• Newsroom
  • Join us!
  • Newsletter
  • Kontakt
  • English English English en
  • Deutsch Deutsch German de
Experts Institut
  • Business Consulting
    • Business Solutions
      • Digitization
      • Sustainability Corporate strategy
      • Management systems
      • Project management
      • Strategy & Performance
      • Transformation & Leadership
  • GXP Consulting
    • GMP Beratung
      • Audits & inspections
      • GMP/GXP training courses
      • GMP Aircheck4
      • Continuous Manufacturing
  • Industries
    • Pharma
    • Service providers & trade
    • Automotive
    • FOOD & BEVERAGES
    • Financial service providers & insurances
    • Informationstechnik (IT)
    • Aerospace
  • Academy
    • Individuelle Inhouse-Schulungen
      • GMP/GXP training courses
    • Experts Institut Events
      • Academy
    • Direkt buchen
      • Live-Events
      • On-Demand Webinar
  • Kunden
  • Über uns
    • Über uns
      • Guideline
      • Portrait
      • Team
      • Geschäftsführung
      • Vision
      • Events
      • History Experts Institute
      • Sustainability at the Experts Institute
      • Social responsibility
    • Wissen
      • Newsroom
      • GMP Glossary
      • FAQ – Frequently asked questions in the GMP environment
      • Videos
    • Services
      • Retaxation
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Link to LinkedIn
  • Link to Xing
Business Solutions

ISMS 2024: What companies need to know now about NIS2, DORA, CRA and ISO/IEC 42001

Informationssicherheit
  • Zuletzt aktualisiert vor:2 weeks 
  • Lesezeit:3Minuten
  • Anzahl Wörter:474Wörter

The demands on information security are increasing rapidly and with them the regulatory pressure. Cyber attacks such as ransomware, supply chain attacks and targeted attacks on critical infrastructures have long been part of everyday life. At the same time, NIS2, DORA, CRA and ISO/IEC 42001 are four key regulations that affect companies of all sizes and from all industries. A structured ISMS (Information Security Management System) thus becomes the indispensable basis for a legally compliant and resilient security architecture. Those who fail to act now risk not only fines, but also considerable competitive disadvantages.

ISMS

NIS2 – The new basic requirement for many companies

The revised NIS2 Directive will apply from October 2024. Companies with 50 or more employees or an annual turnover of over 10 million euros may already be affected, especially if they operate in critical sectors. The most important requirements include the introduction of an information security management system (ISMS), regular risk analyses, business continuity measures and reporting obligations for security incidents. The management bears personal liability. Our tip: Start with a gap analysis to determine your current implementation status.

DORA – Resilience for the financial sector

From January 2025, DORA will be mandatory for all financial companies in the EU. Banks, insurance companies and relevant IT service providers must strengthen their digital resilience, ICT risk management and incident reporting. Here too, an early GAP analysis and review of existing emergency management systems is recommended.

CRA and ISO/IEC 42001 – Security for digital products and AI

The Cyber Resilience Act (CRA) will regulate the entire value chain of digital products – from development to marketing – from 2026. Manufacturers, developers and importers of hardware and software are obliged to implement “security by design” and establish vulnerability management. The new ISO/IEC 42001, in turn, is the international standard for the secure handling of artificial intelligence and addresses AI-specific risks such as bias, lack of transparency and lack of traceability.

Recommendations for a future-proof ISMS strategy

Companies should now prioritize measures, carry out GAP analyses and integrate new standards such as ISO 42001 into existing management systems. Raise awareness among managers and specialist departments, because information security is no longer just an IT task, but a strategic core function.

Conclusion:

A holistic ISMS that integrates IT, OT, AI, data protection and business continuity is the basis for sustainable security and compliance. Those who act early minimize risks and secure clear competitive advantages. We are happy to support you from the GAP analysis to the implementation of practical solutions.

Would you like to find out more or get started right away?
Contact our team – together we can make your company fit for the new information security requirements! Get ahead and in touch with us – info@expertsinstitut.de

Read our entire blog: https://experts-institut.de/newsroom/
And feel free to follow us on LinkedIn: https://de.linkedin.com/company/expertsinstitut

Carsten Pickel
Carsten Pickel

Consultant & Datenschutzbeauftragter von Experts Institut

Fachgebiete:

  • Zertifizierter Datenschutzbeauftragter
  • Microsoft 365 und Azure Active Directory Administration
  • Interner Auditor
  • Projektmanagement
  • Datenschutz
  • Informationssicherheit (BSI-Grundschutz, ISO2700X, ISO27701, TISAX, B3S/KritisV)
  • Qualitätsmanagement
  • Business Continuity Management
  • Risikomanagement
  • Prozessmanagement & Optimierung
  • Internes Kontrollsystem (IT-/Prozesskontrolle)
  • Audit & Prüfungsbegleitung (ISO27001, ISA315, ISAE3000)

Consultant mit Schwerpunkten in den Themengebieten Informationssicherheit, Business Continuity Management, Risikomanagement, IT-Compliance, Qualitätsmanagement, Digitalisierung & Transformation

2 weeks /by Carsten Pickel
Tags: CRA, DORA, Information security, ISMS, ISO/IEC 42001, NIS2
Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on LinkedIn
  • Share by Mail
https://experts-institut.com/wp-content/uploads/2025/07/LinkedIn-Kopie.png 1080 1920 Carsten Pickel https://experts-institut.de/wp-content/uploads/2023/02/GEMI_Logo_Slogan_color_RGB.webp Carsten Pickel2025-07-03 12:32:392025-07-03 12:32:50ISMS 2024: What companies need to know now about NIS2, DORA, CRA and ISO/IEC 42001
You might also like
Informationssicherheit Information security – a must for modern companies
Recent
  • Informationssicherheit
    ISMS 2024: What companies need to know now about NIS2, DORA,...2 weeks 
  • Deviation Management
    Enhancing Process Stability through Effective Deviation...27. March 2025 - 11:07
  • Supplier-Audit Reports
    Untrue Supplier-Audit Reports: The Danger of Ethnocentric...9. January 2025 - 11:29
  • Qualitätssicherungsvereinbarungen
    Insights into our project experience: Successful implementation...4. December 2024 - 8:59
Popular
  • Computergestützte Systeme
    Computerized systems (CS)2. May 2024 - 8:47
  • Retaxation
    Retaxation – a lucrative instrument for health insurance...16. July 2024 - 9:12
  • Cultures in Audits & Inspections
    Crossing Cultures in Audits and Inspections30. July 2024 - 9:14
  • Cultures in Audits & Inspections
    Crossing Cultures in Audits and Inspections1. August 2024 - 9:38

Tags

AI AI Annex Annex 11 Artificial Intelligence Audit audits Cannabis Certification Clean room Computerized systems CRA Cultures Cytostatics Data Integrity DORA Draft Germ count Germ count monitoring GMP GXP Health insurance Information security inspections ISMS ISO/IEC 42001 ISO 27001 ISO standard Laboratory Machine Learning NIS-2 NIS2 Pharmacy Reagents Regulations Retaxation Sustainability Transformation

Kategorien

  • Business Solutions
  • GMP
  • GXP
  • News
  • Retaxation
  • Sustainability
  • Uncategorized

Archiv

  • July 2025 (1)
  • March 2025 (1)
  • January 2025 (1)
  • December 2024 (1)
  • November 2024 (1)
  • October 2024 (3)
  • September 2024 (2)
  • August 2024 (2)
  • July 2024 (2)
  • May 2024 (1)
  • April 2024 (2)
  • March 2024 (2)
  • February 2023 (10)

Neustadt

Experts Institut Beratungs GmbH
Kirchwiesenstrasse 5

D-67434 Neustadt a. d. Weinstraße

Phone: +49 (0)6321 969210
E-mail: info@expertsinstitut.de

Fax: +49 (0)6321 9692199

Bamberg

Experts Institut Beratungs GmbH
Untere Sandstraße 53

D-96047 Bamberg

Phone: +49 (0)951 51939330
E-mail: info@expertsinstitut.de

Freiburg

Experts Institut Beratungs GmbH
Habsburgerstrasse 101a

D-79104 Freiburg im Breisgau

Phone: +49 (0)6321 9692120
E-mail: info@expertsinstitut.de

St. Gilgen (Austria)

Experts Institut Beratungs GmbH
Helenenstrasse 16

A-5340 St. Gilgen, Austria

Tel.: +43 (0)6227 21068
E-mail: info@expertsinstitut.de

kununu
  • Link to LinkedIn
  • Link to Xing

© 2024 Experts Institut Beratungs GmbH
  • Imprint
  • Data protection
  • AGBs
  • Cookie Directive (EU)
Link to: Enhancing Process Stability through Effective Deviation Management Link to: Enhancing Process Stability through Effective Deviation Management Enhancing Process Stability through Effective Deviation ManagementDeviation Management
Scroll to top Scroll to top Scroll to top