Cybersecurity & compliance

Cybersecurity compliance without the maze

NIS2, the Cyber Resilience Act, the EU AI Act, GDPR security requirements — regulation is growing faster than most teams can read it. We help you understand what actually applies to you, what is missing and how to implement it in a way that also improves security.

What makes regulation hard

  • It is unclear which laws apply and what exactly they require
  • Requirements from different regulations overlap and contradict each other on paper
  • Legal texts describe outcomes, not the concrete measures
  • Deadlines are close and internal capacity is limited
  • Measures are implemented for compliance only and do not improve security

How we support compliance

Applicability check

A structured look at which requirements are likely relevant for you — as input for your legal assessment.

Compliance gap analysis

Comparing requirements with your current measures, documentation and processes.

Readiness roadmap

A prioritized plan of technical and organizational measures with owners and timelines.

Risk management

A cybersecurity risk management approach that satisfies NIS2 expectations — ideally inside an ISMS.

Reporting processes

Incident and vulnerability reporting processes that work under time pressure (NIS2, CRA).

Security by design

For manufacturers: secure development, vulnerability handling and SBOM practices for the CRA.

Security governance

Roles, responsibilities and management reporting — including the accountability of management bodies.

Vulnerability management

Processes to identify, assess and remediate vulnerabilities in systems and products.

Our approach

  1. Clarify

    Which regulations are relevant and which obligations follow from them — explained in plain language.

  2. Compare

    Where do you stand? What do existing management systems and measures already cover?

  3. Prioritize

    What matters first: deadlines, risk and effort — not everything at once.

  4. Implement

    Technical and organizational measures, together with your teams.

  5. Evidence & maintain

    Documentation and evidence that hold up — and stay current.

Compliance implementation, not legal advice

We are cybersecurity and management-system consultants, not a law firm. We translate requirements into technical and organizational measures and implement them with you. Binding legal assessments — for example whether your company legally falls under NIS2 — should be confirmed by legal counsel. We are happy to work alongside your lawyers.

What you get out of it

  • Clarity on what applies and what it means
  • One set of measures that serves several regulations
  • Security that improves, not just documentation that grows

Frequently asked questions

What is NIS2?

NIS2 is an EU directive that sets cybersecurity obligations for “essential” and “important” entities in many sectors — including risk management measures, incident reporting and management accountability. In Germany it is implemented by the NIS2 Implementation Act, which has been in force since December 2025 and requires affected companies to register with the BSI.

What is the Cyber Resilience Act?

The Cyber Resilience Act (CRA) is an EU regulation that sets cybersecurity requirements for products with digital elements — hardware and software — across their lifecycle. Manufacturers have had to report actively exploited vulnerabilities and severe incidents since 11 September 2026; most other obligations apply from December 2027.

Does ISO 27001 cover NIS2?

Not automatically, but substantially. An ISO/IEC 27001 ISMS provides the risk management framework and many measures NIS2 expects. Specific obligations — such as registration, reporting deadlines and management training — have to be addressed in addition.

What is DIN SPEC 27076?

DIN SPEC 27076 is a standardized IT security check (“CyberRisikoCheck”) for small companies, developed with the participation of the German Federal Office for Information Security (BSI). It is a pragmatic first step for companies that are not yet ready for a full ISMS.

Related services

Related reading

Unsure which regulations apply to you?

Tell us about your company and your products. We will help you sort out what matters.

contact@feldmanncyber.com · +49 (0)151 6275 6121