A transparent quick check, not an audit
The check follows Directive (EU) 2022/2555 (NIS 2) and the German implementation in the NIS 2 Implementation Act (BGBl. 2025 I No. 301), including the revised BSI Act (BSIG). The BSI provides guidance for NIS 2-regulated entities. Scoring is explicit: Yes = 3, Partly = 2, Unknown = 1, No = 0. The result provides orientation and is neither an audit, a BSI registration, nor legal advice. For methodological orientation along BSI IT-Grundschutz, see the BSI IT-Grundschutz Check.
Result
Prioritised action areas
From quick check to robust IT administration
cube one will review scope, reporting paths and risk measures with you in the actual infrastructure context. A starting point is our IT Administration.
Discuss NIS 2Regulatory context and target groups
Regulatory basis
The questions provide orientation. The binding texts are Directive (EU) 2022/2555 and the BSI Act as recast by the NIS 2 Implementation Act.
For IT operations
IT owners in pharma and life science gain an initial view of registration, reporting paths, cyber hygiene and business continuity: independently of GxP CSV.
For management
The check helps prioritise gaps in accountability, training and the supply chain before supervisory or reporting deadlines tighten.