Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
NIS2 Compliance Consulting, Directive (EU) 2022/2555 | Resilience Guard
NIS2 compliance consulting

NIS2: from scope question to supervised confidence.

Directive (EU) 2022/2555 raises the bar for cybersecurity across essential and important entities in 18 sectors, with management bodies personally accountable. We take you from readiness assessment to full implementation, including the 24 hour reporting clock.

The service

What does NIS2 require?

The NIS2 Directive, Directive (EU) 2022/2555, is the EU's updated cybersecurity regime for essential and important entities across 18 sectors. It mandates risk management measures under Article 21, including incident handling, business continuity and supply chain security, makes management bodies accountable for oversight and training under Article 20, and imposes staged incident reporting under Article 23: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month.

The directive entered into force in January 2023, with member state transposition due by 17 October 2024, and carries supervisory teeth: audits, binding instructions, and fines of up to EUR 10 million or 2 percent of worldwide annual turnover for essential entities. For leadership teams the practical questions are concrete: are we in scope, do our measures meet Article 21, could we actually make the 24 hour early warning, and can we evidence all of it to a supervisor?

Our consulting answers those questions in order, from scope determination and gap assessment through implementation of the measures to reporting readiness, governance and the exercised evidence trail, drawing on the same practice that builds continuity, cyber resilience and crisis capability, because NIS2 compliance is those capabilities, documented.

Instrument
Directive (EU) 2022/2555
Scope
Essential and important, 18 sectors
Reporting
24h, 72h, one month
Sanctions
Up to EUR 10m or 2%
THE CLOCK THAT STARTS WHEN THE INCIDENT DOES0hSignificant incident detected24hEarly warning to the CSIRT or authority72hIncident notification with assessment1 monthFinal report: root cause, mitigationScopeIn scope? 18 sectorsMeasuresArticle 21 measuresGovernanceArticle 20 dutiesEvidenceExercised, documentedArticle 23 reporting duties above, the compliance journey we build beneath them.Directive (EU) 2022/2555, transposition due 17 October 2024. Fines up to EUR 10 million or 2 percent of worldwide turnover.
The Article 23 reporting clock above, the compliance journey beneath: scope, measures, governance and exercised evidence.
What we deliver

The NIS2 service line

Readiness assessment. Scope determination, current cybersecurity maturity evaluated, compliance gaps and regulatory risks identified, responsibilities mapped across the organisation.
Strategy and implementation roadmap. An actionable plan aligned to the directive's articles, risk based prioritisation, and governance, roles and responsibilities defined.
Policy and process development. Cybersecurity policies created or updated, incident response, recovery and risk management procedures established, and compliance integrated into third party and supply chain contracts.
Training, exercising and awareness. Executive and staff training on NIS2 duties, tabletop exercises and crisis simulations that prove the 24 hour clock can be met, and a security aware culture.
Ongoing support. Incident notification support, annual audits and continuous improvement tracking, and advisory on emerging threats and regulatory change.
The wider regime

NIS2 never travels alone

NIS2 is one instrument in a coordinated European architecture. Its twin, the CER Directive, governs the same critical entities' physical and organisational resilience; financial entities answer to DORA as lex specialis; aviation carries Part-IS; and Swiss operators sit under the Information Security Act in parallel. Our briefings cover each, and the compliance calendar puts every date on one timeline.

Questions

Frequently asked questions

Who falls under NIS2?+

Essential and important entities across 18 sectors, from energy, transport, health, water and digital infrastructure to postal services, food, manufacturing of critical products and digital providers, generally medium sized and above, with some entities in scope regardless of size. Scope determination is the first step of every engagement.

What are the NIS2 reporting deadlines?+

Under Article 23, a significant incident triggers an early warning to the CSIRT or competent authority within 24 hours, an incident notification with an initial assessment within 72 hours, and a final report within one month. Meeting the first deadline requires a rehearsed detection and escalation path.

What are the penalties for non compliance?+

For essential entities, fines of up to EUR 10 million or 2 percent of total worldwide annual turnover, whichever is higher; for important entities, up to EUR 7 million or 1.4 percent, alongside audits, binding instructions and, in serious cases, personal consequences for management.

How does NIS2 relate to the Swiss ISG?+

They are parallel regimes: Swiss critical infrastructure operators answer to the ISG and its 24 hour reporting duty to BACS, while their EU operations or customers may pull them into NIS2. We map both; see our German language ISG briefing.

Is NIS2 an IT project?+

No. Article 20 places accountability on management bodies, and Article 21 spans continuity, supply chain and crisis handling. It is an organisational capability with a legal deadline, which is why our delivery combines policy, implementation, training and exercising.

Explore further

Related services

Regulation and crisis

DORA Compliance

The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.

Explore the service ›
Cyber and security

Supply Chain Security

The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.

Explore the service ›
Cyber and security

Cyber Resilience

Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.

Explore the service ›
Cyber and security

Information Security

Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.

Explore the service ›
Continuity and resilience

Business Continuity Management

BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.

Explore the service ›
Regulation and crisis

Crisis Management

Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.

Explore the service ›
Continuity and resilience

Business Continuity Exercises

Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.

Explore the service ›
Continuity and resilience

Organisational Resilience

The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.

Explore the service ›
Risk and governance

Risk Management

From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.

Explore the service ›
Sector framework

DAEDALUS Airport Resilience Framework

The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.

Explore the service ›
Risk and governance

7A Risk Management Framework

Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.

Explore the service ›
Risk and governance

AI Governance and Resilience

Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.

Explore the service ›
Next step

Answer the scope question before a supervisor asks it.

Start with a NIS2 readiness assessment; you will know your gaps, your priorities and your distance to the 24 hour clock.

Book a consultation
All consultations are treated with strict confidentiality.