NIS2 Implementation Act · Executive management · Cyber Resilience
NIS2 is in force.
Is your executive management already personally liable?
The obligations are in effect, and management is personally responsible. Check in three minutes whether your organisation is affected and where the largest gaps are.
What applies now
Three issues on the executive management agenda
NIS2 is no longer purely an IT topic. Legal position, obligations and liability directly affect the leadership level.
Deadline passed, obligations in effect
The law applies without a transition period. KRITIS hospitals automatically qualify as particularly important entities; §391 SGB V also applies to all hospitals.
From risk management to reporting
Risk analysis, incident handling, business continuity, supply chain, access control, cryptography, training and effectiveness reviews.
Close obligations, fund costs
We clarify applicability and classification, close the gap between obligation and evidence, and assess funding eligibility through the KHTF.
For executive management
NIS2 compliance checklist
You have your initial assessment. The checklist puts obligations, deadlines and liability questions on one page, understandable for leadership, not just IT.
- Your classification and what it specifically triggers
- The ten obligations with traffic-light status and the most common gaps
- What personal liability for executive management means
- Assessment path for whether measures are eligible for KHTF funding
What PEC stands for
Care continuity before technology
Digital risks in healthcare are more than an IT issue. PEC connects NIS2, cyber resilience and operational crisis capability so your organisation can continue to act even during disruptions.
Cyber Resilience Check
Make critical risks to care and operations visible: risk profile, prioritised measures and management summary.
NIS2 Readiness
Structured NIS2 assessment with gap analysis, governance and role model, and prioritised implementation roadmap.
Technology meets organisation
Together with OPSWAT, we build technical and organisational resilience: protection of critical systems, restart and emergency concepts.
Care continuity before technology, stability before complexity, practical relevance instead of theory, implementation during ongoing operations.
Experience from transformation and operational stability, focused on healthcare.
Stuttgart, Munich, Friedrichshafen, Düsseldorf, Wolfsburg, Bremen, plus Detroit.
Frequently asked questions
What leadership wants to know first
Are we affected at all?
That depends on the type and size of the organisation. KRITIS hospitals are automatically particularly important entities. Independently of that, §391 SGB V requires all hospitals to maintain state-of-the-art IT security.
What happens if we missed the deadline?
The obligations continue to apply, and a missed registration is itself subject to fines. What matters now is to catch up in a structured way and provide evidence.
Is executive management really personally liable?
Yes. The law makes management responsible for implementing and monitoring risk measures and requires them to participate in training.
Can we get KHTF funding for the measures?
In many cases, yes. IT security is an explicit funding category under the Hospital Transformation Fund. We assess eligibility and shape the project accordingly.
You now know your risk.
Let’s close the gap.
30-minute NIS2 assessment with a PEC expert. Clear, confidential and with no obligation.
Book an assessment