Netsmart’s consulting services and solutions are designed to support organizations in implementing the NIS-2 Directive effectively and efficiently.
We help you assess your readiness, define your roadmap to compliance, identify your scope, set up and implement your risk and security management frameworks, secure your IT supply chain and optimize your cybersecurity awareness program.
A typical NIS-2 compliance process, including security assessments, auditing, consulting, and tool implementation, takes 6 to 12 months (depending on the size of the organization).
Take Action Now. Contact Netsmart today and let us help you navigate the complexities of the NIS-2 Directive.
An in-depth analysis to assess the impact of the guidelines on your organization.
Evaluation of the current status of your regulatory security measures.
Identification of gaps in your technology and processes, defining necessary measures to ensure successful compliance with the NIS-2 Directive.
Development of a roadmap considering your company’s individual cyber risks.
Supporting your company in mitigating risks and implementing appropriate security measures.
Analysis and evaluation of existing processes to develop a customized reporting process.
Customized workshops and training sessions, providing practical insights and knowledge to ensure that participants gain the knowledge required to effectively implement the NIS-2 Directive.
The directive defines two categories for entities in scope: important and essential.
Essential Entities
Energy, Transport, Finance, Healthcare, Water, Digital Infrastructure, Public Administration, Space Activities
Important Entities
Postal Services, Waste Management, Chemicals, Food, Manufacturing, Digital Providers, Research
Entities in both categories will have to meet the same requirements. However, the distinction will be in the supervisory measures and penalties. Essential entities will be required to meet supervisory requirements as of the introduction of NIS-2, while the important entities will be subject to ex-post supervision, meaning that in case authorities receive evidence of non-compliance, action is taken.
The NIS-2 Directive (Network and Information Systems Security Directive) aims to establish harmonized requirements across the EU to enhance resilience against cyber-attacks and improve responses to multinational incidents. As the scope extends to additional sectors, the cybersecurity capabilities of affected institutions will be rigorously tested.
The directive categorizes entities into two groups: essential and important.
Essential Entities
These entities are critical to national infrastructure and include sectors like energy, transportation, finance, healthcare, and digital services.
Important Entities
This category encompasses a broader range of businesses, including postal services, waste management, manufacturing, and digital providers.
Both categories will have similar cybersecurity obligations. However, the enforcement approach differs slightly:
Essential Entities
Stricter supervision applies from the outset of NIS-2.
Important Entities
Supervision occurs after the fact (ex-post), meaning authorities may investigate potential non-compliance upon receiving evidence.
The directive simplifies how authorities determine which businesses fall under its umbrella. Large (headcount over 250 or more than 50 million revenue) and medium-sized (headcount over 50 or more than 10 million revenue) enterprises within defined sectors are automatically included in the scope. tly included in the scope.Member States also retain the authority to extend these requirements to smaller businesses deemed critical to specific sectors or services.
The NIS-2 Directive assigns accountability to the management of organizations in scope. It is mandatory for management to take responsibility for their cybersecurity maturity. This includes conducting risk assessments and approving risk treatment plans for implementation, among other tasks.
To perform these actions, management must undergo cybersecurity training. The Directive even suggests training not only management but also employees, for a more comprehensive understanding of cybersecurity.
NIS-2 introduces stricter penalties for non-compliance, with fines potentially reaching a significant percentage of an entity’s annual turnover.
Essential Entities
Maximum fines can reach €10 million or 2% of annual turnover (whichever is higher).
Important Entities
Maximum fines can reach €7 million or 1.4% of annual turnover (whichever is higher).