Free GDPR test Is your company compliant? · 5 min →
Home Solutions Artificial Intelligence Partner Program Insights Free consultation — 30 min →
MANDATORY SINCE OCTOBER 2024

NIS2 Readiness
for your business.

The NIS2 Directive massively expands the scope of the previous NIS: more sectors, more companies, more obligations. Fines reach up to €10 million or 2% of global turnover — and directors face personal liability. We assess your situation and get you compliant.

Free NIS2 test — 5 min Talk to an expert

Free evaluation · Response within 24h · No commitment

18+
critical sectors subject to NIS2 across the EU
10M€
maximum fine for essential entities
24h
early warning deadline for significant incidents
Who does it apply to?

Sectors subject to
the NIS2 Directive

NIS2 distinguishes between essential entities (high criticality) and important entities. Both are obliged — fines differ in maximum amount.

Energy
Essential
Transport
Essential
Banking & Finance
Essential
Healthcare
Essential
Drinking & Waste Water
Essential
Digital Infrastructure
Essential
Postal Services
Important
Waste Management
Important
Critical Manufacturing
Important
Chemical Industry
Important
Food Sector
Important
ICT Service Providers
Important
NIS2 obligations

What NIS2 requires
from your organisation

Art. 21 — Risk management measures

Cybersecurity risk management

Risk analysis policies, information systems security, business continuity plans and crisis management. Not optional — it must be documented and kept up to date.

Art. 23 — Incident reporting

Incident notification within 24h

Early warning within 24 hours, full notification within 72 hours and final report within one month. Organisations must have the protocol in place before an incident occurs.

Art. 20 — Governance

Management responsibility

Governing bodies must approve risk management measures and oversee their implementation. Management ignorance is not an excuse — it is an aggravating circumstance.

Art. 21 — Supply chain

Supply chain security

NIS2 requires reviewing the security of suppliers and subcontractors. A breach originating from a poorly managed supplier is your responsibility — and your fine.

Art. 21 — Technical measures

Encryption and multi-factor authentication

End-to-end encryption and multi-factor authentication (MFA) on critical systems become requirements, not recommendations. This includes voice, video and text communications.

Art. 20 — Training

Cybersecurity training

Members of the governing body must receive regular cybersecurity training — and must actively encourage all employees to receive it too.

NIS2 non-compliance has personal consequences.

Unlike the previous NIS directive, NIS2 introduces personal liability for executives: the heads of the organisation can be found guilty and sanctioned individually. It's not just a risk for the company — it's a risk for the people who run it.

  • Temporary ban from exercising management functions
  • Civil and criminal liability for directors
  • Public disclosure of non-compliance (naming and shaming)
  • Supervision by the competent authority
10M€
ESSENTIAL ENTITIES
OR 2% GLOBAL TURNOVER
7M€
IMPORTANT ENTITIES
OR 1.4% GLOBAL TURNOVER
24h
EARLY WARNING DEADLINE
AFTER AN INCIDENT
Our service

From gap analysis to full
NIS2 compliance

We assess where you are, design the roadmap and execute the technical implementation. With us, compliance is not just documentation.

01

NIS2 applicability assessment

We determine whether your company falls within NIS2's scope (essential vs. important) and which specific obligations apply to you based on your sector, size and type of services.

→ 3-5 working days
02

Cybersecurity gap analysis

We audit your current cybersecurity posture against NIS2 requirements: existing policies, implemented technical measures, incident management, staff training and supplier security.

→ Detailed report
03

Prioritised implementation plan

With the gap analysis in hand, we design an action plan with three horizons: urgent actions (first 4 weeks), structural (3 months) and continuous maturity (12 months).

→ Complete roadmap
04

Technical security implementation

MFA on all critical systems, end-to-end encryption, network segmentation, vulnerability management, SIEM, EDR and verified backups. We don't just recommend — we implement.

→ Real security
05

Incident notification protocol

We design the complete procedure: detection, classification, escalation, 24h notification to the competent authority and communication to those affected. Simulation exercises included.

→ Ready before the incident
06

Supply chain risk management

We review and audit critical suppliers, establish contracts with NIS2-compliant security clauses and implement a continuous third-party evaluation process.

→ Suppliers in order
07

Management and team training

NIS2-specific training for the governing body (legally mandatory) and operational teams. Documented certification proving compliance with the training requirement.

→ Certification included
08

Monitoring and continuous compliance

NIS2 is not a one-off project — it requires continuous vigilance. We provide 24/7 monitoring, quarterly compliance reviews and support during any authority inspection.

→ SOC 24/7 available
How we work

From zero to NIS2-compliant
in 8 weeks

01

Applicability test

5 minutes to find out if your company is subject to NIS2 and in which category.

02

Full gap analysis

2 weeks. Technical and governance audit to map the gap between your current situation and NIS2 requirements.

03

Technical implementation

4-6 weeks. We execute the prioritised plan: MFA, encryption, SIEM, incident protocols and training.

04

Ongoing compliance

Monitoring, quarterly reviews and support during inspections. Compliance doesn't have an expiry date.

Frequently asked questions

Everything you need
to know about NIS2

NIS2 applies to entities operating in the sectors defined in Annexes I and II of the Directive, that exceed certain size thresholds (generally, more than 50 employees or more than €10M in turnover). But there are exceptions: some critical organisations are obliged regardless of size. The free 5-minute test gives you an immediate answer.

GDPR regulates the protection of personal data. NIS2 regulates the cybersecurity of networks and information systems. Although they share some technical measures (such as encryption), they are different regulatory frameworks with different supervisory authorities. Many companies need to comply with both. We manage both without duplicating work.

NIS2 establishes a three-phase process: early warning within 24 hours (notification to the competent authority that a significant incident has occurred), full notification within 72 hours (with details of the incident, impact and measures taken) and a final report within one month. Without the protocol in place, meeting these deadlines is impossible.

Yes. NIS2 explicitly requires obliged organisations to manage security risks in their supply chain. This means you are responsible for verifying that your critical suppliers also have adequate security measures. A security breach originating from a supplier does not exempt you from liability.

It depends on the complexity of the systems, the sector and the current cybersecurity maturity level. For an SME of up to 50 employees in a high-criticality sector, the initial compliance project typically ranges between €8,000 and €20,000. Ongoing maintenance ranges from €2,400 to €6,000 per year. We do a free gap analysis first.

The NIS2 Directive entered into force at EU level in October 2024. Member states are in the process of transposing it into national law. Obliged organisations must comply with the requirements regardless of the status of national transposition — legislative delays do not exempt you from European obligations.

// Start now

Is your company subject
to NIS2?

The free 5-minute test tells you whether your company falls within NIS2's scope, in which category and what your main obligations are. You receive the report by email.