Who it applies to
▸Medium and large entities in 18 sectors (energy, transport, banking, health, digital infrastructure, public administration, and others)
▸Smaller entities covered as critical suppliers or through explicitly defined exceptions
▸Enforcement is governed by national law, with direct accountability of management
What it requires
The obligations, clearly explained.
01
Risk management measures
Technical and organizational measures proportionate to the risk, from baseline controls to supply-chain security.
02
Incident reporting
An early warning within 24 hours and a fuller notification within 72 hours of a significant incident.
03
Supply-chain security
Security requirements passed down to suppliers and service providers through contracts.
04
Governance and accountability
Management bodies approve and oversee the risk management measures and can be held personally liable for failures.
How Raptoric helps
We do the engineering work, not just the documentation.
Gap analysis
We establish your current posture against the NIS2 requirements and your national transposition.
Program implementation
We put in place the risk management, policies, and controls the directive requires.
Incident readiness
We build the detection and response that make the reporting deadlines achievable.
Supply-chain review
We assess third-party exposure, which regulators now examine in detail.
We prepare the organization and deliver the evidence. Oversight and enforcement sit with the national authority.
Services that deliver it
FAQ
Questions, answered
Does NIS2 apply to my company?
If you are a medium or large entity in one of the 18 covered sectors, very likely yes. Smaller companies can be covered as critical suppliers or through defined exceptions. The national transposition is decisive, and your status can be established through a formal assessment.
What are the incident reporting deadlines?
An early warning within 24 hours and a fuller notification within 72 hours of becoming aware of a significant incident. We build the detection and reporting procedures that make those deadlines achievable.
Can management be held liable under NIS2?
Yes. Management bodies approve and oversee the risk management measures and can be held personally accountable for failures. Security governance therefore has to be established at board level.
What does the preparation look like?
We run a gap analysis against NIS2 and the national transposition, implement the controls, and prepare the evidence for supervision. Oversight remains with the national authority.
Further reading