NIS 2 Consulting
NIS2 is the EU cybersecurity directive that expands risk-management, incident-reporting, governance, and resilience expectations for essential and important entities. We turn those requirements into a practical roadmap for your organization, combining gap analysis, technical testing, documentation support, and focused remediation.
Does NIS2 apply to your organization?
Sector and activity
Start with the entity types in Annexes I and II of Directive (EU) 2022/2555. They cover areas including energy, transport, health, water, digital infrastructure, ICT service management, postal services, waste, chemicals, food, selected manufacturing, digital providers and research. National implementation determines the practical route to registration and supervision.
Size, finances and group structure
The general rule covers medium-sized and larger entities in the listed categories. Under the referenced SME definition, being below 50 staff is not enough to qualify as small if both annual turnover and balance sheet total exceed EUR 10 million. Partner and linked enterprises can affect the calculation. National rules may account for an entity’s independence from its group.
Exceptions and specific rules
Some entities are covered regardless of size, including specified communications, trust and DNS service providers. Criticality-based identification and public-administration provisions also matter. Check national law and sector-specific EU rules with legal advisers before concluding that your organization is excluded.
From scope to evidence
We help translate applicable requirements into management accountability, risk controls, incident-reporting processes, supplier oversight, continuity planning and evidence of operation. Supervision and penalties depend on the relevant rules and classification. An assessment supports readiness, it does not guarantee compliance.
What is NIS2?
NIS2 is the EU framework for a higher common level of cybersecurity. It brings more essential and important sectors into scope and requires organizations to manage cyber risk, report significant incidents, and demonstrate that appropriate safeguards are in place.
Current focus
The focus is moving from first-time implementation to continuous compliance, evidence maintenance, and repeat assurance. Organizations that are late on an audit or approaching a future cycle should act early to understand their gaps and plan the work.
European Commission NIS2 overviewNIS2 timeline
- 2022
NIS2 is adopted at EU level, replacing the earlier NIS1 framework.
- 2023
The Directive enters into force.
- 17 Oct 2024
The national transposition deadline is 17 October 2024, with national measures to apply from 18 October 2024.
- 2025 →
Organizations move through registration, readiness, audit, remediation, and recurring compliance cycles.
Audit support
If your organization is behind on its first audit or preparing for a future one, we can assess the current position, prioritize remediation, organize the required evidence, coordinate with an authorized auditor, and support the process through completion.