EU directive · cyber risk management

NIS2

NIS2 (Directive 2022/2555) raises the level of cybersecurity for organizations across 18 sectors. It is transposed into the national law of each member state, which defines the obligated entities, the obligations, and the competent authorities.

Who it applies to

Medium and large entities in 18 sectors (energy, transport, banking, health, digital infrastructure, public administration, and others)
Smaller entities covered as critical suppliers or through explicitly defined exceptions
Enforcement is governed by national law, with direct accountability of management
What it requires

The obligations, clearly explained.

01
Risk management measures
Technical and organizational measures proportionate to the risk, from baseline controls to supply-chain security.
02
Incident reporting
An early warning within 24 hours and a fuller notification within 72 hours of a significant incident.
03
Supply-chain security
Security requirements passed down to suppliers and service providers through contracts.
04
Governance and accountability
Management bodies approve and oversee the risk management measures and can be held personally liable for failures.
How Raptoric helps

We do the engineering work, not just the documentation.

Gap analysis
We establish your current posture against the NIS2 requirements and your national transposition.
Program implementation
We put in place the risk management, policies, and controls the directive requires.
Incident readiness
We build the detection and response that make the reporting deadlines achievable.
Supply-chain review
We assess third-party exposure, which regulators now examine in detail.
We prepare the organization and deliver the evidence. Oversight and enforcement sit with the national authority.
FAQ

Questions, answered

Does NIS2 apply to my company?
If you are a medium or large entity in one of the 18 covered sectors, very likely yes. Smaller companies can be covered as critical suppliers or through defined exceptions. The national transposition is decisive, and your status can be established through a formal assessment.
What are the incident reporting deadlines?
An early warning within 24 hours and a fuller notification within 72 hours of becoming aware of a significant incident. We build the detection and reporting procedures that make those deadlines achievable.
Can management be held liable under NIS2?
Yes. Management bodies approve and oversee the risk management measures and can be held personally accountable for failures. Security governance therefore has to be established at board level.
What does the preparation look like?
We run a gap analysis against NIS2 and the national transposition, implement the controls, and prepare the evidence for supervision. Oversight remains with the national authority.

Need to be ready for NIS2?

Our team will define the scope of work with you on a 30-minute call.
Book a scoping call or email contact@raptoric.com