Expanded scope, stricter requirements, personal liability for management. We help you determine if NIS2 applies to you and build a clear path to compliance.
Penalties reach 10 million euro or 2 percent of turnover, early warning is due within 24 hours, and 18 sectors are in scope.
Criteria: 50+ employees or €10M+ turnover, within a covered sector
For significant incidents, notify your CSIRT within a day.
Update with an initial assessment of severity and impact.
Detailed analysis, root cause and mitigation measures.
NIS2 covers Essential entities (energy, transport, banking, healthcare) and Important entities (postal services, manufacturing, digital providers). Criteria are size, over 50 employees or €10M turnover, and sector.
Up to €10M or 2% of global annual turnover for Essential entities; up to €7M or 1.4% for Important entities. Management bears personal responsibility.
ISO 27001 covers many NIS2 requirements, but the directive adds specifics, incident reporting deadlines, supply chain security, management accountability. ISO certification is an excellent foundation.
Yes. The transposition deadline was October 17, 2024, and enforcement is now active. If your organization hasn't started compliance, act now, regulators are already conducting reviews.