S105
·
Weiterbildung

NIS2/KRITIS: Applicability, Registration, Documentation

With NIS-2, the number of regulated companies in Germany grows to around 30,000 entities. You learn to check whether you are affected and to implement registration and reporting obligations.

Security officer explains the incident reporting process by the control room as the managing director signs it off
Duration

55 min

Format

Multimodal

Languages

Über 30 Sprachen

Proof

Teilnahmebescheinigung

Challenge

With NIS-2 and the NIS-2 implementation act, the group of regulated companies in Germany is expanded to around 30,000 particularly important and important entities, far beyond the traditional KRITIS (critical infrastructure) operators. Affected companies must register with the BSI, submit an initial report on significant security incidents within 24 hours, implement risk management measures in line with the state of the art, and include the supply chain. Management is liable to its own entity for implementation and is obliged to undergo training.

Learning objectives
  • You check whether your company is affected based on sectors, size categories, and special rules.
  • You have an overview of the obligation to register with the BSI and the obligations regarding evidence and documentation.
  • You understand the three-stage reporting procedure (24 hours, 72 hours, final report) for significant security incidents.
  • You know the ten minimum risk management measures, including supply chain security.
  • You know about the obligations and liability of management and the supervisory and fine provisions.
Agenda
00 Fundamentals: NIS-2 and the German implementation act
01 Applicability check and registration
02 Reporting obligations for security incidents
03 Risk management measures and supply chain
04 Management obligations, supervision, and sanctions
05 Summary
06 Knowledge check incl. certificate of completion
Target group

Management, IT security and compliance managers, and information security officers in potentially affected companies and KRITIS operators.

Leading organizations trust Bridgly

Logo von Ols
Logo von Ols
Logo von Ols
All training courses on one platform:

Bridgly learning platform

Our platform bundles all training management functions, from planning to reporting, in one place.

Training organization

Define who is trained on which content and when.

Training documentation

See at any time who completed which content and when.

Manage participants

CSV import, learning groups, and access rights in one place.

Automated
reminders

Deadlines and recurring training run automatically.

FAQ

Frequently Asked Questions

Here you will find the most important answers.

Is data protection training for employees mandatory under the GDPR?
Which cyber threats should companies train their employees on?
What are the consequences of missing data protection training in the event of a data breach?
What training obligations arise from NIS-2 and the BSI Act (BSIG)?
How often must data protection and IT security training be repeated?
How does GDPR training for employees differ from the qualification as a data protection officer?
Contact

Train your employees in a legally compliant and verifiable way

Training and professional development for companies and public-sector clients – with audit-proof documentation and a practical focus.

Get in touch now
Eine Hand blättert in einem grauen Ringordner mit Tabellen, dahinter ein aufgeklappter Laptop

Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.