NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Weiterführende Seiten

  • Blog
  • FAQ
  • Glossar
  • Use Cases
  • Branchen
  • Preisgestaltung

Offizielle Quellen

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Ihr Navigator durch die NIS2-Compliance

Rechtliches

  • Datenschutzerklärung
  • Allgemeine Geschäftsbedingungen
  • Cookie-Richtlinie
  • Impressum

Ressourcen

  • Blog
  • Use Cases
  • Branchen
  • Preise
  • FAQ
  • Glossar

Kontakt

Kontakt

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. Alle Rechte vorbehalten.

Entwickelt in DeutschlandAllianz für Cyber-Sicherheit — Teilnehmer
Home/Blog/Implementing NIS2 Without a Consultant: A Guide for SMEs
Guide

Implementing NIS2 Without a Consultant: A Guide for SMEs

Authored by NIS2Compass Experten, NIS2 Compliance Expert
Last updated:July 1, 20268 min read
A winding path with five numbered waypoints and a compass needle leading to a protective shield – symbolising self-directed NIS2 implementation in five phases without a consultant

Implementing NIS2 without a consultant: SMEs handle around 80% of the §30 BSIG duties on their own. The five phases, the realistic effort, and when external help is genuinely needed.

NIS2 compliance can be achieved independently in many SMEs. Around 80% of the obligations under §30 BSIG are manageable without an external consultant when you use a structured guide like NIS2Compass. According to the draft NIS2UmsuCG legislation, more than 29,000 companies in Germany are affected. A consultant can be helpful, but is rarely strictly necessary. The Pre-Check shows you your starting point.

Can an SME Implement NIS2 Without a Consultant?

Yes, in most cases an SME can implement NIS2 without an external consultant. The legal requirements are publicly documented, and §30 BSIG lists ten specific minimum measures. The prerequisite is a structured implementation path and an IT team with sufficient capacity.

What a consultant provides is not exclusive, secret knowledge. Expertise, structure, and templates are based on publicly available sources: the legal text of §30 BSIG, the BSI publications on NIS2-regulated companies, and established standards such as ISO 27001 or BSI IT-Grundschutz. This content is open to every company.

The pressure to act is real. The draft NIS2UmsuCG legislation notes that around 83 percent of the roughly 30,000 affected entities have substantial catching up to do on cybersecurity. For many companies, self-implementation is therefore not only possible, but the most realistic way to close that gap quickly.

So the real question is not whether the content is available. It is: Does your internal IT team have the capacity and a clearly structured path to work through the ten minimum measures properly? This is exactly where NIS2Compass comes in, with curated expert articles, ready-made templates, and a step-by-step guide.

Before you start with implementation, you should clarify whether your company is affected at all. The Pre-Check from NIS2Compass shows you in just a few minutes where your company stands and which of the ten minimum measures are already covered.

Which 5 Phases Does Self-Directed NIS2 Implementation Involve?

Self-implementation follows five phases, from the applicability assessment to BSI registration. Each phase is manageable without a consultant when you have clear instructions. They build on one another logically and lead step by step to compliance.

  1. Clarify applicability. First, you check your sector affiliation and the thresholds: 50 employees or EUR 10 million in revenue. From this you determine whether your company is classified as an essential or important entity. The result is a documented entity classification.
  2. Risk analysis and asset inventory. You record all relevant IT assets and assess the associated threats. The basis is provided by §30 (2) BSIG No. 1. The result of this phase is a complete risk register with prioritized risks.
  3. Implement technical and organizational measures. Here you implement the 10 minimum measures under §30 (2) BSIG. These include risk management, incident handling, BCM and backup, supply chain security, access control with MFA, encryption, and training. This phase is the substantive core of the NIS2 implementation.
  4. Documentation and evidence. You create the necessary policies, processes, and evidence for each measure. Important: company management must actively approve and monitor the measures (§38 BSIG). The result is an audit-ready documentation package.
  5. BSI registration and reporting process. Registration with the BSI is mandatory under §33 BSIG and remains so even after the deadline of 6 March 2026 has passed. In parallel, you set up the three-stage reporting process under §32 BSIG: initial report within 24 hours, follow-up report after 72 hours, final report after one month.

This sequence is deliberate: without clarified applicability there is no suitable risk register, and without a risk register there are no targeted measures. NIS2Compass maps exactly these five phases as a structured implementation path and guides you through each step with ready-made templates. The guide Step by Step to NIS2 Compliance shows what this looks like in detail.

Which NIS2 Obligations Can You Handle Yourself, and With Which Tools?

SMEs can handle most of the measures from §30 BSIG on their own when a guide brings together requirement, step, and template. NIS2Compass maps the 10 minimum measures across 8 chapters. This turns a legal obligation into a workable checklist.

What you can handle yourself with instructions and templates:

  • Information security policy & risk management (§30 (2) No. 1): You define the scope, responsibilities, and a methodical risk process.
  • Asset inventory & risk register: You record your critical systems and assess risks systematically by likelihood of occurrence and impact.
  • Access control, MFA & authorization concepts (No. 9/10): You define least-privilege, introduce multi-factor authentication, and document authorizations.
  • Backup, contingency & business continuity concept (No. 4): You define RTO/RPO and describe recovery and crisis communication.
  • Incident response and reporting process (No. 2): You establish detection, escalation, and timely reporting to the BSI.
  • Awareness training & cyber hygiene (No. 7): You train staff on a recurring basis and document participation in a verifiable way.
  • Supplier security / supply chain security (No. 6): You classify suppliers and anchor security requirements contractually.
  • Documentation & record-keeping: You maintain all artifacts under version control so that you remain audit-ready toward management and the BSI.

This is not magic, but organizational diligence plus the right templates. Experience shows that SMEs with a clear implementation path handle around 80 percent of the requirements themselves. External support only remains worthwhile for a few specialized topics.

Three building blocks make this self-implementation possible. The NIS2 Guide takes you through the entire setup with 8 chapters and around 124 steps. The Knowledge Hub provides the necessary NIS2 knowledge with more than 40 expert articles, presented in an accessible way. The Template Library offers more than 45 Word and Excel templates, each assigned to a specific implementation step — all NIS2 templates in one overview.

How Much Time and Which Resources Does Self-Implementation Cost?

Realistically, expect 3 to 6 months part-time within IT, depending on your starting point. The effort amounts to roughly 400 to 800 internal person-hours in the first year. These are spread across the IT team and company management.

Who is involved? The IT manager steers the process operationally. One person takes on the role of the information security officer (ISB); this can be filled internally. Company management approves the measures and monitors their implementation.

Important: the training and monitoring obligation of company management under §38 BSIG is non-delegable. The article on the personal liability of company management under §38 BSIG explains the consequences of this.

What shortens the timeframe? Existing structures from ISO 27001 or BSI IT-Grundschutz save considerable time. So does a clear implementation path with sensible prioritization that puts the steps into a workable order, as described in the implementation path across 8 chapters.

However, an existing certification does not cover everything. Registration, reporting obligations, and the liability of company management remain NIS2-specific and must be implemented separately.

Rough distribution of effort in the first year:

  • Inventory & risk analysis: approx. 20–25% of the effort. This includes the asset inventory, protection needs assessment, and the initial risk analysis.
  • Measures & technical implementation: approx. 40%. The largest block, because this is where concrete technical and organizational measures are implemented.
  • Documentation & evidence: approx. 20%. Policies, concepts, and evidence for company management and potential audits.
  • Registration, reporting process & training: approx. 15–20%. BSI registration, setting up the reporting process, and training staff.

The effort may seem high at first. Spread across several months and contributors, it remains well manageable for an IT team of 3 to 10 people.

Where Does a NIS2 Consultant Still Make Sense?

Self-implementation has clear limits. With KRITIS classification, unclear applicability, complex supply chains, or legal liability questions, targeted external expertise is worthwhile. For SMEs, the most efficient approach is usually a hybrid model of structured self-implementation and selective consulting.

NIS2Compass deliberately does not recommend itself for every situation. In the following cases, external expertise remains indispensable:

  • Unclear applicability / sector special cases: A lawyer specializing in NIS2 provides clarity when the classification of your company is not clear-cut.
  • KRITIS classification: Operators of critical facilities have additional obligations that go beyond §30 BSIG.
  • Complex international supply chains: These require individual risk analyses rather than standard templates.
  • Penetration tests & technical audits: These require certified specialists, and no guide can replace that.
  • Legal borderline cases of management liability: For §38 liability questions, a specialist lawyer should be brought in.

Why the hybrid model? You handle the foundational work yourself in a structured way, while deploying 3 to 5 consulting days specifically for the specialized questions. NIS2Compass covers around 80 percent of the typical consulting service: structure, expertise, templates, and a clear implementation path. The budget you save then goes exactly where specialist knowledge is genuinely needed.

This produces a realistic picture of the costs. Anyone who wants to know how self-implementation and external help compare financially will find a detailed cost comparison and a breakdown of what external NIS2 consulting really costs.

"For most SMEs, the question is not whether they need a consultant, but what for. Those who handle the foundational work themselves in a structured way deploy the saved budget specifically for the specialized questions that a guide cannot cover." — NIS2Compass Experts

Case Study: A Machine Builder Implements NIS2 in 4 Months on Its Own

A machine-building company with 120 employees in North Rhine-Westphalia falls under NIS2 as part of the manufacturing sector. The IT department consists of five people, without a dedicated ISB and without ISO 27001 certification. Instead of a consulting offer of EUR 85,000, the IT team opts for structured self-implementation.

The 4-month path:

  1. Month 1 (Applicability & inventory): The team runs through the Pre-Check, determines the entity classification, and starts the asset inventory.
  2. Month 2 (Risk analysis & policies): The risk register, information security policy, and access concept are created from ready-made templates.
  3. Month 3 (Technical measures): MFA rollout, backup concept, and network segmentation are implemented; the external penetration test is purchased in a targeted manner.
  4. Month 4 (Documentation, registration & training): BSI registration (§33), reporting process (§32), and documented approval by company management (§38) follow, complemented by an awareness training.

The result: the NIS2 fundamentals are implemented in four months, and external help was only needed selectively for the penetration test. The NIS2 Guide from NIS2Compass lays out exactly this path.

Frequently Asked Questions About Implementing NIS2 Without a Consultant

Can an IT manager implement NIS2 alone?

Yes, with a structured guide and the backing of company management, this is realistic. Management can delegate operational tasks. However, the obligations under §38 BSIG remain with company management itself, including approval and monitoring of the measures.

What happens if I make a mistake during implementation?

NIS2 requires appropriate, documented measures, not perfection. What matters is comprehensible documentation and continuous improvement. A structured guide considerably reduces the risk of major gaps, because it works through the central obligations systematically.

Do I need an external ISB for NIS2?

No, the ISB function can be filled internally. External ISBs incur ongoing costs depending on the model. For many SMEs, a designated internal person with clear responsibility and a sufficient time budget is enough, provided that company management formally establishes this role.

How long does NIS2 implementation take without a consultant?

Realistically, expect 3 to 6 months part-time within IT. The exact timeframe depends on the maturity of your existing security structures. Existing ISO 27001 or BSI IT-Grundschutz structures considerably shorten the implementation, since many measures already exist in documented form.

Which NIS2 tasks should I definitely not do myself?

Penetration tests, legal assessments of sector affiliation, and complex supply chain analyses require specialist knowledge. You are better off purchasing these tasks externally in a targeted way. Everything else can be handled in a structured, self-directed manner, such as policies, the asset inventory, and the reporting process.

Implement NIS2 step by step

NIS2Compass guides you step by step through implementation – with guide, templates and knowledge hub.

Get started

Ähnliche Artikel

guide

The KRITIS Umbrella Act and NIS2: What Applies to Whom?

Since July 2026, around 2,000 KRITIS operators must register in addition to NIS2. Who needs to comply with NIS2, the KRITIS Umbrella Act, or both — sectors, deadlines, and fines explained.

7 Min. Lesezeit

guide

NIS2 ISO 27001 Mapping: Excel Checklist Download

ISO 27001 covers approximately 70% of NIS2 requirements. The mapping Excel shows at a glance what is already covered — and where the regulatory gap remains.

6 Min. Lesezeit

guide

NIS2 BSI Registration: Missed the Deadline — What Now?

The statutory NIS2 registration deadline has expired, but the BSI is granting an extended deadline until 31 July 2026. How to complete your registration in the BSI portal step by step.

9 Min. Lesezeit

Back to Blog