NIS2 Implementation Act · Executive management · Cyber Resilience

NIS2 is in force.
Is your executive management already personally liable?

The obligations are in effect, and management is personally responsible. Check in three minutes whether your organisation is affected and where the largest gaps are.

up to €10 millionor 2 percent of revenue, as a fine for serious violations.Source: NIS2UmsuCG
personallyManagement is liable and must participate in mandatory training.Leadership level

What applies now

Three issues on the executive management agenda

NIS2 is no longer purely an IT topic. Legal position, obligations and liability directly affect the leadership level.

01 · The legal position6 March 2026

Deadline passed, obligations in effect

The law applies without a transition period. KRITIS hospitals automatically qualify as particularly important entities; §391 SGB V also applies to all hospitals.

02 · The ten obligations10

From risk management to reporting

Risk analysis, incident handling, business continuity, supply chain, access control, cryptography, training and effectiveness reviews.

03 · The PEC pathOPSWAT

Close obligations, fund costs

We clarify applicability and classification, close the gap between obligation and evidence, and assess funding eligibility through the KHTF.

For executive management

NIS2 compliance checklist

You have your initial assessment. The checklist puts obligations, deadlines and liability questions on one page, understandable for leadership, not just IT.

  • Your classification and what it specifically triggers
  • The ten obligations with traffic-light status and the most common gaps
  • What personal liability for executive management means
  • Assessment path for whether measures are eligible for KHTF funding
PDF NIS2 compliance checklist for executive management

Request checklist

Plus an individual assessment from a PEC expert.

We will send your request to PEC Healthcare by email. Your calculator settings will be included.
✓ Thank you. The form endpoint will be connected for the live version.

What PEC stands for

Care continuity before technology

Digital risks in healthcare are more than an IT issue. PEC connects NIS2, cyber resilience and operational crisis capability so your organisation can continue to act even during disruptions.

Service2 to 4 weeks

Cyber Resilience Check

Make critical risks to care and operations visible: risk profile, prioritised measures and management summary.

Service6 to 8 weeks

NIS2 Readiness

Structured NIS2 assessment with gap analysis, governance and role model, and prioritised implementation roadmap.

PartnershipOPSWAT

Technology meets organisation

Together with OPSWAT, we build technical and organisational resilience: protection of critical systems, restart and emergency concepts.

How we work

Care continuity before technology, stability before complexity, practical relevance instead of theory, implementation during ongoing operations.

Part of the PEC Group

Experience from transformation and operational stability, focused on healthcare.

Locations

Stuttgart, Munich, Friedrichshafen, Düsseldorf, Wolfsburg, Bremen, plus Detroit.

Frequently asked questions

What leadership wants to know first

Are we affected at all?

That depends on the type and size of the organisation. KRITIS hospitals are automatically particularly important entities. Independently of that, §391 SGB V requires all hospitals to maintain state-of-the-art IT security.

What happens if we missed the deadline?

The obligations continue to apply, and a missed registration is itself subject to fines. What matters now is to catch up in a structured way and provide evidence.

Is executive management really personally liable?

Yes. The law makes management responsible for implementing and monitoring risk measures and requires them to participate in training.

Can we get KHTF funding for the measures?

In many cases, yes. IT security is an explicit funding category under the Hospital Transformation Fund. We assess eligibility and shape the project accordingly.

You now know your risk.
Let’s close the gap.

30-minute NIS2 assessment with a PEC expert. Clear, confidential and with no obligation.

Book an assessment