Compliance · Cybersecurity regulation

NIS2, from directive to evidence.

The EU's cybersecurity directive for essential and important entities — mandatory risk-management measures, tight incident reporting and personal accountability for management.

  • 18sectors in scope
  • 24 hearly-warning deadline
  • 2%of turnover, top fine tier
What it is

Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union

NIS2 replaced the original 2016 NIS Directive and had to be transposed by member states by 17 October 2024. It widens scope to eighteen sectors — energy, transport, banking, financial-market infrastructure, health, water, digital infrastructure, ICT service management, public administration and space among the high-criticality ones; postal, waste, chemicals, food, manufacturing, digital providers and research among the others — and applies to medium and large entities in them, plus some regardless of size.

Entities are classified as essential or important, with the same obligations but different supervision and penalties. Article 21 lists ten risk-management measures every entity must implement, Article 23 sets a three-step incident-reporting timeline, and Article 20 makes management bodies responsible for approving the measures, overseeing them and undergoing training.

Non-EU organisations are pulled in two ways: as suppliers, because supply-chain security is one of the ten measures and EU customers push requirements down their contracts; and, for digital providers offering services in the EU, directly. Moldova's own Cybersecurity Law follows the same model, so alignment serves both markets.

The requirements

What the framework demands

The obligations an auditor or supervisor will test, in plain language.

Risk analysis and security policies

A documented, management-approved risk-management framework with security policies covering all network and information systems.

Incident handling

Detection, analysis, containment, recovery and lessons learned, with the capability to meet the Article 23 reporting clock.

Supply-chain security

Security requirements in supplier contracts, assessment of direct suppliers and service providers, and awareness of vulnerabilities specific to each.

Business continuity and crisis management

Backup management, disaster recovery and crisis procedures — tested rather than filed.

Incident reporting — 24 h / 72 h / 1 month

Early warning to the CSIRT or competent authority within 24 hours of awareness of a significant incident, an incident notification with initial assessment within 72 hours, and a final report within one month.

Secure acquisition, development and maintenance

Security in procurement and development, and a vulnerability-handling and disclosure process.

Effectiveness assessment, hygiene and training

Policies to assess whether measures work, basic cyber-hygiene practices, and cybersecurity training for staff and management.

Cryptography, access control and asset management

Policies on encryption, human-resources security, access control, asset management, and multi-factor or continuous authentication and secured communications.

What's at stake

The cost of getting it wrong

  • Fines up to €10 million or 2% of global turnover for essential entities; €7 million or 1.4% for important entities
  • Personal liability for management bodies, including possible temporary bans from management functions at essential entities
  • Binding instructions, audits and public-disclosure orders from supervisory authorities
  • Exclusion from EU supply chains by customers who must vet their providers
Typical timeline3–6 months to a defensible programme, depending on sector and starting maturity
How we help

From gap to evidence

Assessment, remediation, documentation and audit support — run as one programme.

  1. 01

    Scoping and classification

    We determine whether and how you fall under NIS2 or the national transposition — as an essential or important entity or as a supplier — and which authority you report to.

  2. 02

    Gap assessment against Article 21

    A measure-by-measure review of the ten domains and the Article 23 reporting capability, producing a prioritised roadmap.

  3. 03

    Controls implementation

    Our security team implements the technical measures — MFA, logging and detection, backup and recovery, vulnerability management, supplier controls — and drafts the policies.

  4. 04

    Incident-reporting readiness

    Playbooks and drills so a 24-hour early warning is achievable, plus templates for the 72-hour notification and one-month final report.

  5. 05

    Governance and management training

    Board-level approval and oversight processes and the management training Article 20 requires, with metrics for ongoing assurance.

What you get

Deliverables

  • Scope and classification memo (essential / important / supplier)
  • Gap assessment against Article 21 measures and Article 23 reporting
  • Risk-management framework and policy set
  • Implemented technical controls with evidence
  • Incident-reporting playbooks and tested drills
  • Supplier-security requirements and assessment programme
  • Management training and governance pack
FAQ

Questions we hear most

We are outside the EU. Does NIS2 reach us?

Directly, if you provide digital services into the EU and meet the thresholds; indirectly — and more commonly — through customers who must secure their supply chain and will flow requirements into contracts. Moldova's Cybersecurity Law follows the same structure, so one programme serves both.

What counts as a significant incident?

One that has caused or can cause severe operational disruption or financial loss, or has affected or can affect others by causing considerable damage. The 24-hour early warning applies from the moment you become aware of it.

How does NIS2 relate to ISO 27001?

Closely. An ISO 27001 ISMS covers most Article 21 measures; NIS2 adds sector supervision, hard reporting deadlines and management accountability. We map the two so evidence is collected once.

Does NIS2 apply to small companies?

Generally it applies to medium-sized and larger entities, but some — such as DNS, TLD, trust-service and certain digital-infrastructure providers, or sole providers of a critical service — are in scope regardless of size.

Get Started

Ready to Transform Your Business?

Let's discuss how our expertise in IT security, development, and DevOps can help you achieve your goals.