NIS2 Directive
The NIS2 Directive (Directive EU 2022/2555) is the European Union's updated cybersecurity law, replacing the original 2016 NIS Directive. It expands the scope of regulated organizations and raises the bar for cyber risk management, applying to "essential" and "important" entities across 18 sectors - from energy, transport, and banking to health, digital infrastructure, and managed service providers.
At its core, NIS2 is built around risk management measures, corporate accountability, incident reporting, and business continuity. It requires a baseline of technical and organizational controls, reporting of significant incidents within strict deadlines: an early warning within 24 hours, an incident notification within 72 hours, and a final report generally within one month. Management bodies must approve and oversee cybersecurity risk-management measures.
It exists to create a consistent, high level of cyber resilience across the EU - closing the gaps and uneven enforcement of the original directive as threats to critical services grow. We help you interpret how NIS2 applies to your organization and build the controls, processes, and governance needed to meet it.
Are you in scope for NIS2?
NIS2 reaches far more organizations than the original directive. A quick check:
You likely need this if
- You operate in energy, transport, banking, health, water, digital infrastructure, public administration or another covered sector or service.
- You are a medium or large entity (roughly 50+ staff or €10M+ annual turnover), or a smaller entity providing critical services.
- You supply in-scope organisations and are being asked to meet their supply-chain security requirements.
- You are unsure whether you count as an essential or an important entity
Not sure where you land? A short assessment call will tell you plainly, including if you do not need this yet.
How We Help You Comply
From gap analysis to fully operational controls, we guide you through every NIS2 requirement.
We determine whether your organization qualifies as an essential or important entity, map the sectors and services in scope, and clarify your specific obligations under national NIS2 transpositions.
A structured review of your current security posture against the NIS2 baseline measures - covering risk analysis, incident handling, supply chain security, access control, and cryptography - with a prioritized remediation roadmap.
We design the detection, triage, and escalation processes needed to support the applicable 24-hour early warning, 72-hour incident notification, and final-report requirements, generally within one month, including playbooks and communication templates for your CSIRT and authorities.
Support for board-level oversight, security training for management, and the documented policies and responsibilities management bodies must approve and supervise under NIS2.
Assessment and hardening of your supplier and service provider relationships, aligning vendor risk management with NIS2's supply chain security expectations.
Turn Compliance Into Resilience
NIS2 is an opportunity to strengthen how your organization detects, responds to, and recovers from incidents. We translate each legal requirement into concrete technical controls and operational processes, so you meet your obligations and genuinely reduce risk to the services you deliver. Every measure we implement is documented and audit-ready. This page is for general information and does not constitute legal advice or a formal NIS2 applicability assessment.