Who we help

Organisations in NIS2 sectors

NIS2 covers far more than banks. If you operate in one of its sectors and are medium-sized or larger, you probably have obligations: risk-management measures approved by management, incident reporting within 24 hours, and evidence for the supervisor.

The first conversation is free. Scope and price are confirmed in writing before work starts.

Check whether NIS2 applies to you

Sectors covered by NIS2

  • Highly critical (Annex I): energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration, space.
  • Other critical (Annex II): postal and courier services, waste management, chemicals, food, manufacturing (medical devices, electronics, electrical equipment, machinery, motor vehicles, other transport equipment), digital providers (online marketplaces, search engines, social networks), research.
  • As a rule medium-sized and large organisations are covered — from 50 employees, or above €10 million annual turnover and balance sheet. Some providers are covered regardless of size. Member States transpose the list; Bulgaria’s Act has its own annexes — see NIS2 in Bulgaria.

What NIS2 asks of you

Management approves and oversees

The management body approves the cybersecurity risk-management measures, oversees them, can be held liable and must be trained (Art. 20).

Ten minimum measures

Risk analysis and policies, incident handling, business continuity and backup, supply-chain security, secure development and vulnerability handling, effectiveness checks, cyber hygiene and training, cryptography, access control and asset management, multi-factor authentication (Art. 21(2)).

Incident reporting

Early warning within 24 hours, notification within 72 hours and a final report within one month of a significant incident (Art. 23).

Fines

Up to €10 million or 2% of worldwide turnover for essential entities, €7 million or 1.4% for important entities (Art. 34).

How we help

StepWhat you receivePrice
Applicability assessmentA written conclusion: in scope or not, essential or important, which authorityfrom €900
Assessment and evidence packThe ten measures against what you have, gaps and an ordered plan for managementfrom €7 900
Incident readinessWho decides, who reports within 24 hours, templates and a rehearsed scenarioby quotation
External expert rolesA named specialist for the annual cycle: reviews, registers, training, reporting readinessfrom €1 400 / month

Read more

Boundaries

  • We are not a certification body and do not issue legal opinions; legal questions are commissioned separately from a lawyer.
  • We do not act as a statutory EU representative (under GDPR, NIS2 or the AI Act) — that is a separate legal role.
  • Responsibility for decisions and reporting stays with the organisation’s management.

Check whether NIS2 applies to you

EU law first, national law where it applies. EU regulations such as DORA, the AI Act and the GDPR apply directly in every Member State. Directives such as NIS2 are transposed into national law, so scope details, authorities, reporting channels and deadlines depend on the Member State where you are established or operate. Examples on this site often use Bulgarian law; in each engagement we confirm the national law that applies to you and involve local counsel where needed.