// NIS2 · Directive (EU) 2022/2555
NIS2 readiness, assessed by engineers
Also available: Română · Italiano
NIS2 — Directive (EU) 2022/2555 — is now national law across the EU. It widens cybersecurity obligations to roughly 160,000 "essential" and "important" entities in 18 sectors, makes management personally accountable, and backs the requirements with fines of up to €10 million or 2% of worldwide turnover for essential entities (€7 million or 1.4% for important ones). Most in-scope organisations are not security companies — and the directive was written knowing that.
Who NIS2 applies to
Energy, transport, banking, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space — plus "important" sectors such as manufacturing of critical products, food, chemicals, waste, postal services, and digital providers. Size generally starts at 50 employees or €10M turnover, but supply-chain requirements pull smaller vendors in through their customers' contracts. If your customers are in scope, parts of NIS2 will arrive in your inbox as security questionnaires.
What the directive actually requires
- Risk-analysis and information-system security policies, and their evidence.
- Incident handling with hard deadlines: early warning within 24 hours, notification within 72, final report within a month.
- Business continuity: backups, disaster recovery, crisis management.
- Supply-chain security, secure development and vulnerability handling.
- Cryptography policy, access control, MFA, security training — including for management, which now carries personal responsibility for approving and supervising these measures.
Readiness assessment, done by engineers
Our assessment is not a questionnaire. It pairs document review with hands-on technical analysis — external attack surface, exposed services, DNS and email hygiene, patching posture, real-world exploitability — the methodology productised in RECON, the attack-surface management platform architected and development-led by this studio, which maps an organisation's full external footprint and auto-evaluates NIS2 technical coverage.
- Scope & classification — are you essential, important, or pulled in via supply chain; which national registration duties apply.
- Gap analysis — measured against the Article 21 measures, with evidence, not self-declarations.
- Remediation roadmap — prioritised by exploitability and cost, written for the people who will implement it.
- Re-measurement — the same scans re-run, so progress is a number, not an opinion.
Deadlines and penalties
Member states apply NIS2 through national law — in Romania supervision and registration run through DNSC, in Italy through ACN under D.Lgs 138/2024 — with registration windows, incident-reporting duties and sanctions already active. The pragmatic reading: regulators are prioritising entities that can show nothing. A measured baseline and a dated roadmap change your position entirely.
Fixed-scope engagements, delivered in English, Romanian or Italian. One conversation covers the technical and the commercial side — the same two principals answer for both.