Skip to main content
ServicesComplianceAboutContact
Free assessment

Professional cybersecurity services. Protecting your business from modern threats.

ServicesPenetration TestingSOC as a ServiceVulnerability ManagementCloud SecuritySecurity Training
ComplianceISO 27001 ReadinessGDPR ComplianceNIS2 Directive
CompanyAbout UsContactLet's talkBlog
© 2026 IT Baseline OOD (EIK: 202950882). All rights reserved.
Privacy PolicyTerms of ServiceCookies
Compliance

NIS2 is here.Are you ready?

Expanded scope, stricter requirements, personal liability for management. We help you determine if NIS2 applies to you and build a clear path to compliance.

Am I affected by NIS2?Get a compliance quote

Penalties reach 10 million euro or 2 percent of turnover, early warning is due within 24 hours, and 18 sectors are in scope.

Does it apply to you?

Essential entitiesHigh scrutiny
Critical infrastructure, strict requirements
EnergyTransportBankingHealthcareWater supplyDigital infrastructure
Penalties up to €10M or 2% of global turnover
Important entitiesLighter regime
Extended scope, proportionate obligations
ManufacturingPostalFoodChemicalDigital providers
Penalties up to €7M or 1.4% of global turnover

Criteria: 50+ employees or €10M+ turnover, within a covered sector

Key requirements

R/01
Risk Management
  • /Risk assessment
  • /Security policies
  • /Technical measures
R/02
Incident Handling
  • /Detection
  • /Response
  • /Recovery
R/03
Business Continuity
  • /BCP / DRP
  • /Backup systems
  • /Crisis management
R/04
Supply Chain
  • /Vendor assessment
  • /Third-party risk
  • /Contractual security

Incident reporting clock

24h
Early warning

For significant incidents, notify your CSIRT within a day.

72h
Incident notification

Update with an initial assessment of severity and impact.

1mo
Final report

Detailed analysis, root cause and mitigation measures.

What changed

AspectNIS1NIS2
Scope7 sectors, ~400 operators18+ sectors, 10,000+ organizations
PenaltiesLeft to member states€10M or 2% of turnover
Incident reportingNo specific deadlines24h early warning, 72h notification
Management liabilityNoYes, personal responsibility

Questions, answered.

Does my organization fall under NIS2?+

NIS2 covers Essential entities (energy, transport, banking, healthcare) and Important entities (postal services, manufacturing, digital providers). Criteria are size, over 50 employees or €10M turnover, and sector.

What are the penalties?+

Up to €10M or 2% of global annual turnover for Essential entities; up to €7M or 1.4% for Important entities. Management bears personal responsibility.

How does NIS2 relate to ISO 27001?+

ISO 27001 covers many NIS2 requirements, but the directive adds specifics, incident reporting deadlines, supply chain security, management accountability. ISO certification is an excellent foundation.

Is the NIS2 deadline already passed?+

Yes. The transposition deadline was October 17, 2024, and enforcement is now active. If your organization hasn't started compliance, act now, regulators are already conducting reviews.

Fines up to €10M. Management personally liable.
Find out if NIS2 applies to you, and what to do next
Check if NIS2 applies