← All posts

Zero Trust Becomes the Standard: What NIS-2 Now Requires of Companies

In 2026, Zero Trust has become the standard, and NIS-2 makes it mandatory for around 30,000 companies. What is behind it, and how to get there.

Zero Trust Becomes the Standard: What NIS-2 Now Requires of Companies (KAEMI)

Zero Trust has gone from buzzword to standard. What long counted as a topic for the future is becoming the foundation of every serious security architecture in 2026. The trigger is not technology alone but regulation: with NIS-2, a Zero Trust approach becomes a de facto obligation for around 30,000 companies in Germany, including personal liability for executive management. NIS-2 requires exactly this kind of proof.

Why the castle-wall model no longer holds

For decades, the rule was: trustworthy inside, dangerous outside. A strong firewall at the edge was supposed to protect the internal network. Three developments have dissolved that picture: data and applications live in the cloud, employees work from anywhere, and partners are deeply embedded in internal processes. The classic perimeter no longer has a clear boundary.

The real problem shows up after the initial intrusion. Once inside a flat network, an attacker is treated by the systems like a trusted colleague and keeps moving laterally. Exactly this lateral movement turns a small incident into company-wide damage.

Zero Trust is not a product

Zero Trust cannot be bought, and it is not a firewall replacement. It is an architectural principle that starts from a sober assumption: an attacker may already be in the network (assume breach). Three ground rules follow from that:

  • Every connection is verified, regardless of whether it comes from inside or outside.
  • No trust by default, neither for users nor for servers or services.
  • Segmentation, so that one compromised system does not drag down the entire company.

Three pillars carry the model

In practice, Zero Trust rests on three pillars:

  • Identity: Multi-factor authentication (MFA) becomes the minimum standard for all access, explicitly including administrative and service accounts. Identity becomes the actual perimeter.
  • [Microsegmentation](/mikrosegmentierung/): Critical systems are isolated from one another, and communication between the zones is controlled. That keeps an incident locally contained.
  • Continuous verification: Access is reassessed on an ongoing basis. Login is the start of the check, not its end.

Secure, identity-based access to applications comes from a SASE/SSE architecture : verified access instead of open network access, delivered from the cloud and the same at every location.

NIS-2 makes Zero Trust binding

With NIS-2, cybersecurity is no longer a voluntary project for many companies. The requirements affect around 30,000 organizations in Germany and demand, among other things, continuous authentication, MFA, network segmentation, least-privilege access, and supply chain security. Violations carry fines of up to 10 million euros or two percent of global annual revenue, and executive management is personally liable.

These requirements read like a Zero Trust checklist. Anyone who implements NIS-2 properly is, in effect, building a Zero Trust architecture.

How mature is the market?

The trend is clear; the maturity is not. According to Gartner, around 63 percent of organizations worldwide have started with Zero Trust, but for most it covers less than half of the IT environment. For 2026, Gartner expects only about 10 percent of large enterprises to have a truly mature program in place.

The incident numbers show why the effort pays off. The Verizon Data Breach Investigations Report 2025 cites ransomware in 44 percent of data breaches, stolen credentials as the entry point in 22 percent, and external partners in around 30 percent of cases. The advantage comes from depth, not from a quick start.

Getting there happens in phases

Zero Trust is not a cutover date. It is a journey over several years, and three phases have proven themselves:

  • Inventory: First, critical processes, data, and communication flows are mapped. This map is the foundation of any targeted architecture.
  • MFA across the board: Multi-factor authentication without exceptions delivers the best ratio of effort to protection, especially for service accounts that have gone untouched for a long time.
  • Segmentation step by step: Instead of converting the entire network at once, we secure the critical processes first. That builds protection early without blocking everyday operations.

The most common mistake is to see Zero Trust as a project with an end date. Realistically, it takes three to five years to reach maturity, with ongoing care rather than a one-time investment. That is exactly why half-finished implementations often produce islands of security instead of end-to-end coverage.

Zero Trust with KAEMI

As a managed security service provider, KAEMI supports this journey from the analysis through to a permanent managed service. We assess your environment, design the target architecture, and implement it without interruption: Professional Services for consulting and implementation, plus SASE/SSE, ZTNA, and microsegmentation as an ongoing managed service. This turns the obligation into a resilient standard.

Want to know where your environment stands today? Talk to us .

*This article draws on a specialist piece by Beck Consult: Zero Trust: The New Security Standard .*

Want to secure access consistently with Zero Trust?

KAEMI designs, implements and manages SASE/SSE with Cloudflare One: ZTNA instead of VPN, verified access from anywhere — as a managed service.