Who we help
Organisations in NIS2 sectors
NIS2 covers far more than banks. If you operate in one of its sectors and are medium-sized or larger, you probably have obligations: risk-management measures approved by management, incident reporting within 24 hours, and evidence for the supervisor.
The first conversation is free. Scope and price are confirmed in writing before work starts.
Check whether NIS2 applies to youSectors covered by NIS2
- Highly critical (Annex I): energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration, space.
- Other critical (Annex II): postal and courier services, waste management, chemicals, food, manufacturing (medical devices, electronics, electrical equipment, machinery, motor vehicles, other transport equipment), digital providers (online marketplaces, search engines, social networks), research.
- As a rule medium-sized and large organisations are covered — from 50 employees, or above €10 million annual turnover and balance sheet. Some providers are covered regardless of size. Member States transpose the list; Bulgaria’s Act has its own annexes — see NIS2 in Bulgaria.
What NIS2 asks of you
Management approves and oversees
The management body approves the cybersecurity risk-management measures, oversees them, can be held liable and must be trained (Art. 20).
Ten minimum measures
Risk analysis and policies, incident handling, business continuity and backup, supply-chain security, secure development and vulnerability handling, effectiveness checks, cyber hygiene and training, cryptography, access control and asset management, multi-factor authentication (Art. 21(2)).
Incident reporting
Early warning within 24 hours, notification within 72 hours and a final report within one month of a significant incident (Art. 23).
Fines
Up to €10 million or 2% of worldwide turnover for essential entities, €7 million or 1.4% for important entities (Art. 34).
How we help
| Step | What you receive | Price |
|---|---|---|
| Applicability assessment | A written conclusion: in scope or not, essential or important, which authority | from €900 |
| Assessment and evidence pack | The ten measures against what you have, gaps and an ordered plan for management | from €7 900 |
| Incident readiness | Who decides, who reports within 24 hours, templates and a rehearsed scenario | by quotation |
| External expert roles | A named specialist for the annual cycle: reviews, registers, training, reporting readiness | from €1 400 / month |
Read more
Boundaries
- We are not a certification body and do not issue legal opinions; legal questions are commissioned separately from a lawyer.
- We do not act as a statutory EU representative (under GDPR, NIS2 or the AI Act) — that is a separate legal role.
- Responsibility for decisions and reporting stays with the organisation’s management.