Skip to main content

infosecacademy Eğitim Danışmanlık Hizmetleri

NIS2 · Directive (EU) 2022/2555

NIS2 compliance consulting under the national act that applies to you

From scope determination to audit-ready evidence. We have delivered NIS2 programmes in Slovakia and Romania, work directly to the national transposition rather than a generic reading of the directive, and cover suppliers in Türkiye as part of the same programme. Every engagement is led personally by our founder, a multi-standard ISO Lead Auditor.

Articles 20, 21, 23Slovakia · Act 69/2018Romania · GEO 155/2024OT/ICSSupply chain
In brief

What is NIS2?

NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It applies to essential and important entities in the sectors listed in Annexes I and II, through each member state’s national transposition. It makes cybersecurity a governance obligation of the management body (Article 20), sets ten minimum risk-management measures (Article 21), imposes a 24-hour / 72-hour / one-month incident reporting chain (Article 23), and provides for fines of up to €10 million or 2 % of worldwide turnover for essential entities (Article 34). It is not a certification: compliance is demonstrated to a supervisory authority with documents and evidence.

What this means in practice

  • Scope is wider than most companies assume. Manufacturing of motor vehicles, machinery, electrical equipment, chemicals, food and medical devices are all inside Annex II.
  • Compliance is proven by documentation and evidence, not by tooling. A firewall does not satisfy Article 21.
  • Your obligations flow down your supply chain — including to suppliers outside the European Union.
  • National transpositions differ in deadlines, registration mechanics and technical detail. The directive is the floor; the member-state act is what you are actually audited against.
The regulatory landscape

Four articles that change who owns cybersecurity

NIS2 is no longer a technical programme owned by IT. It is a governance obligation owned by the management body, with personal accountability attached.

Article 20 — Governance

Management bodies must approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for failures. Members must follow regular training.

Article 21 — Measures

Ten minimum measures, including risk analysis, incident handling, business continuity and crisis management (21(2)(c)), supply chain security (21(2)(d)), security in acquisition, development and maintenance (21(2)(e)), cryptography, access control and multi-factor authentication.

Article 23 — Reporting

Early warning within 24 hours, incident notification within 72 hours, and a final report within one month — a chain that only works if suppliers are contractually obliged to report to you far faster than that.

Article 34 — Penalties

Up to €10 million or 2 % of total worldwide annual turnover for essential entities, and up to €7 million or 1.4 % for important entities — whichever is higher.

Country focus

Slovakia and Romania: the national act is the controlling text

Running programmes in two member states means we treat the directive as the common core and the national act as what the entity is audited against. Every statutory reference in our deliverables is verified against the primary source, never quoted from a secondary summary.

Slovakia

Slovakia transposed NIS2 through Act No. 366/2024 Coll., which amends and substantially strengthens the Cybersecurity Act No. 69/2018 Coll.; the amendment entered into force on 1 January 2025. Security measures are specified in detail by Decree No. 227/2025 Coll.

The Národný bezpečnostný úrad (NBÚ) is the single competent authority, maintaining the register and supervising all regulated sectors. Entities register through the unified information system (JISKB), and security measures must be implemented within twelve months of registration.

We apply the Decree’s four-level classification scheme — Public, Internal, Protected, Strictly Protected — across the entire document set, so an auditor sees one coherent system rather than an ISO scheme bolted onto a national one.

Slovak instruments we work to

  • Act 69/2018 Coll. as amended by Act 366/2024 Coll.
  • Decree 227/2025 Coll. — security measures
  • NBÚ registration and reporting via JISKB
  • Explicit ICT and OT relevance — the basis for a true IT/OT split
  • CIR (EU) 2024/2690 as a good-practice benchmark

Romania

Romania transposed NIS2 through Government Emergency Ordinance No. 155/2024, with the Directoratul Național de Securitate Cibernetică (DNSC) as competent authority. The regime is built around a sequence of fixed, short deadlines that run from registration — so an entity can be compliant on paper and still in breach on timing.

Romanian NIS2 deadlines under GEO 155/2024
ObligationDeadline
Registration with the DNSC30 days from entry into force / notification
Designation of a cybersecurity officer30 days from registration
Adoption of internal cybersecurity policies120 days from registration
Risk analysis and technical / organisational measures6 months from registration
Staff cybersecurity trainingWithin 12 months from registration
First external security audit1 year after registration, then every 2 years
Incident notification to the DNSC24 hours; detailed report within 72 hours

Why the sequence matters

Because the Romanian clock starts at registration, we plan backwards from the audit date, not forwards from the kick-off.

Group-level consistency

Where a group has entities in more than one member state — common in automotive and industrial supply chains — we build one management system with country-specific annexes, rather than two unrelated programmes that later have to be reconciled.

How we deliver

How we run a NIS2 programme

Seven steps, tailored to the entity’s classification, sector and member state. The standard structure is adjusted to the entity, not padded.

  1. Scope and classification

    Determine whether the entity is essential or important, under which annex and NACE code, and in which member state each obligation lands. Registration support where the deadline is still open.

  2. Gap analysis against the national act

    A structured assessment mapped to the national decree and to ISO/IEC 27002 controls, scored and prioritised, delivered as a working document the client can maintain — not a static report.

  3. Risk assessment and treatment

    Primary and supporting asset taxonomy, threat and vulnerability analysis, treatment plan with named owners and dates, and formal residual risk acceptance by the management body.

  4. Documentation build

    Governance, risk, operational and OT-specific documents written to the client’s real processes, with a Statement of Applicability tying every control back to the standard and the statute.

  5. Supply chain remediation

    Assessment of critical supplier agreements, drafting of cybersecurity annexes and data processing terms, and alignment of notification timelines to the statutory reporting chain.

  6. Implementation, training and evidence

    Rollout support, management-body and staff training, incident response and continuity exercises, and construction of the evidence set the auditor will ask for.

  7. Internal audit and management review

    A full internal audit cycle — programme, plan, findings, corrective actions — and a facilitated management review, so the system is demonstrably operating before the external audit.

Engagement summary

Typical duration
4–9 months, depending on entity size, OT footprint and existing documentation
Delivered as
English-language document set in Word and Excel; version-controlled, metadata cleaned, document IDs applied
Certificate
Where wanted, ISO/IEC 27001 certification comes out of the same work
Led by
Our founder personally, from scoping to management review

Our approach

  • OT and ICS treated as a first-class domain, never folded into the IT policy
  • Supplier notification timelines checked against the statutory reporting chain
  • Every statutory reference verified against the primary source
  • Internal audit and management review completed before any external scrutiny
What you receive

Six layers of deliverables

A NIS2 engagement is delivered as a defined document set. This is the standard structure; scope is adjusted to the entity.

Governance layer

  • Cybersecurity strategy (three-year horizon)
  • Information security policy
  • Management accountability framework (Article 20)
  • Roles, responsibilities and authorities matrix
  • Compliance obligations register

Risk layer

  • Risk management process
  • Risk assessment and treatment report
  • Risk treatment plan with owners and dates
  • Residual risk acceptance record
  • Risk assessment tool (Excel, with dashboard and reference controls)

Compliance layer

  • Gap analysis workbook mapped to the national decree and ISO/IEC 27002
  • Statement of Applicability — 93 Annex A controls, cross-mapped
  • Evidence register

Operational layer

  • Asset management procedure and inventory tool
  • Information classification and handling policy
  • Categorisation of networks, information systems and OT
  • IT security policy and OT/ICS security policy
  • Access control, cryptography, backup and secure communication policies
  • Incident response plan, reporting procedure, BC/DR plan

Supply chain layer

  • Supplier security gap assessment
  • Cybersecurity annex for supplier contracts
  • Data processing agreement and transfer package

Assurance layer

  • Internal audit programme, plan and report
  • Corrective action tracking
  • Management review pack
Adjacent regimes

Scoped so the work is done once

The same governance and resilience core supports neighbouring EU requirements.

GDPR

Regulation (EU) 2016/679. Breach notification within 72 hours (Article 33) and security of processing sit directly on the NIS2 incident chain.

Data protection →

DORA

Regulation (EU) 2022/2554, applicable since 17 January 2025 to financial entities. ICT risk and third-party requirements reuse the ISO 22301 and supplier work.

Cyber Resilience Act

Regulation (EU) 2024/2847. Reporting obligations apply from 11 September 2026, main obligations from 11 December 2027. Connects to secure development under Article 21(2)(e).

ISO/IEC 42001

AI governance where in-scope systems use AI components, aligned with the EU AI Act, Regulation (EU) 2024/1689.

ISO 42001 →
Delivered programmes

Two NIS2 programmes in two member states

Described without identifying the clients. In both, the national act was more decisive than the directive itself.

Slovakia — automotive components manufacturer

Important entity under NACE C29.3, in scope through Annex II. Full NIS2 and ISO/IEC 27001:2022 programme: cybersecurity strategy 2026–2028, risk management process and tool, Statement of Applicability across all 93 Annex A controls cross-mapped to NIS2 and the Slovak Act, and a separate OT/ICS security policy.

The IT services agreement with the Turkish parent-group provider was remediated: a notification trigger of three business days after resolution was replaced with a 12-hour, detection-triggered outer limit.

Act 69/2018Decree 227/2025OT/ICSSupply chain

Romania — NIS2 compliance programme, completed

Completed under GEO 155/2024 and the DNSC registration regime: scope determination, gap analysis against the national requirements, and the documented management system built within the statutory deadline sequence.

Policies at 120 days, risk analysis and measures at six months, first external audit at twelve months.

GEO 155/2024DNSC
Frequently asked questions

NIS2 questions we are asked

Is NIS2 a certification?

No. NIS2 is a directive implemented through national law, and there is no NIS2 certificate or accredited body that signs you off. What exists is a supervisory authority that can ask, at any point, for evidence that the Article 21 measures are implemented and that the management body has approved and overseen them. Where a client also wants a certificate, we run the programme so that ISO/IEC 27001 certification comes out of the same work.

We are a manufacturer. Are we really in scope?

Quite possibly. Annex II of Directive (EU) 2022/2555 covers the manufacture of motor vehicles, machinery, electrical equipment, chemicals, food and medical devices, among others. Whether you are an essential or important entity, and in which member state each obligation lands, depends on sector, NACE code and size under the national act — which is why scope and classification is the first step of every programme we run.

Does NIS2 apply to our suppliers in Türkiye?

Not directly — it applies to entities established in the EU. But Article 21(2)(d) makes in-scope entities responsible for the security of their supply chain, so obligations reach suppliers outside the EU through contracts: security requirements, audit rights and notification timelines that allow you to meet the 24-hour early warning. We assess and remediate those supplier relationships on both sides of the contract.

How long does a NIS2 programme take?

Typically four to nine months, depending on entity size, OT footprint and how much documentation already exists. In Romania the statutory sequence sets the pace: policies within 120 days of registration, risk analysis and measures within six months, first external audit one year after registration. We plan backwards from the audit date, not forwards from the kick-off.

Does ISO/IEC 27001 make us NIS2 compliant?

It covers a large part of the Article 21 measures, but not all of NIS2. Management-body accountability under Article 20, the 24/72-hour reporting chain under Article 23 and the technical detail of the national decree need additional work. We build a Statement of Applicability cross-mapped to NIS2 and the national act, so the work is done once.

Let us start with a scoping conversation

Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.