Significant fines
Up to millions of euros or a percentage of annual turnover, depending on the entity type.
NIS2 is already law in Romania. We explain, without jargon, who it applies to, what you risk and what you need to do — and we give you a free checker to see where you stand in 2 minutes.
A European cybersecurity directive that requires a much larger number of companies to get their IT security in order — not as a recommendation, but as a legal obligation, with deadlines and penalties. The goal: fewer incidents and greater resilience. The challenge for companies: the requirements are concrete and must be proven.
Medium and large companies (from roughly 50 employees or EUR 10M turnover) in regulated sectors — energy, healthcare, transport, water, manufacturing, digital infrastructure, IT services and others. Even if you are not an „essential entity”, you may be an „important” one. And if you are a supplier to a covered company, compliance is required across the supply chain.
Up to millions of euros or a percentage of annual turnover, depending on the entity type.
Responsibility sits with company management, not just „the IT person”. It is a business decision.
Major incidents must be flagged within 24 hours and fully notified within 72 hours of detection.
9 questions, 2 minutes, no personal data. You get a score and the priority gaps to close.
Mark where you stand on each measure:
No local admin rights, MFA, a clear role model and PAM for critical access.
Unnecessary services disabled, restrictive firewall and CIS/BSI hardening policies.
Central log storage and EDR solutions to document endpoint events.
BitLocker, TPM and Secure Boot to protect data from manipulation.
Regular testing and proof of the measures' effectiveness - mandatory under NIS2.
Network segmentation (VLAN) and a next-gen firewall that limit an attacker's lateral movement inside.
HA equipment, redundant ISP links and elimination of single points of failure (SPOF).
Automated backup with an immutable/offline copy and a tested DR/BCP plan, with defined RTO/RPO.
Scanning and patching across servers, firewalls and network devices, with prioritized remediation.
Centralized logging (SIEM), network detection and alerting for fast incident response.
Every NIS2 requirement (Art. 21) has a clear technical solution. We choose the stack that fits your size and budget — Microsoft 365, Bitdefender, Coro, Fortinet or a combination.
Identifying risks and written policies for information systems.
Detection, response and reporting of incidents within legal deadlines (24–72h).
Immutable backup, tested recovery plan and crisis management.
Supplier assessment and controlled access for third parties.
Secure systems across the lifecycle and timely patching.
Periodic testing and auditing of the measures in place.
Best practices and employee training, including anti-phishing.
Protecting data at rest and in transit.
Least privilege, separate admin accounts and device inventory.
Strong authentication and protected communication channels.
We don't force a single vendor. We choose the tool that best fits what you already have and your budget.
Identity (MFA, Conditional Access, PIM), endpoint (Intune + Defender EDR), email (Defender for Office 365), SIEM (Sentinel) and data (Purview).
Ideal if you already use Microsoft 365.
Endpoint protection, EDR/XDR, patch management and encryption, with optional managed SOC (MDR).
When you want strong, centrally managed protection.
All-in-one, modular platform: endpoint, email, cloud, data and network, with a single console and a single agent.
A good fit for small and mid-sized companies that want solid security without complexity.
Next-gen firewall, network segmentation, VPN and centralized logging (FortiAnalyzer / FortiSIEM).
For network-level security and NIS2 segmentation.
Automated, immutable backup with a cloud copy and tested recovery.
For NIS2-compliant backup and disaster recovery.
Not just 'we help with NIS2'. We deliver complete, audit-ready compliance documentation - technical measures, policies and evidence. And if an inspection finds something we should have covered, we fix it at our own cost.
NIS2 mainly targets medium and large companies in regulated sectors. However, small companies can be caught indirectly, as suppliers to a covered company that requires supply-chain compliance. Besides, NIS2 measures are good security practice for any organization anyway.
The directive is already in force and transposed into national law. Our recommendation is to start assessment and implementation now — NIS2 compliance is not an overnight task, and requirements from partners and authorities are already appearing.
You risk significant fines (up to millions of euros or a percentage of turnover), direct management liability and the obligation to report incidents within 24–72 hours. Beyond penalties, the absence of measures means a real risk of a security incident.
It depends on your starting point. Typically an initial implementation runs over a few months, in stages: assessment, priority measures (MFA, backup, hardening), then maturity (segmentation, monitoring, documentation). It's best to start with an honest assessment of your current situation.
We run the compliance assessment, implement the technical measures (Microsoft 365, Fortinet, backup, endpoint protection), prepare the required documentation and policies, and support you during audits. In practice, we take on both the technical and the „paperwork” side, end to end.
Start with an honest assessment. Run the checker above or talk directly to an NCS specialist — no obligations.
Fill in the form and we'll get back to you shortly. No obligations.
Your request has been sent. We'll get back to you shortly.
This site uses cookies and similar technologies to work correctly and, with your consent, to understand how the site is used.