Everything you need to know about our IT consultancy services.
The NIS-2 Implementation Act has come into force – are you affected?
The NIS-2 Implementation Act has been in force since 6 December 2025 and sets new standards for cyber and information security in Germany. Under the Act, binding legal obligations now apply to a significantly larger number of organisations. For the first time, around 30,000 organisations are required to implement comprehensive technical and organisational security measures to protect their networks and information systems.
From risk management systems and attack detection to strict reporting requirements – these requirements are designed to ensure a consistent and appropriate level of security across the EU.
Make proactive use of the new NIS 2 requirements – not only to meet your compliance obligations, but also to strengthen your cyber security in the long term.
Companies in the spotlight: risks in cyberspace
Every day, sensitive information is exchanged that is exposed to risks in cyberspace. Whether they are small and medium-sized enterprises or global corporations, every company is a potential target for cybercriminals.
The NIS 2 Implementation Act: How to improve your cyber security with GKK
The entry into force of the Act marks the start of a new phase in cybersecurity regulation in Germany: it provides greater legal certainty, whilst at the same time increasing the responsibilities of company management and extending information security obligations to a large number of small and medium-sized enterprises.
Failure to comply with the prescribed measures may not only result in substantial fines for the company, but may also lead to personal liability claims against the management.
Our chartered accountants and certified IT specialists at GKK IT-Consulting can assist you with a NIS 2 impact assessment and the subsequent implementation of the statutory NIS 2 requirements.
What we offer
Impact analysis
We analyse your business areas and business units against the complex, defined criteria of the BSIG (as amended). In doing so, we take into account not only potential immediate applicability but also IT security-related due diligence requirements, which increasingly arise from business relationships with regulated clients and may become contractually relevant. We summarise the results clearly in a management letter, thereby providing an appropriate basis for decision-making.
GAP analysis
In the event that your organisation is affected, we will carry out a NIS-2 GAP analysis to assess how well your organisation is already prepared to meet the specified requirements and what steps are still needed to fully comply with the legal requirements.
NIS-2 Governance & Implementation of Measures
We support you in the efficient management and coordination of NIS 2 measures, so that your organisation can meet the requirements quickly and effectively. In doing so, we assist you in the successful implementation and documentation of the required measures.
Reporting
We design a reporting process to the supervisory authority that is tailored to your needs and integrate it into your existing incident and crisis management processes.
Workshops & Training Courses
We offer training courses and workshops on cyber security, tailored to your specific needs, to ensure that you and your team are as well prepared as possible to face the challenges you currently face.