NIS2 · EU Directive · In Force Oct 2024

NIS2 is in force.
Is your organization ready?

The NIS2 Directive extends mandatory cybersecurity obligations to thousands of organizations across critical sectors. Bitsecura helps you identify your obligations, build compliant frameworks, and maintain your security posture as the threat landscape evolves.

Four services. Complete NIS2 coverage.

Whether you're an essential or important entity — newly in scope or closing gaps ahead of supervisory scrutiny — our services cover every NIS2 obligation, from entity classification and governance frameworks to supply chain security and incident reporting readiness.

NIS2 Readiness Assessment

We determine your entity classification (essential vs. important), map all in-scope systems, and run a structured gap analysis against all Article 21 security measures. You get a prioritized remediation roadmap — so your compliance programme starts with clarity, not guesswork.

Compliance & Governance Framework

We build the policies, controls, and governance structures that satisfy NIS2 Article 21 obligations — risk management frameworks, access controls, and business continuity procedures. Critically, we establish the Article 20 management oversight structures that place accountability at board level, not just in the IT department.

Supply Chain Security

NIS2 Article 21(2)(d) requires proactive management of supply chain risk. We classify your critical suppliers, embed mandatory security clauses in ICT contracts, design third-party due diligence processes, and build ongoing monitoring workflows — so your compliance posture isn't undermined by a vendor you haven't reviewed.

Incident Response & Reporting

NIS2 mandates a 24-hour early warning, 72-hour notification, and one-month final report for significant incidents. We design your detection and classification workflows, build authority reporting templates, and run tabletop exercises so your team knows exactly what to do when an incident occurs.

Frequently asked questions

Who falls under NIS2?

NIS2 (Directive (EU) 2022/2555) covers "essential" and "important" entities across 18 sectors, from energy, transport and health to digital infrastructure, manufacturing and digital providers, generally from 50 employees or EUR 10m turnover, with some entities in scope regardless of size.

We are UK-based. Why do NIS2 questionnaires keep landing on our desk?

Because your EU clients must manage supply-chain risk under NIS2, and that assessment includes you. The UK market is downstream of EU regulation: if you cannot evidence your security posture, your EU customers will find a supplier who can.

What are the penalties?

For essential entities, fines up to EUR 10 million or 2% of worldwide annual turnover (whichever is higher); for important entities, up to EUR 7 million or 1.4%. Management bodies carry personal accountability for approving and overseeing cybersecurity risk measures.

Does ISO 27001 certification satisfy NIS2?

It is the best running start: a certified ISMS covers most NIS2 risk-management measures and gives you the governance evidence regulators expect. Gaps typically remain around incident reporting timelines and sector-specific requirements in your national transposition.

Get Started

Ready to turn NIS2 obligations into stronger security?

Bitsecura's NIS2 services go beyond documentation. We combine regulatory expertise with hands-on cybersecurity consulting to build frameworks that satisfy national authorities — and genuinely reduce your exposure to cyber threats.

Schedule a Call

From in-scope to compliant

No generic checklists. Every engagement is shaped by your sector, entity type, and existing security maturity — not a one-size-fits-all template.

Step 01

Classify

We confirm whether your organization falls under NIS2 as an essential or important entity, which sector rules apply, and what obligations your national transposition introduces. Know your obligations before you build anything.

Step 02

Assess

A structured gap analysis against all Article 21 security measures — risk management, access control, cryptography, supply chain, and more. You'll see exactly where you stand, with findings ranked by regulatory and business risk.

Step 03

Implement

Policies, controls, and governance structures built alongside your teams — cybersecurity risk frameworks, business continuity plans, and supply chain oversight woven into your existing operations. Compliance that works in practice, not just on paper.

Step 04

Respond

Incident detection workflows, authority reporting templates, and regular drills to keep your team ready. When a significant incident hits, you execute — you don't scramble to figure out the 24-hour early warning process.

Explore Our Full Range of Compliance Services

View All Frameworks