No. Only government bodies such as the German Armed Forces or security authorities are exempt. Private manufacturers and suppliers are subject to NIS2 like any other company, provided they meet the size thresholds.
No. ISO 27001 covers general information security and provides a good foundation. As soon as classified information from VS-NfD level upward is involved, additional requirements apply, such as BSI-approved encryption and the need-to-know principle.
CADIS is an industry-specific certification standard that builds on ISO 27001 and NIST frameworks and adds topics such as physical security and export control. On request, we factor in CADIS requirements as standard right from the ISMS setup, so you don't have to build things twice.
That depends heavily on your company's scope and starting point, so a blanket timeframe here wouldn't be credible. The baseline assessment at the start shows what scope and timeframe is realistic for you.
That depends on your starting point and the scope you need. We'll work that out together with you in the free initial consultation.