Client Success Stories

“NIS-2 ASSESSMENT & ROADMAP”

Karer Consulting brings structure and clarity to the evolving regulatory landscape around NIS‑2, ISO 27001 and related cybersecurity obligations. Our focus is not on theoretical compliance, but on translating regulatory requirements into clear priorities, executable work packages and a realistic roadmap.

 

The Customer

Kreis 1

Sector

Engineering & Manufacturing

Kreis 1

Turnover

< 500. MIO EUR

Kreis 1

Employees

< 2.000

Initial Situation

Our client – a global medical technology company – develops, manufactures and distributes medical devices. As a European company headquartered in Germany, the group is required to comply with the NIS-2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG).

In addition to NIS‑2, the client aims to establish the foundation for a future ISO 27001 certification and to address further industry‑specific standards, such as ISO 81001‑5‑1.

The key challenge was to review, prioritize and integrate these requirements into a single, coherent ISMS, while considering existing processes, documentation, and IT security measures already in place.

Organizations affected by NIS‑2 should address the requirements early and holistically – and use implementation as an opportunity to strengthen their overall security posture.

Objectives

  • Development of a NIS-2-driven roadmap for establishing an integrated ISMS
     
  • Identification of relevant areas of action and derivation of measures for implementation
     
  • Concrete implementation of previously defined work packages in the context of ISMS development

Our Assignment

Karer Consulting was engaged to leverage its expertise in regulatory requirements, information security and NIS‑2 to design a comprehensive roadmap for implementation. The assignment explicitly focused on pragmatic execution: existing processes and compliance concepts were reviewed, aligned with regulatory requirements and translated into concrete work packages that could be realistically implemented within the organization.

Challenges

  • NIS‑2 implementation impacts multiple business areas, not only IT
  • Alignment of NIS‑2, ISO 27001 and additional regulatory frameworks
  • Clear definition of roles and responsibilities, especially regarding management obligations under NIS‑2

Measures

  • Early involvement of all relevant stakeholders, including management, IT and business units, to establish awareness and ownership
  • Structured review and mapping of all applicable regulatory requirements, with a clear focus on NIS‑2 and ISO 27001
  • Derivation of concrete and prioritized implementation measures
  • Regular checkpoints to ensure transparency on progress, risks and next steps

KC Process Model

Karer Consulting started with a structured assessment workshop together with the client’s experts and management. This workshop provided a comprehensive overview of the NIS‑2 Directive, its implications and its relationship to ISO 27001 certification.

Beyond knowledge transfer, the workshop served to raise awareness of new regulatory obligations and align all participants on common objectives. Building on this foundation, Karer Consulting performed a systematic gap analysis.NIS‑2 and ISO 27001 requirements were compared against existing documentation, processes and the security measures actually implemented in day‑to‑day operations. The identified gaps were translated into client‑specific measures, carefully prioritized and structured into a compliance roadmap.

Strong emphasis was placed on best practices, feasibility and practical implementation, rather than purely formal compliance. Finally, Karer Consulting developed the initial set of overarching ISMS policies and guidelines and supported their implementation together with the client.

 

Kreis 2

“With KC, you can turn compliance into a catalyst for transformation.
We’re here to support you.”

Alexander Lambrecht-Kuhn
Principal Consultant

Customer Benefits

Efficiency

Transparency regarding regulatory requirements through prioritised roadmap content

Transparency

A clear vision of individual and organisational NIS-2 implementation

Management

Meaningful integration of management and recommendations for fulfilling future obligations

As NIS-2 experts, we offer specialist knowledge and best practices and provide active support in implementing compliance requirements.