Skip to content

NIS-2 · MANAGED SOC

Protect your core business before the damage grows

The NIS-2 reporting period begins as soon as you become aware of a significant security incident. Cypurge Managed SOC detects threats 24/7, while our consultants support you in implementing the remaining NIS-2 obligations.

  • 24/7 monitoring, 365 days a year
  • Structured escalation and evaluation of every incident
  • Managed SOC and security consulting from one provider
Cypurge eagle, symbol of vigilance

SECURITY MONITORING

24/7/365

VERIFIED SECURITY Cypurge security certification Cypurge security certification Cypurge security certification Cypurge security certification

SCOPE

Does NIS-2 apply to your company?

NIS-2 applies to medium-sized and large entities in one of the sectors covered by the Directive. National requirements vary by country.

Certain covered entities are subject to NIS-2 regardless of their size.

Not sure if you are in scope? Ask our experts

50 or more employees

or over €10M in both turnover and balance sheet total

In force in Germany since 6 December 2025 — with no transition period

REPORTING OBLIGATION

The 24-hour clock starts when you become aware

Under § 32 BSIG, significant security incidents must be reported in three stages. Early detection limits the damage — and gives your team the information it needs for timely reporting.

  1. 24 h

    Incident notification

    01 · NIS-2

  2. 72 h

    Status report

    02 · NIS-2

  3. 1 month

    after the status report: final report

    03 · NIS-2

Late detection

Monday, 08:15 — the attacker has had the whole weekend.

Early detection

Friday, 17:45 — your team contains the incident before it spreads.

Cybersecurity operations monitoring

02:00:00

SUNDAY · ACTIVE MONITORING

Who is watching your environment at 02:00 on a Sunday?

Anyone building 24/7 detection in-house needs at least five to six analysts, clear processes, infrastructure and seamless shift schedules.

Internal team

  • Staff night shifts
  • Cover weekends
  • Absorb holidays and sick leave
  • Organise on-call duty

Managed SOC

  • Staffed 24/7/365
  • Experienced analysts
  • Agreed escalation plan
  • No in-house recruiting
Request your quote

What the Cypurge Managed SOC delivers

24/7 monitoring

We monitor your infrastructure — day and night.

Rapid detection

We detect threats early — giving your team time.

Structured escalation

Following an agreed escalation plan, we notify the right contacts — even at night.

Evaluation & improvement

Every incident raises your security level.

HOLISTIC IMPLEMENTATION

A SOC is only one building block of your NIS-2 implementation

NIS-2 also requires risk analysis, policies, business continuity, supply-chain security, training and more. Cypurge closes the remaining gaps with security consulting.

Start your NIS-2 assessment Cypurge security consulting workshop
  1. 01 Risk analysis & policies
  2. 02 Incident handling
  3. 03 Business continuity
  4. 04 Supply-chain security
  5. 05 Vulnerability handling
  6. 06 Effectiveness reviews
  7. 07 Cyber hygiene & training
  8. 08 Cryptography & encryption
  9. 09 Access & asset management
  10. 10 Secure communications

From gap analysis to 24/7 protection

  1. 01

    NIS-2 assessment

    We identify your NIS-2 gaps.

  2. 02

    Roadmap

    You receive a prioritised action plan with effort and timeframe.

  3. 03

    Managed SOC

    Continuous monitoring, detection and escalation.

  4. 04

    Continuous improvement

    Regular evaluations keep your security level up to date.

Frequently asked questions

Is management liable?

Management must approve the risk-management measures, oversee their implementation and participate in training. Liability is governed by the applicable corporate-law provisions.

Does a SOC make me NIS-2 compliant?

No. A SOC covers detection and part of incident handling. Risk management, business continuity, supply chains and training remain your responsibility — and we support you with them.

When does the 24-hour period begin?

As soon as your entity becomes aware of a significant security incident.

Do I need to build my own SOC?

No, the law does not require an in-house SOC. A Managed SOC provides 24/7 monitoring without requiring you to recruit and retain a team.

Ready before the clock starts. Start today.

Request your quote for the Cypurge Managed SOC, or start with a NIS-2 assessment to see where you stand.

Managed SOC and security consulting from one provider

Request your quote

We will get back to you within one business day.

No commitment and free of charge.

Request your quote

Request your quote

No commitment and free of charge.