senn-techsenn-tech
Security
Security2025-09-02· by Mag. (FH) Franz Senn

NIS2 and Self-Operation: Compliance through Control

NIS2 is no longer a future topic. The EU directive applies, national implementation is underway, and the circle of affected companies is significantly larger than under its predecessor NIS1. Those who operate their IT infrastructure themselves have an advantage: they know where their data is.

Who NIS2 Applies To

NIS2 does not only apply to KRITIS operators. Medium-sized and large companies from sectors such as energy, transport, health, digital infrastructure, wastewater, public administration, and — newly — also IT service providers fall under it.

The rule of thumb: from 50 employees or €10 million in turnover, caution is advised. For SMEs with critical services, NIS2 may also apply. In Germany, the NIS2 Implementation Act (NIS2UmsuCG) regulates the details; in Austria, the Network and Information Systems Security Act. Those affected must also register with the responsible authority.

What Is Required

The directive demands risk management measures and reporting obligations:

  • Technical security: Access controls, network segmentation, encryption, patch management
  • Incident detection: Monitoring, logging, alerting — exactly what Uptime Kuma, Graylog, and CrowdSec deliver in self-operation
  • Reporting obligation: Significant security incidents with early warning within 24 hours, followed by a report within 72 hours
  • Supply chain security: You are liable for security vulnerabilities at service providers — and this is the point where uncontrolled SaaS usage becomes a risk

Management Bears Personal Liability

The sharpest lever of NIS2: Management must approve risk measures, oversee their implementation — and is personally liable for shortcomings. Cybersecurity is thus finally a management issue and no longer a pure IT matter. Even training obligations expressly extend to the management level.

Why Self-Hosting Simplifies Compliance

Those who operate a service themselves can implement every required measure. Those who purchase it as SaaS depend on the provider's assurances — and on their willingness to release forensic data in an emergency.

Example: NIS2 requires that you can detect and document security incidents. On your own Proxmox infrastructure with centralized monitoring, you have logs, metrics, and access audits. With a SaaS platform, you get — at best — a status dashboard.

The Duty of Due Diligence

NIS2 is no reason for panic, but one for taking stock:

  • Which services do we operate ourselves? Which are SaaS?
  • Do we have functioning monitoring for the self-operated services?
  • Are reporting processes defined — who informs whom within the 24-hour window?

What NIS2 Is Not

No certification mania. The directive does not prescribe a specific framework, no ISO-27001 mandate, no BSI basic protection by law. It prescribes outcomes: manage risks, report incidents, control the supply chain. How you achieve this is left to you.

Conclusion

NIS2 rewards those who understand and control their infrastructure. Self-operation with clean monitoring, network segmentation, and documented processes fulfills the requirements better than a jumble of SaaS services whose internals you do not know.

FAQ
Does NIS2 even affect our company?+

Probably more than you think. NIS2 applies not only to KRITIS operators but also to medium-sized and large companies in sectors such as energy, transport, health, digital infrastructure, and — newly — IT service providers. The rule of thumb: from 50 employees or €10 million turnover, caution is advised, and for SMEs with critical services NIS2 can also apply. Those affected must also register.

What happens if we do not meet the requirements?+

Management bears personal liability. NIS2 requires the management level to approve risk measures, oversee their implementation, and undergo training — cybersecurity is a management issue. Add the reporting obligations: significant incidents must be reported with an early warning within 24 hours and a report within 72 hours. Neglect supply-chain security and you are also liable for gaps at service providers.

Why does self-operation simplify NIS2 compliance?+

Because you have control and traceability. On your own Proxmox infrastructure with centralized monitoring, you have logs, metrics, and access audits and can implement every required measure yourself. With a SaaS platform you depend on the provider’s assurances and, in an emergency, get at best a status dashboard. Self-operation with network segmentation and documented processes meets the requirements better.