The implementation of the NIS2 Directive is an important step for many companies toward establishing a structured and future-proof digital security framework. Under the new legislation, organizations are required to think about cybersecurity and the opportunity to measurably improve their own security level has never been greater.
In practice, however, it’s clear that certain issues repeatedly cause difficulties and lead to errors during NIS2 implementation. Addressing them early on allows for an efficient, audit-ready, and stress-free implementation. Below, we’ll discuss the most common stumbling blocks and how to avoid them.
The contents at a glance:
Many companies know that the NIS2 Directive applies to them, but they are unsure which steps are now required. A key requirement is registration with the Federal Office for Information Security (BSI).
Even though the official registration deadline has already passed, you should still registration be completed as soon as possible, as failure to do so can result in substantial fines. At the same time, registration marks the official starting point for compliance implementation and signals to both authorities and business partners: We take cybersecurity seriously.
Recommendation:
Check now whether your company is considered an essential or important facility, define internal responsibilities, and actively complete the registration process. Those who address this issue promptly will be better able to plan for and prioritize the remaining NIS2 requirements.
2. Mistake:
Lack of transparency regarding assets and risks
Sound risk management begins with transparency. NIS2 requires an overview of systems, services, and processes—and their interdependencies.
This is where the open-source CMDB and asset management tool DataGerry really shines:
- The flexible data structure allows you to tailor your own object types, fields, and relationships precisely to your business environment.
- Graphical visualizations make it possible to intuitively depict dependencies and relationships among IT systems, applications, and service providers.
- The integrated ISMS module maps processes related to information security, risk assessments, and measures management directly within the system.
This makes DataGerry the central information hub for all security-related decisions. Instead of simply checking off obligations, it provides a real-time overview of assets, responsibilities, and risks—the ideal foundation for active NIS2 compliance.
What is DataGerry?
DataGerry is an open-source CMDB and IT asset management platform specifically designed to provide a transparent view of complex IT landscapes and to serve as the central foundation for an information security management system (ISMS)—making it ideally suited for implementing the NIS2 Directive.
Thanks to the freely definable data model, companies can map their entire IT landscape in a customized way: from systems and applications to service providers and dependencies. The integrated CI Explorer visualizes these relationships and makes risks and impacts transparent.
A key component is the integrated ISMS and risk module: Risks can be assessed directly at the asset level, calculated automatically, and documented in a traceable manner. This enables the structured implementation of key requirements from NIS2, ISO 27001, and BSI IT-Grundschutz.
Through APIs, webhooks, and the OpenCelium integration platform, DataGerry also serves as a data hub that consolidates information from various systems and processes it automatically. Combined with flexible reporting functions, this creates an audit-proof foundation for audits and compliance.
In short: DataGerry combines asset transparency, risk management, and ISMS into a single system, thereby laying the foundation for efficient and sustainable NIS2 implementation.
3. Mistake: Treating
safety management as a one-time project
One-time projects are not sufficient for NIS2. Cybersecurity is a continuous improvement process. In many respects, the directive is based on existing standards such as ISO 27001 and the IT-Grundschutz. Both provide proven guidelines for the targeted further development of an ISMS.
With the ISMS module from DataGerry, these requirements can be implemented both technically and organizationally: policies, controls, and improvement measures are managed centrally, responsibilities are assigned, and progress is documented in a verifiable manner.
Companies that adopt this approach benefit in two ways: they meet legal obligations and create a clearly structured, scalable security architecture that can be continuously adapted to new threat scenarios.
4. Mistake:
Failing to detect and report security incidents in a timely manner
One of the key requirements of NIS2 is the rapid detection and reporting of security incidents within 24 hours. This is not merely a formal obligation, but a practical tool for improving an organization’s ability to respond.
At this point, Wazuh, a powerful open-source SIEM/XDR system, offers clear advantages: It analyzes logs in real time, detects anomalies, and generates automated alerts. Security incidents, vulnerabilities (e.g., CVEs), or policy violations become immediately visible and can then be addressed in a targeted manner.
Another advantage: DataGerry can, with the help of the API Integration Platform OpenCelium to import data directly from Wazuh, including detected vulnerabilities and system information. This seamlessly integrates technical events into the context of the ISMS and the asset inventory. The result is a complete picture of the security landscape—both technical and organizational.
In this way, companies lay the groundwork for proactive risk mitigation and transparent reporting requirements—two core objectives of the NIS2 Directive.
What is Wazuh?
Wazuh is an open-source security platform that combines features from SIEM (Security Information and Event Management) and XDR (Extended Detection and Response). It helps companies detect, analyze, and respond to security events in real time.
The solution collects and correlates log data from various sources, detects anomalies, vulnerabilities, and policy violations, and automatically triggers alerts. This enables the early detection of potential security incidents—a key requirement of the NIS2 Directive.
In addition, Wazuh supports compliance efforts by monitoring security policies and providing reports for audits.
5. Mistake:
Excluding the supply chain from the security strategy
Cybersecurity does not stop at the company’s boundaries. NIS2 explicitly requires that service providers and suppliers also be included in security measures.
This creates transparency and strengthens trust throughout the entire value chain.
With DataGerry, you can map dependencies on external partners or critical service providers, as well as track their security assessments and audit histories. This makes supply chain security tangible and verifiable, rather than relying solely on contracts and assurances.
6. Mistake:
Not making cybersecurity a management priority
The long-term success of any security strategy depends on the active involvement of senior management. The NIS2 Directive clearly underscores this by establishing responsibility and liability at the management level.
This is not a risk, but an opportunity: When executives view cybersecurity as part of the corporate strategy, it is automatically prioritized in budgets, decision-making processes, and communication.
Thanks to centralized reports from DataGerry (ISMS, risk status) and real-time insights from Wazuh (security incidents, vulnerabilities), management can make informed decisions. This creates a data-driven foundation for governance and compliance—and a shared understanding that security is an ongoing factor for success.
Successfully Implementing NIS2: Greater Security, Transparency, and Compliance for Businesses
The NIS2 Directive is more than just a regulatory issue. It is an opportunity to professionalize information security over the long term and build trust. Those who actively involve their systems, processes, and partners in the security process not only strengthen compliance but also the entire company.
With DataGerry (flexible CMDB, ISMS, visualization, Wazuh integration) and Wazuh (SIEM/XDR for real-time detection and reporting), two powerful open-source solutions are available that work together seamlessly. Together, they provide transparency, automation, and control—the cornerstones of effective NIS2 security.
To make it easier to get started with NIS2 implementation and ensure that no important requirements are overlooked, a structured guide is recommended. Our NIS2 checklist helps you systematically identify all relevant measures, set priorities, and keep track of your current implementation status at all times. This transforms complex requirements into a clear, practical roadmap for greater cybersecurity.
NIS2 checklist for compliance with the new EU directive
Practical guide to implementing the new EU requirements
The paper not only provides a concise overview of the legal requirements, but also includes a practical checklist that you can use to check the status of your company step by step and determine the necessary measures. In addition, we recommend a tool that will help you implement the requirements in a transparent and future-proof manner.
Contact
Contact us!
We look forward to hearing from you.
Do you have any questions or are you facing a particular challenge? Our dedicated team will be happy to provide you with a no-obligation consultation.













