloudflare engineering; Illumio has named us EMEA Partner of the Year. Management and support work from Germany, contracts follow German law. Instead of an ISO 27001 claim we deliver verifiable technology and evidence your management can rely on.

Cloudflare Authorized Service Delivery Partner Illumio EMEA Partner of the Year Operations & contracts from Germany

As a managed service

How we deliver — managed service on Cloudflare One

Analysis

Establish visibility

We map applications, data flows and access — the basis for every policy and every piece of evidence.

Rollout

Set up Cloudflare One

Zero Trust Access, Secure Web Gateway, WAF, CASB and DLP on the Cloudflare platform, complemented by microsegmentation with Illumio — phased, with validation at every step.

Operations

Managed service

We monitor, configure and enforce policies — with reporting instead of a black box.

Support

Direct line to Cloudflare

As an Authorized Service Delivery Partner we escalate straight into Cloudflare engineering when needed.

Incident

Incident response

If an incident occurs, we react fast and deliver the evidence for the reporting obligation.

Assess your NIS2 readiness together

In a no-obligation conversation we map your current state along the core areas and show which technical gaps can be closed with what effort.

Book a conversation