NIS2 Compliance

NIS2 compliance for your company

NIS2 is already law in Romania. We explain, without jargon, who it applies to, what you risk and what you need to do — and we give you a free checker to see where you stand in 2 minutes.

What is NIS2?

A European cybersecurity directive that requires a much larger number of companies to get their IT security in order — not as a recommendation, but as a legal obligation, with deadlines and penalties. The goal: fewer incidents and greater resilience. The challenge for companies: the requirements are concrete and must be proven.

Who does it apply to?

Medium and large companies (from roughly 50 employees or EUR 10M turnover) in regulated sectors — energy, healthcare, transport, water, manufacturing, digital infrastructure, IT services and others. Even if you are not an „essential entity”, you may be an „important” one. And if you are a supplier to a covered company, compliance is required across the supply chain.

What do you risk if you ignore it?

Significant fines

Up to millions of euros or a percentage of annual turnover, depending on the entity type.

Management liability

Responsibility sits with company management, not just „the IT person”. It is a business decision.

Reporting in 24–72h

Major incidents must be flagged within 24 hours and fully notified within 72 hours of detection.

NIS2 Compliance

Free NIS2 compliance checker

9 questions, 2 minutes, no personal data. You get a score and the priority gaps to close.

Mark where you stand on each measure:

Multi-factor authentication (MFA) on all accounts
Automated, tested backup with an immutable or offline copy
Next-gen firewall with network segmentation (VLAN/Zero Trust)
An incident response plan and a responsible person
Patch and vulnerability management
Secure configuration (hardening) on servers and workstations
Access control: least privilege, separate admin accounts
Centralized logging and monitoring with alerting
Documented security policies and staff training

Key NIS2 requirements at endpoint level

Access control

No local admin rights, MFA, a clear role model and PAM for critical access.

Secure configuration (hardening)

Unnecessary services disabled, restrictive firewall and CIS/BSI hardening policies.

Logging & monitoring

Central log storage and EDR solutions to document endpoint events.

Encryption & integrity

BitLocker, TPM and Secure Boot to protect data from manipulation.

Continuous review

Regular testing and proof of the measures' effectiveness - mandatory under NIS2.

Key NIS2 requirements at infrastructure level

Segmentation & Zero Trust

Network segmentation (VLAN) and a next-gen firewall that limit an attacker's lateral movement inside.

Redundancy & availability

HA equipment, redundant ISP links and elimination of single points of failure (SPOF).

Immutable backup & DR

Automated backup with an immutable/offline copy and a tested DR/BCP plan, with defined RTO/RPO.

Vulnerability management

Scanning and patching across servers, firewalls and network devices, with prioritized remediation.

Monitoring & detection

Centralized logging (SIEM), network detection and alerting for fast incident response.

NIS2 Compliance

From NIS2 requirements to concrete solutions

Every NIS2 requirement (Art. 21) has a clear technical solution. We choose the stack that fits your size and budget — Microsoft 365, Bitdefender, Coro, Fortinet or a combination.

Art. 21 (a) Risk analysis and security policies

Identifying risks and written policies for information systems.

NCS risk assessmentMicrosoft Purview Compliance Manager
Art. 21 (b) Incident handling

Detection, response and reporting of incidents within legal deadlines (24–72h).

Microsoft Sentinel (SIEM/SOAR)Bitdefender XDR / MDRCoro
Art. 21 (c) Continuity, backup and DR

Immutable backup, tested recovery plan and crisis management.

Veeam BackupWasabi (immutable cloud)NCS DR/BCP plan
Art. 21 (d) Supply chain security

Supplier assessment and controlled access for third parties.

NCS supplier policiesEntra Conditional AccessFortinet segmentation
Art. 21 (e) Acquisition, development, maintenance and vulnerabilities

Secure systems across the lifecycle and timely patching.

Intune / Bitdefender PatchVulnerability scanningCoro
Art. 21 (f) Assessing the effectiveness of measures

Periodic testing and auditing of the measures in place.

Periodic NCS auditSentinel / GravityZone dashboards
Art. 21 (g) Cyber hygiene and training

Best practices and employee training, including anti-phishing.

Phishing simulations (Defender / Coro)Employee training
Art. 21 (h) Cryptography and encryption

Protecting data at rest and in transit.

BitLocker + TPM (Intune)Email encryption / PurviewTLS 1.2/1.3
Art. 21 (i) Access control, HR and asset inventory

Least privilege, separate admin accounts and device inventory.

Entra ID (RBAC, PIM)Intune (inventory / compliance)
Art. 21 (j) MFA and secure communications

Strong authentication and protected communication channels.

Entra MFA + Conditional AccessFortiAuthenticator (optional)
NIS2 Compliance

The platforms we work with

We don't force a single vendor. We choose the tool that best fits what you already have and your budget.

Microsoft 365 Defender + Entra + Intune + Sentinel

Identity (MFA, Conditional Access, PIM), endpoint (Intune + Defender EDR), email (Defender for Office 365), SIEM (Sentinel) and data (Purview).

Ideal if you already use Microsoft 365.

Bitdefender GravityZone

Endpoint protection, EDR/XDR, patch management and encryption, with optional managed SOC (MDR).

When you want strong, centrally managed protection.

Coro

All-in-one, modular platform: endpoint, email, cloud, data and network, with a single console and a single agent.

A good fit for small and mid-sized companies that want solid security without complexity.

Fortinet

Next-gen firewall, network segmentation, VPN and centralized logging (FortiAnalyzer / FortiSIEM).

For network-level security and NIS2 segmentation.

Veeam + Wasabi

Automated, immutable backup with a cloud copy and tested recovery.

For NIS2-compliant backup and disaster recovery.

The NCS guarantee

Not just 'we help with NIS2'. We deliver complete, audit-ready compliance documentation - technical measures, policies and evidence. And if an inspection finds something we should have covered, we fix it at our own cost.

  • Assessment and a tailored compliance plan
  • Technical implementation and hardening: Fortinet + Microsoft 365 Defender + Intune
  • Audit-ready documentation and policies

Frequently asked questions about NIS2

Does NIS2 apply to small companies too?

NIS2 mainly targets medium and large companies in regulated sectors. However, small companies can be caught indirectly, as suppliers to a covered company that requires supply-chain compliance. Besides, NIS2 measures are good security practice for any organization anyway.

What is the compliance deadline?

The directive is already in force and transposed into national law. Our recommendation is to start assessment and implementation now — NIS2 compliance is not an overnight task, and requirements from partners and authorities are already appearing.

What happens if we don't comply?

You risk significant fines (up to millions of euros or a percentage of turnover), direct management liability and the obligation to report incidents within 24–72 hours. Beyond penalties, the absence of measures means a real risk of a security incident.

How long does a NIS2 implementation take and what does it cost?

It depends on your starting point. Typically an initial implementation runs over a few months, in stages: assessment, priority measures (MFA, backup, hardening), then maturity (segmentation, monitoring, documentation). It's best to start with an honest assessment of your current situation.

How can NCS help?

We run the compliance assessment, implement the technical measures (Microsoft 365, Fortinet, backup, endpoint protection), prepare the required documentation and policies, and support you during audits. In practice, we take on both the technical and the „paperwork” side, end to end.

NIS2 Compliance

Not sure where to start?

Start with an honest assessment. Run the checker above or talk directly to an NCS specialist — no obligations.