Be NIS2 Compliant
We’re here to help you overcome the challenges posed by the new NIS2 Directive. With our expertise and experience in cyber protection, we will provide you with the support and solutions you need to navigate safely through the digital landscape.
NIS2 is not just another regulation; it’s an opportunity to strengthen your digital security and build a resilient infrastructure for the future. With our help, you can turn an obligation into an advantage and take your company to a new level of data and information protection.
Continuous Risk Monitoring and Rapid Response
We monitor and identify potential threats and vulnerabilities in your digital infrastructure and provide flexible solutions to respond quickly to potential cyber attacks.
Cybersecurity Strategy Implementation
NIS2 Compliance Assessment
About Us
Your Cybersecurity Partners
We are CIGroupEMEA, your trusted partners in cybersecurity. With our team of experts who have extensive experience in the industry, we provide you with industry-leading services and solutions that protect your business from ever-increasing cyber threats. Our goal is to ensure you are compliant with the latest security standards so you can focus on growing your business.
Our Services
Tailored Security Solutions
Cyber Audit with Key Recommendations
Full Audit with Detailed Solutions
Comprehensive NIS2 Solution from A to Z
NIS2
Cybersecurity Act
The new Directive (EU) 2022/2555 of the European Parliament and of the Council on measures to ensure a high common level of cybersecurity in the Union (“NIS2 Directive”) entered into force on 16 January 2023. Member States are obliged to implement the NIS2 Directive in their legal systems by 17 October 2024 at the latest.
The implementation of NIS2 is ensured by an amendment to the Cyber Security Act (ZoKB) issued by the National Cyber and Information Security Bureau (NCISB). The bill is currently on the books for consideration in the Chamber of Deputies.
Who Will Be Covered by NIS2 and ZoKB?
NIS2 applies to regulated service providers in the EU, as well as to entities that meet the European Commission’s criteria for medium or large enterprises. This includes public and private sector organizations that represent critical or important sectors, such as electricity, healthcare, or electronic communications.
Consequences of Non-Compliance
Failure to comply with the NIS2 requirements can have significant consequences, including financial penalties and suspension of certification. The Directive introduces a range of sanctions and control measures for effective enforcement and compliance.
Are You Within the Scope of NIS2?
What Measures Do You Need to Take?
The planned law sets new cybersecurity requirements for many companies. Fill out our form to find out how the proposed new cybersecurity law may affect your organization.
NIS2 Entity Categories
If your organization falls under any of the categories listed below, the NIS2 Directive applies to you. In such a case, we recommend familiarizing yourself with the sector-specific cybersecurity challenges through the provided links, as well as the general NIS2 requirements.
Essential Entities (EE)
Size threshold: varies by sector, but generally 250 employees, an annual turnover of €50 million, or a balance sheet of €43 million.
-
-
- Energy
- Transport
- Finance
- Public Administration
- Health
- Space
- Water Supply (Drinking & Wastewater)
- Digital Infrastructure
(e.g., cloud computing service providers and ICT management)
-
Important Entities (IE)
Size threshold: varies by sector, but generally 50 employees, an annual turnover of €10 million, or a balance sheet of €10 million.
-
-
- Postal Services
- Waste Management
- Chemicals
- Research
- Food
- Manufacturing
(e.g., medical devices and other equipment) - Digital Providers
(e.g., social networks, search engines, online marketplaces)
-
Additionally, all sectors classified under “Essential Entities” that meet the size threshold for “Important Entities” also fall under NIS2.
Note:
An entity may still be classified as “essential” or “important” even if it does not meet the size criteria, particularly in cases where it is the sole provider of a critical service for societal or economic activity in a Member State.
FAQ
Frequently Asked Questions
What is NIS2?
NIS2 is an updated version of the 2016 EU Network and Information Security (NIS) Directive. This directive introduces a new standard for securing cyberspace across Europe. It aims to unify the cybersecurity regulatory framework among EU member states. NIS2 must be implemented in national legislation by 17 October 2024, replacing the original NIS Directive.
How does NIS2 differ from the original NIS Directive?
The original NIS Directive focused on a limited range of organizations with a high impact on society. NIS2 expands this to cover all providers of essential services. It introduces stricter requirements for managing cybersecurity risks and reporting incidents. Another key change is categorizing entities into ‘important’ and ‘essential’, which determines the level of obligations each organization must meet.
Who is affected by NIS2?
NIS2 applies to medium and large organizations that provide essential services in sectors such as energy, transport, healthcare, digital infrastructure, and others. Some services, such as electronic communications providers, are covered by the Directive regardless of the size of the organization. Each company should check whether it is affected by the Directive by consulting the relevant legislation.
What is the relationship between NIS2 and the Czech Cybersecurity Act?
NIS2 is an EU directive that must be transposed into Czech law through the new Cybersecurity Act. This law must meet the minimum requirements set out by the Directive, although Czech regulations may impose stricter standards.
What are the penalties for non-compliance with NIS2?
If an organization fails to comply with the NIS2 requirements, it may face fines of up to €10 million or 2% of global turnover for essential entities. For important entities, fines can be as high as €7 million or 1.4% of turnover. In addition to financial penalties, other measures such as mandatory incident reporting or the implementation of corrective actions may be ordered.
Are there exemptions for certain organizations under NIS2?
Yes, some services, such as electronic communications or DNS service providers, fall under NIS2 regardless of the size of the organization. Member states may expand the scope of regulated entities based on their national needs.
What are the main requirements of NIS2?
The primary requirement of NIS2 is that organizations adopt technical, operational, and organizational measures to manage security risks. The directive outlines 10 key areas, such as information systems security management, incident handling, supply chain security, backup, and disaster recovery, among others.
What are the obligations under the new Cybersecurity Act?
Organizations that fall under the regulation will need to register their obligations, implement cybersecurity management measures, report security incidents, and implement required countermeasures. Providers of critical services must also ensure the security of their supply chain and the availability of critical services.
Who is responsible for transposing NIS2 into Czech law?
The National Authority for Cyber and Information Security (NÚKIB) is responsible for transposing the NIS2 Directive into Czech legislation.
When must organizations comply with the requirements of the new law?
Organizations must report their obligations to NÚKIB within 30 days of determining that they fall under the regulation. They then have 1 year from the date of registration to implement the necessary measures.
Contact
(+420) 793 923 473
(+420) 736 238 825
nis2@cigroupemea.com
www.cigroupemea.com
Nové sady 988/2, 602 00 Brno
IN: 14202816 TIN: CZ14202816
The first consultation is free!
NIS2.SUPPORT
How Does the Cooperation Work?
First Contact
Solution Proposal