Starting point
NIS-2 brings roughly 29,000 German companies under a cybersecurity regime for the first time. Most of them are mid-sized businesses with no security department, and their management is now personally liable for approving and overseeing the measures (§ 38 BSIG). Three questions arrive at the same time and in the wrong order: are we even in scope? What do the ten measure areas mean for us concretely? And how do we prove it to an auditor?
The consultancy had been answering those questions in engagements, and the answers lived where consulting answers usually live: in spreadsheets. A decision tree for the scoping question, a measure catalogue with hundreds of implementation steps, a self-assessment questionnaire — all correct, all maintained by hand, and none of it usable by a company without a consultant in the room. They wanted a product that does the first consultation for free, in the browser, without a sign-up — and then turns into the tool the company implements NIS-2 with.
Solution
The public entry point is a guided check along § 28 BSIG: sector, company size, revenue and balance sheet establish whether the company is in scope and whether it counts as an important or a particularly important entity. Companies in scope continue into a GAP self-assessment of 23 questions, and every no becomes a task. Before registering, the visitor already sees the plan of measures that registration will create; registration then creates the tenant, the first admin and that plan in one step. The whole path takes about ten minutes and costs nothing.
The consultancy's spreadsheet catalogue was imported with a purpose-built parser and became reference data: 61 measures across the ten BSIG measure areas, 725 implementation steps and the criteria that decide which measure applies to which company — 14 sectors, size, revenue and balance-sheet bands and the NIS-2 classification. Administration screens let the consultancy maintain all of it without a developer. As the BSIG and the BSI guidance evolve, that is a content change, not a release.
Inside the platform each measure is a task with sub-tasks on a kanban board: priority, assignee, due date, status, a review step before done, and comments. Changes reach every open browser over WebSockets, notifications and a daily digest keep owners informed, and progress is measured per measure, per area and overall for reporting to management. Every change is written to an append-only history with the state before and after; deletion is only ever a flag.
The NIS-2 assistant is a retrieval-augmented chat: the BSIG, the BSI IT-Grundschutz compendium and ISO/IEC 27001 material are stored as vectors, and every answer is generated from the passages that match the question. It is opened from a task, so “how do we implement this?” is answered for this measure in this company. Conversations stay per task and per tenant and never cross a company boundary.
For the supply chain the platform models the requirement of Art. 21(3) directly: a supplier register, a structured assessment per supplier with a risk score, recorded treatment of high risks, a contractual checklist with evidence uploads and a review cycle with reminders. The supply chain measure cannot be closed while a critical supplier has no valid assessment. The audit report for the authority, the auditor and internal committees is rendered server-side as a PDF from live data — plan of measures, state of implementation, ownership and supplier register included.
- Free scoping check along § 28 BSIG, no sign-up, about ten minutes
- Measure catalogue with 61 measures and 725 implementation steps, maintained by the consultancy itself
- Kanban board with a review step, real-time updates and an append-only history
- AI assistant with retrieval over the BSIG, IT-Grundschutz and ISO/IEC 27001, opened from the task at hand
- Supplier register and per-supplier assessment along Art. 21(3)
- Audit report as a PDF from live data, for the authority, the auditor and internal committees
- Tenant isolation at the service layer, roles over 29 permissions, two-factor authentication and around 120 automated test suites — deployed with Docker on cloud infrastructure in Germany
Results
The platform is in production and the consultancy's customers implement NIS-2 with it. The first consultation is now a URL: a company finds out whether it is in scope and receives its own plan of measures without a meeting, a sign-up or a fee — the beginning of the working relationship rather than a brochure. Catalogue, questionnaire and criteria remain data the consultancy maintains itself, so a change in the law is a content update and not a development ticket.
Three decisions carried the project: building the free part first and as a real public flow, treating the consultants' spreadsheet as the domain model, and grounding the assistant in the source rather than in a generic language model.
- The first consultation as a free, public flow that ends in the company's own plan of measures
- The consultancy owns its content: catalogue, questionnaire and criteria are maintained without a developer
- Compliance as a project with ownership, deadlines and review on one board instead of email threads and spreadsheets
- An assistant customers trust, because its answers come from the law and the standards
- Audit-ready evidence on demand, including a per-supplier supply chain record