NIS2 Compliance Made Clear. The NIS2 Directive raises the bar for cybersecurity across the EU. ARLITECH guides your organization from gap analysis to full compliance, efficiently and without disruption.
NIS2 (Network and Information Security Directive 2) significantly expands the scope of the original NIS Directive. It applies to organizations in critical and important sectors across the EU and introduces stricter security requirements, incident reporting obligations and substantial penalties for non-compliance.
Organizations must demonstrate proactive risk management, supply chain security, business continuity planning and regular security testing, all within tight timelines.
Essential entities (energy, transport, banking, health, water) and important entities (digital infrastructure, manufacturing, waste).
Up to €10M or 2% of global annual turnover for essential entities. Non-compliance carries reputational and operational risk.
24-hour early warning, 72-hour incident notification and 1-month final report requirements for significant incidents.
NIS2 extends to suppliers and service providers, organizations must assess and manage third-party cyber risk.
We assess your current security posture against NIS2 requirements and identify gaps, priorities and estimated effort.
A structured implementation plan with milestones, resource requirements and risk-prioritized remediation actions.
Deployment of required security controls: MFA, logging, network segmentation, vulnerability management and more.
Development of NIS2-aligned security policies, procedures, risk registers and incident response plans.
Role-specific cybersecurity awareness training and tabletop exercises to build organizational resilience.
Continuous compliance monitoring, annual reassessments and regulatory update tracking to maintain compliance over time.
Compliance is not a document-production exercise. We work in four stages, and each stage ends with an output that is usable on its own, even if the project is later rescheduled.
We determine and document in writing whether the organisation falls under Act XXIII of 2023, and if so, under which annex. The result is a documented position even if the answer is negative.
We work through all ten measure areas of the law and record where the organisation stands today. Interviews, document review and technical verification combined, not a questionnaire exercise.
A risk-weighted roadmap with owners, deadlines and estimated effort. Quick wins highlighted separately, so there are measurable results in the first weeks.
Delivering the technical and organisational measures, then organising the evidence: policy, operational trace, owner and review frequency for every measure.
NIS2 does not start from a blank page. If a management system is already in place, much of it can be carried across, we perform this mapping in the first step of the gap analysis.
| NIS2 measure | Related standard | What can be reused |
|---|---|---|
| 1. Risk analysis | ISO 27001 (6.1, 8.2) | Existing risk management methodology and register |
| 2. Incident handling | ISO 27035 / ISO 27001 A.5.24–5.28 | Procedure, extended with reporting deadlines |
| 3. Business continuity | ISO 22301 | BCP/DRP, impact analysis, restore testing |
| 4. Supply chain | ISO 27001 A.5.19–5.23 | Supplier register and contractual clauses |
| 5. Vulnerability handling | ISO 27001 A.8.8 | Patch process, testing regime |
| 7. Training | ISO 27001 A.6.3 | Awareness programme, extended with a management module |
| 9. Access control | ISO 27001 A.5.15–5.18, A.8.1 | Access matrix, asset inventory |
| In OT environments | IEC 62443-2-1 / -3-2 | Zone-and-conduit model, Security Level classification |
Two things must be assessed together: sector and size. The sectors are listed in the two annexes to Act XXIII of 2023, and the size threshold is by default at least 50 employees, or turnover and balance sheet total exceeding EUR 10 million. Importantly, an organisation can fall in scope below the size threshold, for example if it is the sole provider of a given activity, or if it is a public administration body. Always start the assessment with the sector rather than headcount, and note that scope applies to the legal entity, not the group.
The gap analysis and prioritised plan typically take 4–6 weeks. Full implementation depends on the starting point: with a working ISO 27001 management system, 3–6 months is realistic; starting from zero, 9–15 months is more likely. Quick wins (MFA, asset inventory, incident reporting template, management training) can however be delivered in the first 4–8 weeks, and these cover a significant share of the risk.
No, but it helps considerably. The Annex A controls overlap heavily with the ten measures, so much of the work carries across. NIS2 goes beyond ISO 27001 in three respects, however: the strict incident reporting deadlines (24 hours / 72 hours / 1 month), the personal liability and training obligation of the management body, and the level of detail in supply chain requirements. Those gaps must be closed separately.
Under the law, the management body, and that accountability cannot be delegated to the IT manager. Management approves the measures, oversees implementation, is liable for failures, and must attend regular cybersecurity training. Approval and training must be documented; an inspection typically asks for this first. A cybersecurity contact person must also be appointed for communication with the authority.
One that causes severe operational disruption or financial loss, or that is capable of causing considerable material or non-material damage to other natural or legal persons. The threshold must be defined in writing in advance, mid-incident is not the time to debate whether something is reportable. Reporting is three-stage: early warning within 24 hours, incident notification within 72 hours, final report within one month.
Yes (if your sector is manufacturing, energy, water or transport, scope extends to industrial control systems. Much of the standard IT toolkit does not apply there: PLCs cannot be patched on a schedule, and active network scanning can cause damage. The OT side is best delivered along the IEC 62443 family of standards) we covered this in detail on our OT/ICS security page and in our ICS/SCADA article.