EU/EEA Compliance

Compliance Clarified

European security aligned. Tuned to every border.

The European regulatory landscape has changed more in the last few years than in the two decades before it. NIS2, CER, and the Cyber Resilience Act have moved industrial cybersecurity from something you were encouraged to do into something the organization is accountable for, across borders and at the board level. If that shift feels like a lot to absorb, you are not behind. You are exactly where most serious operators are right now, working out what actually applies, to whom, and by when.

That is the work we do alongside you. Ampyx Cyber advises operators, asset owners, and product vendors across the EU and EEA on the regulations that now bind them, and we start from what you already have. Most organizations have done more good work than they give themselves credit for, and building on that foundation is faster and more durable than starting over. Our job is to turn a stack of overlapping directives into a clear picture of your obligations and a program your team can actually run.

Ampyx Cyber GmbH is an EU company. It is registered and headquartered in Germany, independently owned and led, and it operates under the same law our regulators and clients answer to. Engagements run on fully EU-sovereign terms, governed by European law with your work kept in Europe. We know how NIS2 reads in a German transposition versus an Italian one, where CER overlaps it and where it does not, and how the Cyber Resilience Act lands on a product that is still on the drawing board.

You do not need twenty-seven separate programs, and you do not need to react to every headline. You can establish one coherent program, built once for the way Europe regulates, and tuned where a specific border genuinely calls for it. We will help you design it, prove it, and keep it current as the rules continue to move.

NIS2 Compliance

One directive. Twenty-seven transpositions.

We help you find the one that governs you.

If you run essential services in energy, water, transport, healthcare, manufacturing, or digital infrastructure, NIS2 is probably the European rule you will hear about first. NIS2 (Directive (EU) 2022/2555) sets a common baseline for how important operators across Europe manage cyber risk, report serious incidents quickly, and hold their own suppliers to a standard. It sorts the organizations it covers into two tiers, usually called essential and important, which mainly affects how closely a regulator watches you and how large the penalties can be. One detail tends to get leadership's attention: senior managers can be held personally responsible if the organization falls short, so this is no longer only an IT concern.

This is where it gets confusing. NIS2 is a directive, which in practice means the EU sets the goal and each country then writes its own law to reach it, on its own schedule and often with its own additions. So the rules a German operator follows are not identical to the ones an Italian or Polish operator follows, even though all of them come from the same directive. Reading the original European text only gets you part of the way. What actually binds you is the national version that applies where you operate, and that is the piece most operators find hardest to pin down.

That is exactly where we come in. We keep track of where each country stands and how strictly it is enforcing, and we turn that into a plain list of what you specifically need to do, by when, and who you answer to. From there we help you close the gap, building on the security work you have already done rather than starting from a blank page. Most operators are closer to where they need to be than they fear.

We help you:

  • Work out whether NIS2 applies to you, and which of the two tiers you fall into

  • Pin down the exact national version that governs you, and what it actually asks for

  • Build or strengthen a cyber risk management program that meets it

  • Put in place the incident detection and reporting you need to hit tight national deadlines

  • Get ready to register with your national authority and handle its reviews

  • Fit NIS2 together with the other standards you already run, from IEC 62443 and ISO 27001 to NERC CIP where it applies

CER: Critical Entities Resilience

Cybersecurity is only half the picture.
Physical resilience is the other half.

Most of the attention goes to the digital side of security, but the systems you run also have to survive the physical world. A storm floods a site. A fire or a power loss takes a facility offline. Someone cuts a fence, a cable, or a fiber line. The Critical Entities Resilience Directive (Directive (EU) 2022/2557), usually shortened to CER, is the European rule that asks important operators to plan for exactly those events and to keep essential services running through them.

CER is the physical companion to NIS2, and that pairing is deliberate. The two rules cover a very similar list of operators, so if NIS2 applies to you, CER very likely does too. The good news is that you do not have to treat them as two separate projects. Handled together, the risk assessment you do for one feeds the other, which saves your team effort and avoids the conflicting conclusions that come from doing each in isolation.

We work across both the digital and the physical sides of your operation, which many firms keep in separate boxes. That lets us help you put sensible protections in place without getting in the way of production, and without paying twice to cover ground your NIS2 work has already handled. As with NIS2, most operators have more of this in hand than they realize. Usually the job is to organize and document what you already do, not to build it from nothing.

We help you:

  • Work out whether CER applies to you, at the same time as your NIS2 review

  • Carry out the risk assessment CER expects, in plain and usable terms

  • Put practical physical and organizational safeguards around your critical operations

  • Combine CER and NIS2 into one program instead of two competing ones

  • Get ready for the reporting and check-ins your national authority will ask for

CRA: Cyber Resilience Act

Your products already earn a CE mark.
Soon they will earn a security one too.

If your company makes or sells equipment that contains software, firmware, or a network connection, whether that is a controller, a sensor, a gateway, or the software that runs them, a new European law now applies to you. The Cyber Resilience Act (Regulation (EU) 2024/2847), or CRA, says that products sold into the EU must be built to be secure from the start, ship free of known serious weaknesses, and keep receiving security updates for years after the sale. Much like the CE mark you already know from safety and electrical rules, security is becoming part of what earns a product the right to be sold in Europe at all.

The main requirements take effect in December 2027. That can sound far off, but for anyone who designs hardware or plans product releases, it is roughly one development cycle away, so the sensible time to start is now. For industrial equipment specifically, some questions are still genuinely open, such as whether systems already installed in the field are covered. Because that is unsettled, we look at your actual products rather than assuming the worst case or the best.

We meet you wherever you are with this, whether you are a large manufacturer with a full engineering team or a smaller supplier whose customers have suddenly started asking you to prove your products comply. Either way, the goal is the same: a clear, honest picture of what the CRA asks of your products, and a practical plan to get there in time that fits how you already design and ship rather than sitting beside it as a separate burden. Most of what a good engineering team already does counts for more than they expect.

We help you:

  • Work out exactly which of your products the CRA covers, including the tricky older and industrial cases

  • Build security into how you design and release products, rather than bolting it on at the end

  • Set up a clear process for finding, fixing, and reporting security flaws after a product ships

  • Prepare the evidence you need for CE marking and sign-off

  • Connect it to the parts and software inventories, known as SBOMs, that your customers increasingly request

Germany

Europe's toughest cyber regime.
And our home ground.

If you operate in Germany, you are dealing with one of the most demanding cybersecurity regimes in Europe, and usually more than one rulebook at the same time. The national cyber authority, the BSI, oversees the whole system. Germany's version of NIS2 carries some of the toughest enforcement in the EU, including holding senior managers personally responsible. And a separate law known as KRITIS-Dachgesetz adds physical protection duties on top of the digital ones. Most German operators have to satisfy all three at once.

Energy and telecom companies carry an extra layer. The federal network regulator, the BNetzA, keeps its own security catalogue for grid and network operators that sits alongside the NIS2 and BSI requirements, and electricity grid operators also inherit specific European rules for the power network. It adds up quickly, and it is easy to lose track of which requirement comes from where.

This is our home ground. Ampyx Cyber GmbH is based in Hamburg, so we work inside this system every day, in the same language and under the same authorities as you. That lets us help you see the whole picture rather than a pile of separate obligations, trace each demand back to the rule that is actually driving it, and engage with the BSI and the other regulators alongside you. Your engagement runs on fully EU-sovereign terms, so your work and your data stay in Europe throughout. And once the layers are laid out plainly, most German operators find the path more manageable than the stack of laws first suggests.

We help you:

  • Work out whether your sites cross the KRITIS thresholds that pull you into scope in the first place

  • Make sense of the German layers together: the BSI, the German NIS2 law, and KRITIS-Dachgesetz

  • Meet the practical requirements, from registering with the BSI to the 24/7 contact point and management sign-off

  • Set up and rehearse incident reporting to the BSI within its tight early-warning and full-report deadlines

  • Prepare for the recurring proof-of-compliance checks that German critical operators have to submit

  • Handle the BNetzA security catalogue if you are an energy or telecom operator, and the European grid rules for electricity networks

  • Work with a partner based in Germany, on fully EU-sovereign terms

EEA & EU
Reach

You do not have to be in the EU.
You only have to do business there.

It is natural to assume that European rules are a European company's concern. In practice, they reach further than that. If your company sits outside the EU but sells services to European customers or runs any infrastructure on European soil, NIS2 can apply to you directly, and you may need to appoint an official point of contact inside the EU (the directive sets this out in Article 26). A strong security program back home, wherever home is, is a solid foundation, though it does not by itself satisfy these European obligations. If you have European customers, sites, or suppliers, this is simply worth checking early rather than discovering late.

If you operate in Norway, Iceland, or Liechtenstein, there is a helpful quirk to understand. These countries are closely tied to the EU but adopt its rules on a slight delay, so a requirement can already be in force across the EU while their own version is still being finalized. Many European customers do not wait for that. They ask their suppliers in these countries to meet the EU standard now, through the contract. Knowing exactly where your country stands is what keeps you from doing more than you need to, or getting caught short.

None of this is as daunting as it first sounds. Most of the work is simply establishing clearly where you stand, then doing the specific things that follow, and we do exactly this with companies on both sides of the EU border. We will tell you plainly whether the rules reach you, what that means in practice, and the shortest sensible path to meeting them.

We help you:

  • Work out whether European rules reach your company through the business you do there

  • Set up the EU representative arrangement if you need one

  • Sort out the obligations for groups headquartered outside the EU that operate across European borders

  • Stay current on where Norway, Iceland, and Liechtenstein each stand

  • Meet the compliance terms your European customers put in their contracts, even ahead of local law

Ask an Expert

Got a tough question?

Sometimes you just need to phone a friend. Ask us anything, any time. You don’t need to be an existing or prospective client. No cost, no commitment, no sales follow up, no contact lists. Simply put, no strings attached. We will always respect your privacy. We promise.