NIS2 Compliance Services

NIS2 Compliance Made Clear. The NIS2 Directive raises the bar for cybersecurity across the EU. ARLITECH guides your organization from gap analysis to full compliance, efficiently and without disruption.

What Is NIS2?

The EU's Updated Cybersecurity Directive

NIS2 (Network and Information Security Directive 2) significantly expands the scope of the original NIS Directive. It applies to organizations in critical and important sectors across the EU and introduces stricter security requirements, incident reporting obligations and substantial penalties for non-compliance.

Organizations must demonstrate proactive risk management, supply chain security, business continuity planning and regular security testing, all within tight timelines.

Who is Affected?

Essential entities (energy, transport, banking, health, water) and important entities (digital infrastructure, manufacturing, waste).

Significant Penalties

Up to €10M or 2% of global annual turnover for essential entities. Non-compliance carries reputational and operational risk.

Incident Reporting

24-hour early warning, 72-hour incident notification and 1-month final report requirements for significant incidents.

Supply Chain Scope

NIS2 extends to suppliers and service providers, organizations must assess and manage third-party cyber risk.

Our Approach

End-to-End NIS2
Compliance Journey

Gap Analysis

We assess your current security posture against NIS2 requirements and identify gaps, priorities and estimated effort.

Compliance Roadmap

A structured implementation plan with milestones, resource requirements and risk-prioritized remediation actions.

Technical Implementation

Deployment of required security controls: MFA, logging, network segmentation, vulnerability management and more.

Policy & Documentation

Development of NIS2-aligned security policies, procedures, risk registers and incident response plans.

Staff Training

Role-specific cybersecurity awareness training and tabletop exercises to build organizational resilience.

Ongoing Support

Continuous compliance monitoring, annual reassessments and regulatory update tracking to maintain compliance over time.

The process

How a NIS2 Project Runs

Compliance is not a document-production exercise. We work in four stages, and each stage ends with an output that is usable on its own, even if the project is later rescheduled.

01

Scope and applicability assessment

We determine and document in writing whether the organisation falls under Act XXIII of 2023, and if so, under which annex. The result is a documented position even if the answer is negative.

02

Gap analysis against the ten measures

We work through all ten measure areas of the law and record where the organisation stands today. Interviews, document review and technical verification combined, not a questionnaire exercise.

03

Prioritised action plan

A risk-weighted roadmap with owners, deadlines and estimated effort. Quick wins highlighted separately, so there are measurable results in the first weeks.

04

Implementation and evidence building

Delivering the technical and organisational measures, then organising the evidence: policy, operational trace, owner and review frequency for every measure.

Deliverables

What You Receive

Standards mapping

What NIS2 Compliance Builds On

NIS2 does not start from a blank page. If a management system is already in place, much of it can be carried across, we perform this mapping in the first step of the gap analysis.

NIS2 measureRelated standardWhat can be reused
1. Risk analysisISO 27001 (6.1, 8.2)Existing risk management methodology and register
2. Incident handlingISO 27035 / ISO 27001 A.5.24–5.28Procedure, extended with reporting deadlines
3. Business continuityISO 22301BCP/DRP, impact analysis, restore testing
4. Supply chainISO 27001 A.5.19–5.23Supplier register and contractual clauses
5. Vulnerability handlingISO 27001 A.8.8Patch process, testing regime
7. TrainingISO 27001 A.6.3Awareness programme, extended with a management module
9. Access controlISO 27001 A.5.15–5.18, A.8.1Access matrix, asset inventory
In OT environmentsIEC 62443-2-1 / -3-2Zone-and-conduit model, Security Level classification
Frequently asked

NIS2: The Questions We Hear Most

How do I know whether we are in scope for NIS2?

Two things must be assessed together: sector and size. The sectors are listed in the two annexes to Act XXIII of 2023, and the size threshold is by default at least 50 employees, or turnover and balance sheet total exceeding EUR 10 million. Importantly, an organisation can fall in scope below the size threshold, for example if it is the sole provider of a given activity, or if it is a public administration body. Always start the assessment with the sector rather than headcount, and note that scope applies to the legal entity, not the group.

How long does compliance take?

The gap analysis and prioritised plan typically take 4–6 weeks. Full implementation depends on the starting point: with a working ISO 27001 management system, 3–6 months is realistic; starting from zero, 9–15 months is more likely. Quick wins (MFA, asset inventory, incident reporting template, management training) can however be delivered in the first 4–8 weeks, and these cover a significant share of the risk.

Is ISO 27001 certification enough?

No, but it helps considerably. The Annex A controls overlap heavily with the ten measures, so much of the work carries across. NIS2 goes beyond ISO 27001 in three respects, however: the strict incident reporting deadlines (24 hours / 72 hours / 1 month), the personal liability and training obligation of the management body, and the level of detail in supply chain requirements. Those gaps must be closed separately.

Who is accountable for compliance internally?

Under the law, the management body, and that accountability cannot be delegated to the IT manager. Management approves the measures, oversees implementation, is liable for failures, and must attend regular cybersecurity training. Approval and training must be documented; an inspection typically asks for this first. A cybersecurity contact person must also be appointed for communication with the authority.

What counts as a significant incident that must be reported?

One that causes severe operational disruption or financial loss, or that is capable of causing considerable material or non-material damage to other natural or legal persons. The threshold must be defined in writing in advance, mid-incident is not the time to debate whether something is reportable. Reporting is three-stage: early warning within 24 hours, incident notification within 72 hours, final report within one month.

Does it apply to our OT environment too?

Yes (if your sector is manufacturing, energy, water or transport, scope extends to industrial control systems. Much of the standard IT toolkit does not apply there: PLCs cannot be patched on a schedule, and active network scanning can cause damage. The OT side is best delivered along the IEC 62443 family of standards) we covered this in detail on our OT/ICS security page and in our ICS/SCADA article.

Not Sure If You're
NIS2 Ready?

Our NIS2 readiness assessment gives you a clear picture of where you stand and what to prioritize, contact us to get started.