Compliance · Cybersecurity regulation
NIS2, from directive to evidence.
The EU's cybersecurity directive for essential and important entities — mandatory risk-management measures, tight incident reporting and personal accountability for management.
- 18sectors in scope
- 24 hearly-warning deadline
- 2%of turnover, top fine tier
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union
NIS2 replaced the original 2016 NIS Directive and had to be transposed by member states by 17 October 2024. It widens scope to eighteen sectors — energy, transport, banking, financial-market infrastructure, health, water, digital infrastructure, ICT service management, public administration and space among the high-criticality ones; postal, waste, chemicals, food, manufacturing, digital providers and research among the others — and applies to medium and large entities in them, plus some regardless of size.
Entities are classified as essential or important, with the same obligations but different supervision and penalties. Article 21 lists ten risk-management measures every entity must implement, Article 23 sets a three-step incident-reporting timeline, and Article 20 makes management bodies responsible for approving the measures, overseeing them and undergoing training.
Non-EU organisations are pulled in two ways: as suppliers, because supply-chain security is one of the ten measures and EU customers push requirements down their contracts; and, for digital providers offering services in the EU, directly. Moldova's own Cybersecurity Law follows the same model, so alignment serves both markets.
What the framework demands
The obligations an auditor or supervisor will test, in plain language.
Risk analysis and security policies
A documented, management-approved risk-management framework with security policies covering all network and information systems.
Incident handling
Detection, analysis, containment, recovery and lessons learned, with the capability to meet the Article 23 reporting clock.
Supply-chain security
Security requirements in supplier contracts, assessment of direct suppliers and service providers, and awareness of vulnerabilities specific to each.
Business continuity and crisis management
Backup management, disaster recovery and crisis procedures — tested rather than filed.
Incident reporting — 24 h / 72 h / 1 month
Early warning to the CSIRT or competent authority within 24 hours of awareness of a significant incident, an incident notification with initial assessment within 72 hours, and a final report within one month.
Secure acquisition, development and maintenance
Security in procurement and development, and a vulnerability-handling and disclosure process.
Effectiveness assessment, hygiene and training
Policies to assess whether measures work, basic cyber-hygiene practices, and cybersecurity training for staff and management.
Cryptography, access control and asset management
Policies on encryption, human-resources security, access control, asset management, and multi-factor or continuous authentication and secured communications.
The cost of getting it wrong
- Fines up to €10 million or 2% of global turnover for essential entities; €7 million or 1.4% for important entities
- Personal liability for management bodies, including possible temporary bans from management functions at essential entities
- Binding instructions, audits and public-disclosure orders from supervisory authorities
- Exclusion from EU supply chains by customers who must vet their providers
From gap to evidence
Assessment, remediation, documentation and audit support — run as one programme.
- 01
Scoping and classification
We determine whether and how you fall under NIS2 or the national transposition — as an essential or important entity or as a supplier — and which authority you report to.
- 02
Gap assessment against Article 21
A measure-by-measure review of the ten domains and the Article 23 reporting capability, producing a prioritised roadmap.
- 03
Controls implementation
Our security team implements the technical measures — MFA, logging and detection, backup and recovery, vulnerability management, supplier controls — and drafts the policies.
- 04
Incident-reporting readiness
Playbooks and drills so a 24-hour early warning is achievable, plus templates for the 72-hour notification and one-month final report.
- 05
Governance and management training
Board-level approval and oversight processes and the management training Article 20 requires, with metrics for ongoing assurance.
Deliverables
- Scope and classification memo (essential / important / supplier)
- Gap assessment against Article 21 measures and Article 23 reporting
- Risk-management framework and policy set
- Implemented technical controls with evidence
- Incident-reporting playbooks and tested drills
- Supplier-security requirements and assessment programme
- Management training and governance pack
Questions we hear most
We are outside the EU. Does NIS2 reach us?
Directly, if you provide digital services into the EU and meet the thresholds; indirectly — and more commonly — through customers who must secure their supply chain and will flow requirements into contracts. Moldova's Cybersecurity Law follows the same structure, so one programme serves both.
What counts as a significant incident?
One that has caused or can cause severe operational disruption or financial loss, or has affected or can affect others by causing considerable damage. The 24-hour early warning applies from the moment you become aware of it.
How does NIS2 relate to ISO 27001?
Closely. An ISO 27001 ISMS covers most Article 21 measures; NIS2 adds sector supervision, hard reporting deadlines and management accountability. We map the two so evidence is collected once.
Does NIS2 apply to small companies?
Generally it applies to medium-sized and larger entities, but some — such as DNS, TLD, trust-service and certain digital-infrastructure providers, or sole providers of a critical service — are in scope regardless of size.
Often pursued together
Ready to Transform Your Business?
Let's discuss how our expertise in IT security, development, and DevOps can help you achieve your goals.