NIS2 REGULATION

NIS2 – The European directive on the security of network and information systems – explained

WHO IS OBLIGATED

It concerns entities classified as “important” or “essential” in critical sectors — public administrations, companies in sensitive areas, and Universities conducting research activities

We cover the entire NIS2 scope:

Onboarding, risk management, policies, controls, incident registry, audit

MULTITUDE OF ENTITIES

Onboarding

Get the compliance journey on track with clear priorities and measurable results, aligning teams from the very start.

DATA

Risk management

Keep risks, decisions, and stakeholders aligned on a shared vision of what truly matters.

SUPPLIERS

Policies

Reduce the noise and focus on the highest-impact actions, so the team works where it is needed.

NOTIFICATIONS

Controls

Create repeatable systems and rhythms that support growth without adding unnecessary complexity.

WHO FALLS WITHIN THE SCOPE

NIS2 distinguishes between “essential” and “important” entities based on sector, size, and service criticality.

ESSENTIAL ENTITIES

Energy, transport, banking, financial market infrastructures, healthcare, drinking water and waste water, digital infrastructure, public administration, space.

IMPORTANT ENTITIES

Postal services, waste management, chemicals, food, manufacturing, digital providers, research — including many Universities and research centers.

The main obligations

Risk management

Technical, operational, and organizational measures proportionate to the risk: encryption, access management, backup, supply chain security

Incident reporting

Early warning within 24 hours, notification within 72 hours, final report within one month of the significant incident

Governance responsibility

Management bodies approve and oversee security measures and undergo dedicated training; they can be held personally liable in case of serious infringements

Supply chain security

Risk assessment of critical suppliers and their development processes

PENALTIES

In case of non-compliance, fines are a percentage of annual turnover*

* The exact percentages and caps are defined by the national transposition of the directive

Up to 2%

of global annual turnover, for essential entities in case of serious non-compliance

Up to 1.4%

of global annual turnover, for important entities

Contact us

Contact Form Virgilia