NIS2 and the cybersecurity directive
The NIS2 Directive (EU) 2022/2555 newly affects thousands of companies. We guide you through the entire journey to compliance, step by step and from a single partner.

EXCELLENT Based on 627 reviews Posted on Google Matus LelkoTrustindex verifies that the original source of the review is Google. Veľmi ústretový personál, rýchle a úspešné prevedenie opravy tlačiarne. Môžem len vrelo odporúčaťPosted on Google MilanTrustindex verifies that the original source of the review is Google. Profesionálny prístup na riešenie uvedených problémov.Posted on Google Ľubomír GaraiTrustindex verifies that the original source of the review is Google. PRÍJEMNÝ PRACOVNÍCI, RÝCHLE A PROFESIONÁLNE OPRAVY.Posted on Google Ľuboš DudíkTrustindex verifies that the original source of the review is Google. Super firma, vždy keď som sa na nich s niečím obrátil, môj problém rýchlo vyriešili. Odporúčam 👍Posted on Google Eva SommierTrustindex verifies that the original source of the review is Google. S firmou IT pomoc som bola maximálne spokojná. Pomohli mi s kompletným nastavením internetového riešenia, routera aj preinštalovaním počítača. Oceňujem najmä vysoko odborný a profesionálny prístup, rýchlu komunikáciu a promptné dodanie služby. Pán Klozik je naozaj expert vo svojom odbore – všetko mi zrozumiteľne vysvetlil, navrhol najlepšie riešenie a celá realizácia prebehla bez problémov. Veľká spokojnosť z mojej strany a určite využijem Vaše služby aj v budúcnosti. Určite odporúčam.Posted on Google Jozef ČmeloTrustindex verifies that the original source of the review is Google. Som veľmi spokojný so službami firmy IT pomoc. Kedykoľvek som opakovane potreboval urgentne pomoc, vždy boli ochotní a pomohli. Vážim si okamžitú pomoc a ochotu pri vyriešení problémov s tlačiarňou, s internetovým spojením a podobne.Posted on Google Darina MalackáTrustindex verifies that the original source of the review is Google. Oceňujem ústretový prístup zamestnancov pobočky v BA, ktorí do 2 dní vyriešili náš problém s poškodením tlačiarne. Ďakujem vámVerified by TrustindexTrustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more
Does NIS2 affect your company too?
After the update, the NIS2 Directive applies to companies in selected sectors, typically from 50 employees or a turnover above 10 million €, and some entities are covered regardless of size. Important: NIS2 is based on self-identification. Nobody will send you a letter; you have to assess and register yourselves.
We're happy to do the precise assessment with you →
Which sectors NIS2 covers
Sectors of high criticality
When the criteria are met, typically operators of an essential service of critical importance. A stricter regime applies, including a mandatory audit.
Other critical sectors
Operators of an essential service. The full scope of measures; their effectiveness can also be demonstrated through self-assessment.
Energy
Healthcare
Transport
Water management
Manufacturing
Public administrationWhat obligations NIS2 introduces
Six areas a regulated company must have under control.
Registration with the authority

Registration with the competent national authority once you meet the criteria, and keeping the registered details up to date. Each member state runs its own register and sets its own deadlines.
Security measures

Organisational and technical risk-management measures under the NIS2 Directive and its national implementing rules, including the supporting documentation. The deadline for having them in place is set by your national transposition.
Cybersecurity manager

A mandatory role with prescribed knowledge, independent of IT operations, with direct access to management. It can also be external. More about the service →
Incident reporting

An early warning within 24 hours, a notification within 72 hours and a final report within a month, in line with the NIS2 Directive and its national implementing rules, via the authority's system.
Audit or self-assessment

The effectiveness of the measures has to be demonstrated: essential entities typically through an independent audit, important entities often through self-assessment. The intervals and the accepted form of proof are set by your national transposition.
Management responsibility

The statutory body is responsible for managing cyber risks: it approves the measures and must complete cybersecurity training.
Why not to put it off
Failure to meet the obligations can lead to fines of up to 10 million € or 2 % of global turnover for essential entities (up to 7 million € / 1.4 % for important entities) and personal liability for company directors. And supervisory authorities do carry out inspections. The good news: with a systematic approach, compliance is manageable without panic, and most measures genuinely protect your company, not just a file for the authority.
The path to compliance in four steps
The same logic we use to build IT security: first find out, then fix, maintain and prove.
Why IT HELP
Compliance with legislation doesn't end with a document. We're an IT company: we design the measures, deploy them technically and operate them long term. And since we're ISO 27001 certified ourselves, we live managed security, we don't just advise on it.
We operate nationwide, and we deliver a large part of our services remotely.
Our partners

Frequently asked questions
How do we find out whether we fall under NIS2?
It's determined by a combination of sector (Annexes 1 and 2 of the Directive) and size, typically 50 or more employees or an annual turnover above 10 million €; selected entities are covered regardless of size. You can check preliminarily with your national authority, and we'll make a binding assessment as part of the GAP analysis.
What deadlines apply to us?
NIS2 requires you to register with the competent national authority once you meet the criteria, to have risk-management measures in place, and to report incidents: an early warning within 24 hours, a notification within 72 hours and a final report within one month. The registration and implementation deadlines themselves are set by each member state's transposition, so they differ from country to country. We check which ones apply to you.
What happens if we don't meet the obligations?
Fines under the NIS2 Directive: up to 10 million € or 2 % of global turnover for essential entities, up to 7 million € or 1.4 % for important entities; national transpositions add their own penalties for administrative breaches such as failure to register. Company directors bear personal liability. But our approach isn't to scare you. It's cheaper and calmer to have things in order.
Can we handle it with our own IT department?
A large part of the technical measures, certainly. We help where internal capacity isn't enough: analysis against NIS2, documentation, the cybersecurity manager role (which must be independent of IT operations) and specialised technologies such as SIEM or central logging.
Do you also perform the statutory cybersecurity audit?
Where your national transposition requires an independent compliance audit, it is carried out by an accredited auditor rather than by us. We prepare you for it so it runs smoothly. Where self-assessment is permitted instead, our cybersecurity manager will carry it out with you.
Do you also work remotely?
Yes. We operate nationwide, and we can deliver analyses, oversight and the cybersecurity manager role largely remotely.
Don't wait for an inspection or an incident
Tell us where you stand and we'll propose the shortest path to compliance, including timelines and budget. The first consultation is free.
"Your trust inspires us"
Start here
Compliance GAP analysis
Find out exactly what you're missing for compliance and in what order to tackle it.
→ View service
The 4 pillars of IT security
Audit, protection, monitoring and training, putting the measures into practice.
→ View the pillarsWhere to Find Us
IT HELP
Čajakova 26, Bratislava, Slovakia
Franz Mika Weg 7/1/25, Wien, Austria
Svatošská 23, Karlovy Vary, Czech Republic
We are available on business days Monday – Friday, 8:00 AM – 5:00 PM (or by arrangement)



