Be NIS2 Compliant

We’re here to help you overcome the challenges posed by the new NIS2 Directive. With our expertise and experience in cyber protection, we will provide you with the support and solutions you need to navigate safely through the digital landscape.

NIS2 is not just another regulation; it’s an opportunity to strengthen your digital security and build a resilient infrastructure for the future. With our help, you can turn an obligation into an advantage and take your company to a new level of data and information protection.

Continuous Risk Monitoring and Rapid Response

We monitor and identify potential threats and vulnerabilities in your digital infrastructure and provide flexible solutions to respond quickly to potential cyber attacks.

Cybersecurity Strategy Implementation

We design and help implement strategies that enhance the security of your information systems and ensure compliance with current cyber protection requirements.

NIS2 Compliance Assessment

We provide a comprehensive analysis and assessment of your current level of NIS2 compliance so you have a clear picture of where you stand in the process of adapting to the new standards.

About Us

Your Cybersecurity Partners

We are CIGroupEMEA, your trusted partners in cybersecurity. With our team of experts who have extensive experience in the industry, we provide you with industry-leading services and solutions that protect your business from ever-increasing cyber threats. Our goal is to ensure you are compliant with the latest security standards so you can focus on growing your business. 

cyber-security-14

Be ready for NIS2!

Do you want to be ready for NIS2 and stay ahead of the legislative changes?
Sign up for our newsletter and receive a free NIS2 checklist.

Our Services

Tailored Security Solutions

We help you protect your digital world from ever-evolving cyber threats with our industry-leading services and customized security strategies.

Cyber Audit with Key Recommendations

We conduct a full cybersecurity audit to identify all potential improvement opportunities and incompliance to your digital infrastructure. The output is a report listing the most serious issues and recommendations to help you take the first steps towards NIS2 compliance.
cyber-security-illustrated-icons-03

Full Audit with Detailed Solutions

We provide a detailed audit with a full output that includes a comprehensive report identifying all risks and vulnerabilities, along with specific solution suggestions. This audit will provide you with all the necessary information and steps to fully comply with the NIS2 Directive.

Comprehensive NIS2 Solution from A to Z

We offer a complete NIS2 compliance solution. We provide not only a cybersecurity audit, but also the implementation of all necessary measures. From identifying risks to implementing security strategies, we ensure your organization is fully compliant with NIS2 requirements.

NIS2

Cybersecurity Act

The Network and Information System Directive 2 (NIS2) is a European directive that sets out the rules and requirements for cybersecurity and ICT systems. It came into force at the beginning of 2023 and, together with other EU legislative instruments, aims to increase digital operational resilience and cybersecurity in the European Union. 

The new Directive (EU) 2022/2555 of the European Parliament and of the Council on measures to ensure a high common level of cybersecurity in the Union (“NIS2 Directive”) entered into force on 16 January 2023. Member States are obliged to implement the NIS2 Directive in their legal systems by 17 October 2024 at the latest. 

The implementation of NIS2 is ensured by an amendment to the Cyber Security Act (ZoKB) issued by the National Cyber and Information Security Bureau (NCISB). The bill is currently on the books for consideration in the Chamber of Deputies.

Who Will Be Covered by NIS2 and ZoKB?

NIS2 applies to regulated service providers in the EU, as well as to entities that meet the European Commission’s criteria for medium or large enterprises. This includes public and private sector organizations that represent critical or important sectors, such as electricity, healthcare, or electronic communications.

Consequences of Non-Compliance

Failure to comply with the NIS2 requirements can have significant consequences, including financial penalties and suspension of certification. The Directive introduces a range of sanctions and control measures for effective enforcement and compliance.

Are You Within the Scope of NIS2?

What Measures Do You Need to Take?

The planned law sets new cybersecurity requirements for many companies. Fill out our form to find out how the proposed new cybersecurity law may affect your organization.

NIS2 Entity Categories
If your organization falls under any of the categories listed below, the NIS2 Directive applies to you. In such a case, we recommend familiarizing yourself with the sector-specific cybersecurity challenges through the provided links, as well as the general NIS2 requirements.

Essential Entities (EE)
Size threshold: varies by sector, but generally 250 employees, an annual turnover of €50 million, or a balance sheet of €43 million.

      • Energy
      • Transport
      • Finance
      • Public Administration
      • Health
      • Space
      • Water Supply (Drinking & Wastewater)
      • Digital Infrastructure
        (e.g., cloud computing service providers and ICT management)

Important Entities (IE)
Size threshold: varies by sector, but generally 50 employees, an annual turnover of €10 million, or a balance sheet of €10 million.

      • Postal Services
      • Waste Management
      • Chemicals
      • Research
      • Food
      • Manufacturing
        (e.g., medical devices and other equipment)
      • Digital Providers
        (e.g., social networks, search engines, online marketplaces)

Additionally, all sectors classified under “Essential Entities” that meet the size threshold for “Important Entities” also fall under NIS2.

Note:
An entity may still be classified as “essential” or “important” even if it does not meet the size criteria, particularly in cases where it is the sole provider of a critical service for societal or economic activity in a Member State.

FAQ

Frequently Asked Questions

What is NIS2?

NIS2 is an updated version of the 2016 EU Network and Information Security (NIS) Directive. This directive introduces a new standard for securing cyberspace across Europe. It aims to unify the cybersecurity regulatory framework among EU member states. NIS2 must be implemented in national legislation by 17 October 2024, replacing the original NIS Directive.

How does NIS2 differ from the original NIS Directive?

The original NIS Directive focused on a limited range of organizations with a high impact on society. NIS2 expands this to cover all providers of essential services. It introduces stricter requirements for managing cybersecurity risks and reporting incidents. Another key change is categorizing entities into ‘important’ and ‘essential’, which determines the level of obligations each organization must meet.

Who is affected by NIS2?

NIS2 applies to medium and large organizations that provide essential services in sectors such as energy, transport, healthcare, digital infrastructure, and others. Some services, such as electronic communications providers, are covered by the Directive regardless of the size of the organization. Each company should check whether it is affected by the Directive by consulting the relevant legislation.

What is the relationship between NIS2 and the Czech Cybersecurity Act?

NIS2 is an EU directive that must be transposed into Czech law through the new Cybersecurity Act. This law must meet the minimum requirements set out by the Directive, although Czech regulations may impose stricter standards.

What are the penalties for non-compliance with NIS2?

If an organization fails to comply with the NIS2 requirements, it may face fines of up to €10 million or 2% of global turnover for essential entities. For important entities, fines can be as high as €7 million or 1.4% of turnover. In addition to financial penalties, other measures such as mandatory incident reporting or the implementation of corrective actions may be ordered.

Are there exemptions for certain organizations under NIS2?

Yes, some services, such as electronic communications or DNS service providers, fall under NIS2 regardless of the size of the organization. Member states may expand the scope of regulated entities based on their national needs.

What are the main requirements of NIS2?

The primary requirement of NIS2 is that organizations adopt technical, operational, and organizational measures to manage security risks. The directive outlines 10 key areas, such as information systems security management, incident handling, supply chain security, backup, and disaster recovery, among others.

What are the obligations under the new Cybersecurity Act?

Organizations that fall under the regulation will need to register their obligations, implement cybersecurity management measures, report security incidents, and implement required countermeasures. Providers of critical services must also ensure the security of their supply chain and the availability of critical services.

Who is responsible for transposing NIS2 into Czech law?

The National Authority for Cyber and Information Security (NÚKIB) is responsible for transposing the NIS2 Directive into Czech legislation.

When must organizations comply with the requirements of the new law?

Organizations must report their obligations to NÚKIB within 30 days of determining that they fall under the regulation. They then have 1 year from the date of registration to implement the necessary measures.

Contact

(+420) 793 923 473

(+420) 736 238 825

nis2@cigroupemea.com

www.cigroupemea.com

Nové sady 988/2, 602 00 Brno

Mon — Fri: 8:00 — 22:00

IN: 14202816 TIN: CZ14202816

MM

The first consultation is free!

NIS2.SUPPORT

Do you need help with the new NIS2 directive? Do not hesitate to contact us, we are here to help you!

* Required field

How Does the Cooperation Work?

communication

First Contact

Fill out our form, call, or email us to get in touch.
 01 
book_535405

Solution Proposal

We will get in touch with you and propose a tailor-made solution for your company. We’ll discuss what options are available and where we can best help you.
 02 
execution

Implementation

After your approval, we’ll get to work. We can work on-site or connect remotely depending on your preference.
 03