NIS2 Guide: How 8 Chapters Lead to Compliance

The NIS2Compass NIS2 Guide walks you through 8 chapters, from registration to training, toward NIS2 compliance. What each chapter covers and how templates help.
Written by the NIS2Compass editorial team | Last updated: July 2026
The NIS2Compass NIS2 Guide takes companies through 8 sequential chapters, from the applicability check and registration to training and awareness, aligned with the minimum measures under §30 BSIG. Instead of isolated checklists, every chapter comes with matching templates. The Pre-Check shows in a few minutes where you stand.
Why Don't Loose Checklists Cut It for NIS2 Implementation?
Loose NIS2 checklists tend to fail: dependencies between measures are missing, and evidence gets gathered only shortly before an audit. According to BSI, only 15,477 of roughly 29,500 affected companies had registered by April 2, 2026, even though the statutory deadline had expired on March 6, 2026. NIS2Compass counters this fragmentation with a fixed chapter path.
The problem is rarely a lack of willingness, but a missing sequence. A risk analysis needs to come before you select measures, or there's no factual basis for priorities. Evidence then ends up scattered across spreadsheets, emails, and local folders, with nobody keeping the full picture.
On top of that, the NIS2UmsuCG has been in force since December 6, 2025, with no transition periods. All obligations have applied immediately ever since, regardless of a company's internal preparation. If you're still working through the applicability check or registration, the article Getting Started with NIS2: How to Begin Quickly and Correctly offers an entry point.
In mid-sized IT departments, loose checklists repeatedly create gaps because the sequence is missing. A clearly structured chapter path keeps evidence from going missing right before an audit.
A structured path substantially reduces the cognitive load. IT managers without compliance experience always know what comes next, instead of having to prioritize on their own. The Pre-Check shows in advance exactly where a company stands in the process.
This is precisely where the NIS2 Guide comes in: with a fixed chapter path instead of an open-ended list of tasks.
How Is the NIS2 Guide Structured Across 8 Chapters?
The NIS2 Guide breaks NIS2 compliance down into 8 sequential chapters, from applicability and registration to training and awareness. Each chapter covers one thematic building block and links to matching templates, creating a traceable path instead of an unsorted catalog of requirements.
The NIS2 Guide walks you through the following 8 chapters:
- 1. Affected Status and Registration: Clarifies sector and size criteria, the entity classification, and registration with the BSI.
- 2. Risk Management: Builds an asset inventory, a threat analysis, and a risk matrix as the foundation for the gap assessment.
- 3. Technical Security Measures: Covers access control with multi-factor authentication, cryptography, patch management, and network security.
- 4. Incident Management and Reporting Obligations: Establishes an incident response plan and the tiered BSI reporting procedure with its 24-hour, 72-hour, and one-month deadlines.
- 5. Governance and Accountability: Governs the appointment of an information security officer, security policies, management liability, and reporting to senior management.
- 6. Supply Chain Security: Captures suppliers, introduces an assessment procedure, and anchors security requirements in contracts.
- 7. Business Continuity and Crisis Management: Covers business impact analysis, an emergency plan, and a backup strategy for when things go wrong.
- 8. Training and Awareness: Builds a training program with mandatory sessions, phishing simulations, and a lasting security culture.
This sequence follows a clear logic: first clarify whether and how registration applies, then capture risks and derive technical measures and an incident process from them. Organizational anchoring through governance and supply chain comes next, before business continuity and training permanently secure operations.
Each chapter maps to a concrete implementation step under §30 (2) BSIG. The provision defines 10 statutory minimum risk management measures, including risk analysis, security incident management, business continuity, supply chain security, training, cryptography, and multi-factor authentication. This mapping creates traceability toward senior management and later audits. Matching templates from the Template Library are embedded directly into each chapter — more on that later.
What Do the Chapters on Applicability, Risk Management, and Technical Measures Cover?
The first three chapters clarify whether and how a company is affected, run a structured risk analysis, and derive technical security measures from it. According to Bitkom Wirtschaftsschutz 2025, 87 percent of German companies were affected by data theft, espionage, or sabotage in the past 12 months. Without a documented risk analysis, there's no basis for selecting the right measures.
How Does Chapter 1 Kick Off the Applicability and Registration Check?
Chapter 1 is the formal starting point of the NIS2 Guide. It checks sector and company size, sets the entity classification, and determines the responsible supervisory authority, then walks you through BSI registration via the ELSTER organization certificate and MUK account.
A detailed walkthrough of this step is available in the article Implementing NIS2 Without a Consultant: SME Guide.
What Does Chapter 2 Deliver on Risk Management?
Chapter 2 builds on the applicability check and creates the factual foundation for further measures. It includes:
- Asset inventory and protection needs analysis: capturing all relevant systems and their protection requirements
- Threat and vulnerability analysis: systematic identification of risk sources
- Risk matrix: assessment of likelihood and severity of impact
- NIS2 gap assessment: comparison against the measures under §30 (2) BSIG
Which Technical Security Measures Does Chapter 3 Bundle?
Chapter 3 translates the results of the risk analysis into concrete technical measures. The core building blocks are:
- Access control and multi-factor authentication
- Encryption and cryptography standards
- Vulnerability and patch management
- Network security and segmentation
In-depth articles on individual measures are available in the Knowledge Hub. The order here is deliberate: applicability first, then risk analysis as the basis. Only this way can technical measures be prioritized rather than implemented at random.
How Does the NIS2 Guide Handle Incident Management, Governance, and Supply Chain Security?
The middle chapters build a reporting process under §32 BSIG, anchor responsibilities in the organization, and extend the view to suppliers. The BSI situation report 2025 counted 950 ransomware reports between July 2024 and June 2025, 72 percent involving an additional data leak. A documented incident process and vetted suppliers reduce this risk.
Chapter 4 introduces incident management: it covers an incident response plan and the three-stage BSI reporting procedure under §32 BSIG — early warning within 24 hours, initial report within 72 hours, and a final report after one month. This is complemented by an incident response exercise and a forensics and post-incident process.
Chapter 5 puts governance front and center. It covers appointing an ISO or CISO, a security policy framework, and documenting management liability, including mandatory training for the leadership. Regular security reporting to senior management rounds it out.
Governance deliberately follows the operational groundwork: roles and reporting lines anchor more cleanly once risks and incident processes are already captured. Without that foundation, documented responsibilities often lead nowhere.
Chapter 6 widens the view to the supply chain. Central elements are a supplier and service provider inventory, an assessment procedure, and contractual security requirements. The underlying principle: your own security doesn't stop at the company's borders.
Inadequate governance or reporting practices have consequences, as the article on NIS2 fines shows. If you want to dig deeper into reporting obligations and governance roles, the Knowledge Hub has matching explainers. Templates such as a supplier assessment checklist and liability documentation are available for hands-on use.
What's in the Chapters on Business Continuity and Training?
The final two chapters secure operations in an emergency and permanently embed security within the workforce. ENISA analyzed 4,875 security incidents across Europe between July 2024 and June 2025; many of them could have been mitigated by emergency plans or trained staff. Together, these two chapters round out the NIS2 Guide.
What Does Chapter 7 Cover for Business Continuity and Crisis Management?
Chapter 7 starts with a business impact analysis to assess critical processes and their tolerance for downtime. This is followed by the business continuity plan, or IT emergency plan, and a backup strategy based on the 3-2-1 rule.
Regular BCM tests and crisis exercises round out the chapter. That way, an emergency stays a rehearsed routine rather than a theoretical construct.
What Does Chapter 8 Cover for Training and Awareness?
Chapter 8 walks you through designing a training program with mandatory training for employees and separate formats for the leadership level under §38 (3) BSIG. Phishing simulations add practical testing on top of the theoretical training.
The goal is a lasting security culture that outlasts individual training sessions. The Knowledge Hub has in-depth content on training concepts and BCM.
Documentation and evidence don't get their own closing chapter — they're built into every step instead, with templates and audit-proof archiving as standard. Chapters 7 and 8 thereby secure what came before: operations in an emergency, and the people who carry every measure forward.
How Do Linked Templates from the Template Library Speed Up the Process?
Every chapter of the NIS2 Guide is linked to matching Word and Excel templates from the Template Library, so companies don't have to start from scratch. For the roughly 29,500 affected companies in Germany, reusable §30-BSIG-compliant templates are a major time factor. IT managers adapt ready-made templates instead of designing documents from scratch.
The underlying principle: every template maps to a concrete implementation step under §30 BSIG, but also works independently of the NIS2 Guide. Typical examples from the library include:
- Risk matrix: structured assessment of threats and their likelihood
- Reporting process template: workflow document for timely reports to the BSI
- Training record: documentation of awareness measures for employees
- Supplier assessment checklist: basis for vetting critical suppliers
For IT departments with typically 3 to 10 people and no dedicated compliance resource, this makes a real difference: adapting an existing template takes far less time than designing a form from scratch. These pre-structured documents replace part of what classic NIS2 consultants otherwise bill by the day. For a detailed cost comparison, see NIS2 Consultant or DIY? A Cost Comparison.
Which Companies Is the NIS2 Guide the Right Starting Point For?
The NIS2 Guide especially suits IT managers and information security officers without prior compliance experience who need a solid starting point fast. According to Bitkom Wirtschaftsschutz 2025, 34 percent of companies reported ransomware damage in the past 12 months. A structured path prevents baseline measures from being overlooked. The Guide is ideal for companies with 30 to 250 employees and a small IT department.
Who benefits most: Companies without prior compliance experience and limited IT resources get a clear roadmap instead of an unwieldy catalog of requirements. Not sure whether NIS2 even applies to you? The article Am I Affected by NIS2? How to Check offers initial orientation. Even with statutory deadlines already passed, an orderly start still matters more than rushed action.
Where it doesn't fit as well: Companies already running an ISMS, for example on international ISMS tools, tend to use the NIS2 Guide as a complement. The NIS2 expertise and templates can then be adopted selectively into existing processes, rather than working through the whole path from scratch.
For highly complex edge cases, such as multiple affected sectors or foreign subsidiaries, the NIS2 Guide doesn't replace individual consulting. These cases require case-by-case legal review beyond structured self-help.
An IT service provider in the digital infrastructure sector (around 90 employees) determined during Chapter 1 (Affected Status and Registration) that it qualified as an "important entity" under the NIS2UmsuCG, and completed BSI registration in that same chapter. Its IT department (4 people) had no documented risk analysis under §30 (2) No. 1 BSIG so far. Using the NIS2 Guide, the company then worked through Chapter 2 (Risk Management) and Chapter 3 (Technical Security Measures) in about 6 weeks, relying on existing templates instead of designing documents from scratch.
The easiest way in is the Pre-Check: it shows your individual starting point before moving straight into Chapter 1 of the NIS2 Guide.
Frequently Asked Questions
What is the NIS2 Guide from NIS2Compass?
The NIS2 Guide is NIS2Compass's structured implementation path, taking companies through 8 chapters, from applicability and registration to training and awareness, toward NIS2 compliance. Each chapter is aligned with the minimum measures under §30 BSIG and linked to matching templates from the Template Library.
How long does it take to work through the entire NIS2 Guide?
Duration depends on your starting point and company size. Companies without prior documentation typically need a few weeks for the first chapters, and several months for the full path with a small IT department. The Pre-Check gives an initial estimate of your starting point and time investment.
Do I have to work through the 8 chapters in order?
The sequence follows a content-driven logic: applicability/registration and risk management form the foundation for later measures such as technical implementation or evidence. Companies with prior groundwork, for example from an existing ISMS, can skip chapters or work on them in parallel, provided that foundation is already documented.
Does the NIS2 Guide replace an NIS2 consultant?
For many SMEs, the NIS2 Guide fully covers structured self-implementation, relying on templates instead of billed consulting days. In highly complex edge cases, such as multiple sectors or international group structures, external consulting can still make sense. The article NIS2 Consultant or DIY? A Cost Comparison compares both paths.
How do the 8 chapters connect to §30 BSIG?
§30 (2) BSIG lists 10 statutory minimum risk management measures, including risk analysis, access control, cryptography, business continuity, and training obligations. The Guide's chapters group these measures thematically, so every implementation step maps to a traceable legal basis and stays verifiable toward senior management.
Implement NIS2 step by step
NIS2Compass guides you step by step through implementation – with guide, templates and knowledge hub.
Get startedÄhnliche Artikel
When Is a Security Incident Reportable? (§ 32 BSIG)
A significant security incident under § 2 no. 11 BSIG: when you have to report to the BSI, and why the 500,000 euro threshold binds only eleven types of digital service provider.
9 Min. Lesezeit
Management Self-Check under Section 38 BSIG: The Free Excel Template
Free Management Self-Check under Section 38 BSIG as an Excel template: 20 yes/no questions, 5 sections, traffic-light status, no email gate.
6 Min. Lesezeit
The Best ISMS Tool to Kick Off Strong After the 2026 Summer Lull
A comparison of the six leading ISMS tools for 2026: KaitoSec, Kertos, Vanta, Grasp, Athereon, and HiScout, with guidance on which tool fits which company profile.
11 Min. Lesezeit