NIS2 and the cybersecurity directive

The NIS2 Directive (EU) 2022/2555 newly affects thousands of companies. We guide you through the entire journey to compliance, step by step and from a single partner.

In line with the NIS2 Directive (EU) 2022/2555 ISO 27001 certified ourselves Everything from a single partner
A relieved manager has NIS2 and cybersecurity directive compliance under control thanks to IT HELP
3 000+organisations newly covered by the NIS2 Directive
24 hto send an early warning after a significant incident
12 mo.to adopt measures after entry in the register
24 hdeadline for the first incident report

Does NIS2 affect your company too?

After the update, the NIS2 Directive applies to companies in selected sectors, typically from 50 employees or a turnover above 10 million €, and some entities are covered regardless of size. Important: NIS2 is based on self-identification. Nobody will send you a letter; you have to assess and register yourselves.
We're happy to do the precise assessment with you →

Which sectors NIS2 covers

Sectors of high criticality

When the criteria are met, typically operators of an essential service of critical importance. A stricter regime applies, including a mandatory audit.

EnergyTransportBankingFinancial marketsHealthcareDrinking waterWaste waterSpaceDigital infrastructureICT service management (B2B)Public administration

Other critical sectors

Operators of an essential service. The full scope of measures; their effectiveness can also be demonstrated through self-assessment.

Postal and courier servicesWaste managementChemicalsFoodMedical devicesElectronicsMachineryMotor vehiclesDigital servicesResearch
Energy
Healthcare
Transport
Water management
Manufacturing
Public administration

What obligations NIS2 introduces

Six areas a regulated company must have under control.

Registration with the authority

Registration with the competent national authority once you meet the criteria, and keeping the registered details up to date. Each member state runs its own register and sets its own deadlines.

Security measures

Organisational and technical risk-management measures under the NIS2 Directive and its national implementing rules, including the supporting documentation. The deadline for having them in place is set by your national transposition.

Cybersecurity manager

A mandatory role with prescribed knowledge, independent of IT operations, with direct access to management. It can also be external. More about the service →

Incident reporting

An early warning within 24 hours, a notification within 72 hours and a final report within a month, in line with the NIS2 Directive and its national implementing rules, via the authority's system.

Audit or self-assessment

The effectiveness of the measures has to be demonstrated: essential entities typically through an independent audit, important entities often through self-assessment. The intervals and the accepted form of proof are set by your national transposition.

Management responsibility

The statutory body is responsible for managing cyber risks: it approves the measures and must complete cybersecurity training.

Why not to put it off

Failure to meet the obligations can lead to fines of up to 10 million € or 2 % of global turnover for essential entities (up to 7 million € / 1.4 % for important entities) and personal liability for company directors. And supervisory authorities do carry out inspections. The good news: with a systematic approach, compliance is manageable without panic, and most measures genuinely protect your company, not just a file for the authority.

Why IT HELP

Compliance with legislation doesn't end with a document. We're an IT company: we design the measures, deploy them technically and operate them long term. And since we're ISO 27001 certified ourselves, we live managed security, we don't just advise on it.

30+years of IT experience
ISO27001 & 9001 certified
Hundredsof satisfied clients in the EU
24/7infrastructure monitoring

We operate nationwide, and we deliver a large part of our services remotely.

Our partners

Microsoft partner ESET partner Dell partner Synology partner VMware partner Epson partner TeamViewer partner Veeam partner KROS partner

Frequently asked questions

How do we find out whether we fall under NIS2?

It's determined by a combination of sector (Annexes 1 and 2 of the Directive) and size, typically 50 or more employees or an annual turnover above 10 million €; selected entities are covered regardless of size. You can check preliminarily with your national authority, and we'll make a binding assessment as part of the GAP analysis.

What deadlines apply to us?

NIS2 requires you to register with the competent national authority once you meet the criteria, to have risk-management measures in place, and to report incidents: an early warning within 24 hours, a notification within 72 hours and a final report within one month. The registration and implementation deadlines themselves are set by each member state's transposition, so they differ from country to country. We check which ones apply to you.

What happens if we don't meet the obligations?

Fines under the NIS2 Directive: up to 10 million € or 2 % of global turnover for essential entities, up to 7 million € or 1.4 % for important entities; national transpositions add their own penalties for administrative breaches such as failure to register. Company directors bear personal liability. But our approach isn't to scare you. It's cheaper and calmer to have things in order.

Can we handle it with our own IT department?

A large part of the technical measures, certainly. We help where internal capacity isn't enough: analysis against NIS2, documentation, the cybersecurity manager role (which must be independent of IT operations) and specialised technologies such as SIEM or central logging.

Do you also perform the statutory cybersecurity audit?

Where your national transposition requires an independent compliance audit, it is carried out by an accredited auditor rather than by us. We prepare you for it so it runs smoothly. Where self-assessment is permitted instead, our cybersecurity manager will carry it out with you.

Do you also work remotely?

Yes. We operate nationwide, and we can deliver analyses, oversight and the cybersecurity manager role largely remotely.

What do companies that entrusted us with their IT say?

They once faced the same decision. We have been looking after their IT for years.

“Jungheinrich, a global group with a subsidiary in Slovakia as well, has been working with this team for 27 years. They take exemplary care of our network, which currently has more than 150 computers, to our complete satisfaction, as this long cooperation shows.”

Chief Financial OfficerJungheinrich s. r. o. · 27 years

“We have found a responsible partner in information technology. Cooperation in this field is about trust and expertise. This company demonstrates both. Speed of response, professionalism and a human approach are the calling card we encounter every time. We are glad to have found a team of professionals we can rely on.”

IT Manager Production and InfrastructureBNP Paribas Cardif poisťovňa, a. s.

“Our cooperation began in 2012. The strengths of this company include responsibility, reliability and precision. Our cooperation on comprehensive IT management continues to this day and we are convinced we will keep developing it.”

Inštitút pre verejnú správuInstitute for Public Administration · since 2012

See all client references

Don't wait for an inspection or an incident

Tell us where you stand and we'll propose the shortest path to compliance, including timelines and budget. The first consultation is free.

"Your trust inspires us"

Start here

NIS2 compliance GAP analysis

Compliance GAP analysis

Find out exactly what you're missing for compliance and in what order to tackle it.

→ View service
Cybersecurity manager as a service

Cybersecurity manager

We provide the role required by NIS2 as an external service.

→ View service
IT security and infrastructure, 4 pillars

The 4 pillars of IT security

Audit, protection, monitoring and training, putting the measures into practice.

→ View the pillars

IT HELP Hotline

+421 948 07 97 07

+421 2 5244 2951

+421 948 07 97 07

hotline@ithelp.digital

Where to Find Us

IT HELP
Čajakova 26, Bratislava, Slovakia
Franz Mika Weg 7/1/25, Wien, Austria
Svatošská 23, Karlovy Vary, Czech Republic

We are available on business days Monday – Friday, 8:00 AM – 5:00 PM (or by arrangement)