Have you heard of NIS2, but your company isn’t subject to the NIS2 regulation? If so, you’re one of the approximately 300,000 German small and medium-sized enterprises that, while not directly affected by the NIS2 Directive, will nevertheless feel its massive impact. The reason is as simple as it is far-reaching: Your major customers—energy providers, hospitals, logistics companies, and automakers—must secure their entire supply chain. And this sets off a chain reaction that will ultimately reach you.
What was conceived as a European directive for critical infrastructure is evolving into a de facto compliance requirement for hundreds of thousands of suppliers, service providers, and partners. The first major corporations began adapting their supplier contracts as early as 2024. The broad wave of implementation is now reaching small and medium-sized enterprises in 2026 and 2027. The question is no longer whether you need to take action, but how quickly and how systematically you will proceed.
This book provides the answers you need—in a practical, easy-to-understand way, without all the regulatory jargon.
The logic behind this trend is clear: Companies regulated under NIS2 must demonstrate that their supply chain is cyber-secure. A medium-sized supplier with VPN access to a major customer’s production systems represents a potential entry point for cyberattacks. Supply chain attacks have increased dramatically in recent years—the SolarWinds attack and the Log4j vulnerability have vividly demonstrated just how vulnerable modern supply chains are.
The result: Companies subject to NIS2 systematically assess their direct suppliers for cybersecurity risks. Violations can result in fines of up to 10 million euros. This economic reality means that compliance requirements are trickling down the entire supply chain—from large regulated companies all the way down to the two-person IT service provider performing maintenance work.
It is advisable not to view this development as bureaucratic red tape, but rather as a structural change in business relationships in the B2B sector. Those who begin systematically professionalizing their cybersecurity today will be able to capitalize on competitive advantages tomorrow. Those who wait will have to react under time pressure and at significantly higher costs.
“Successfully Implementing NIS2 in Small and Medium-Sized Enterprises!” is not an academic set of rules, but a practical guide for decision-makers in small and medium-sized enterprises. The book is specifically aimed at CEOs, IT managers, and business owners who, due to their business relationships with NIS2-regulated customers, face the challenge of meeting cybersecurity requirements.
You’ll get concrete answers to the most pressing questions: Am I actually affected? What exactly do my customers expect from me? What costs will I incur? How long does ISO 27001 certification realistically take? Which technical measures should be prioritized? How do I document security measures professionally? And above all: How do I manage all of this with limited resources and without a dedicated IT security department?
The book systematically covers all phases of NIS2 compliance implementation—from the initial impact assessment through the current state analysis and action planning to operational implementation and ongoing compliance management. Each chapter is based on real-world project experience and includes specific figures, timeframes, and cost estimates.
You’ll find real-world examples from various industries: a mechanical engineering company with 85 employees that supplies its automotive customers; an IT service provider with 22 employees that serves hospitals; and a logistics company with 120 employees in the pharmaceutical supply chain. These case studies illustrate realistic implementation paths—complete with all the challenges, obstacles, and potential solutions.
Particularly valuable: The book demystifies the technical requirements. ISO 27001, penetration tests, multi-factor authentication, encryption, backup strategies—all these terms are explained in an easy-to-understand way and translated into concrete steps you can take. You’ll learn what’s truly necessary and where to find practical solutions that fit your resources.
The numbers speak for themselves: ISO 27001 certification costs small and medium-sized enterprises between 20,000 and 80,000 euros, depending on the company’s size, the complexity of its IT infrastructure, and the maturity level of its existing security measures. Realistically, implementation takes between 12 and 18 months. On top of that, there are ongoing costs for maintenance, audits, and continuous improvement.
This investment is significant, but the alternative is more expensive: Companies that cannot demonstrate adequate cybersecurity will lose contracts. The first requests for proposals from companies subject to NIS2 already include exclusion criteria for suppliers without security certification. The trend is clearly on the rise.
Essentially, this means that cybersecurity is evolving from a technical afterthought into a strategic business factor. The NIS2-driven transformation of supplier relationships is irreversible. Those who start early can use this development as a differentiator. ISO 27001 certification opens doors to new customers, strengthens your negotiating position with existing customers, and reduces the risk of costly security incidents.
The book is aimed at four key target groups: First, CEOs and owners of medium-sized companies who must make strategic decisions regarding investments in cybersecurity. Second, IT directors and technical managers who plan and carry out the operational implementation. Third, quality managers and compliance officers who structure documentation and processes. Fourth, purchasing managers and sales managers who are confronted with new requirements in customer contracts.
You don’t have to be an IT expert to benefit from this book. The content is deliberately presented in a way that allows even non-technical readers to understand the concepts and make informed decisions. At the same time, the book offers enough technical depth that even IT professionals will find practical implementation guidance.
The timeline is clear: The first large companies began assessing their suppliers against NIS2 criteria as early as 2024. The broad wave of implementation is now underway in 2026 and 2027. Companies that start today have ample time for a systematic implementation. They can take their time selecting external consultants, carefully plan implementation steps, and train employees gradually.
Companies that wait until 2028 will have to respond under immense time pressure: Customers are threatening to cancel contracts, external consultants are fully booked and therefore expensive, and certification bodies have long wait times. The financial and organizational burden increases exponentially as time runs out.
Furthermore, cybersecurity cannot be implemented overnight. A functioning information security management system takes time to mature. Processes must be fine-tuned, employees must be trained, and measures must be evaluated for effectiveness. This maturation process cannot be accelerated; it can only be started in a timely manner.
This book represents over 45 years of IT experience, condensed into a structured guide for the practical implementation of NIS2 in small and medium-sized businesses. It saves you months of research, costly mistakes, and unnecessary detours. The savings you’ll realize by taking early action far exceed the cost of this book.
You can now download the complete guide, “Successfully Implementing NIS2 in Small and Medium-Sized Businesses!” for free as a PDF. No hidden fine print, no follow-up costs, no obligations. Our goal is to provide small and medium-sized businesses with access to professional expertise so they can successfully overcome the challenges ahead.
Download the book, read the chapters that apply to your situation, and start putting the ideas into practice. Every day you start sooner gives you more room to maneuver. The companies that take action today are tomorrow’s winners.
This book is the result of more than four decades of practical experience in digital transformation. As a doctor of business administration and a master craftsman, I combine analytical precision with entrepreneurial pragmatism—a combination that has proven particularly valuable in over 200 international projects.
My expertise covers the full spectrum of IT transformation: from strategic direction and the development of digital infrastructures to the operational implementation of complex NIS2 compliance requirements. As an interim CIO, CTO, and CDO, I have built IT and OT infrastructures, led Industry 4.0 initiatives, and developed cyber resilience strategies—always with a focus on practical implementation rather than theoretical concepts.
My guiding principle is: “Digital resilience begins when management and technology speak the same language.” This philosophy also shapes this book. Complex technical issues are explained in a way that enables board members, CEOs, and advisory board members to make informed decisions. At the same time, IT leaders receive concrete implementation guidance on an equal footing.
As an author, keynote speaker, and lecturer at international universities, I present these topics in a practical way to companies, committees, and executive teams—never in an overly academic or detached manner, but always with the goal of empowering my audience to take action on their own.
I have enjoyed a high level of international recognition for many years. Projects and guest lecturing engagements have taken me to renowned institutions such as the IMD International Institute for Management Development in Lausanne, the WHU – Otto Beisheim School of Management in Vallendar, and the University of Dubai. I would like to consistently build on this visibility and recognition in the German market.
If, after reading this book, you need assistance with implementation—whether for an initial strategic assessment, support with ISO 27001 certification, or the implementation of an information security management system—I would be happy to assist you.
Dr. Claus Michael Sattler
Email: cms@sattlerinterim.com
Phone: +49 174 6031377
Website: www.sattlerinterim.com
The decision is yours: You can wait and see and react when the pressure from your customers becomes too great. Or you can start now and maintain control over your compliance strategy. The choice is simple; the consequences are far-reaching.
Download the book, get a clear picture of your situation, and make informed decisions. Companies that take action today won’t pay the price of inaction tomorrow.






