THREAT BRIEFING · 09.10.2026 DEENFRES

Case Studies

Case Study: Achieving NIS2 Readiness in 6 Months — A Utility Company Shows How It’s Done

By Tobias Massow · February 28, 2025 · 4 min read

A utility company with 900 employees achieved NIS2 readiness in 6 months — with a limited budget and without external consulting firms. The key: consistent use of existing frameworks as a basis.

TL;DR

A utility company with 900 employees achieved NIS2 readiness in 6 months – with a limited budget and without external consulting firms. The key: consistent use of existing frameworks (ISO 27001, BSI IT-Grundschutz) as a basis and focusing on actual gaps rather than complete rebuilding.

Initial Situation

The utility company supplies a major city with electricity, gas, water, and district heating. As a KRITIS operator, an ISMS according to ISO 27001 was already implemented. However, the NIS2 gap analysis revealed significant gaps:

The 6-Month Plan

Month 1-2: Reporting Process

Month 2-3: Supply-Chain Security

Month 3-4: Management and Governance

Month 4-5: OT Security Integration

Month 5-6: Testing and Documentation

Budget

Total costs: approx. 95,000 EUR

Key Facts

Industry: Energy supply / utility company (KRITIS)

Starting Point: ISO 27001 certified

NIS2 Readiness Achieved in 6 Months

Total Budget: 95,000 EUR (without external consultants)

Highest Effort: Supply-chain inventory (127 suppliers)

Fact: The BSI (Federal Office for Information Security) counts over 1,500 utility companies and municipal suppliers in Germany, the majority of which fall under the KRITIS regulation.

Fact: According to ENISA, municipal infrastructures were the third most frequent target of attacks in the EU in 2024 – after the healthcare and financial sectors.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Can NIS2 readiness be achieved without external consultants?

Yes, if a solid foundation exists (e.g., ISO 27001). The key lies in a structured gap analysis and focusing on actual gaps rather than complete rebuilding.

Which NIS2 requirement causes the most effort?

Experience shows that supply-chain security does: inventorying all IT service providers and software suppliers, risk assessment, and contractual safeguards are time-consuming but essential.

What special challenges do utility companies face in NIS2 implementation?

Utility companies often operate heterogeneous IT and OT landscapes with established structures. Many systems date back to a time before modern security standards. Additionally, limited IT budgets and a shortage of skilled workers in municipal operations make NIS2 implementation particularly demanding.

Further Articles

NIS2 Directive: What Companies Need to Know

Cyber Insurance 2026

Zero Trust: The 7 Most Common Mistakes

Related Articles

More from the MBF Media Network

MyBusinessFutureMore IT Security Trends on mybusinessfuture.comcloudmagazinCloud & Infrastructure News on cloudmagazin.com

Translated from the German original using artificial intelligence. The German version is authoritative.

Further reading

A magazine by Evernine Media GmbH