02 · Audit
We check whether NIS2 applies to you, audit your organization against the 10 risk management measures and implement what is missing — policies, incident reporting, business continuity, supplier oversight and board training.
Service details
NIS2 (Directive (EU) 2022/2555) is the European Union's cybersecurity law for organizations that provide services essential to the economy and society. It replaces the original NIS directive, covers many more sectors and companies, and requires them to manage cybersecurity risk, report significant incidents and oversee the security of their suppliers — with the management board personally accountable.
In Poland, NIS2 is transposed by the amendment to the National Cybersecurity System Act (KSC 2.0). Remote Admin helps you determine whether and how you are covered, audits your organization against the requirements and implements what is missing — from policies and procedures to incident reporting and security testing.
Our services
A thorough review of your IT infrastructure, processes and security policies, with a gap report and an implementation plan with priorities.
Risk management, information security policy, access control, cryptography, asset management — documentation that meets the directive's requirements.
Detection, classification and an incident procedure that lets you meet the 24-hour, 72-hour and one-month reporting deadlines.
Continuity and disaster recovery plans, backup policy and recovery tests that keep your services running during an attack.
Assessment of IT suppliers, security requirements in contracts and ongoing oversight of third parties with access to your systems.
Cyber hygiene training for employees and mandatory cybersecurity training for management bodies, as NIS2 requires.
Who it applies to
Energy, transport, banking and financial market infrastructure, healthcare, drinking water and wastewater, digital infrastructure, ICT service management, public administration, space.
Postal and courier services, waste management, chemicals, food production and distribution, manufacturing (including medical devices, electronics, vehicles), digital providers, research organizations.
As a rule, medium and large enterprises (50+ employees, or annual turnover and balance sheet above EUR 10 million) — with exceptions for entities of particular importance regardless of size.
The amendment to the Polish National Cybersecurity System Act (KSC) transposes NIS2 — an entity register, obligations and penalties enforced by national authorities.
Obligations
Key facts
How we work
Questions and answers
It applies mainly to medium and large organizations (50 or more employees, or annual turnover and balance sheet above EUR 10 million) operating in one of the 18 sectors listed in the directive — for example energy, transport, banking, healthcare, digital infrastructure, ICT service management, manufacturing or food. Some entities, such as DNS and trust service providers, are covered regardless of size. We start every engagement by checking your classification.
Both must meet the same risk management and reporting obligations. The difference is in supervision and penalties: essential entities are supervised proactively and face fines of up to EUR 10 million or 2% of global turnover, while important entities are supervised after the fact, with fines of up to EUR 7 million or 1.4% of turnover.
For a significant incident: an early warning within 24 hours of becoming aware of it, an incident notification with an initial assessment within 72 hours, and a final report within one month. Meeting these deadlines requires monitoring and a rehearsed procedure — which is why many clients combine NIS2 with our 24/7 SOC.
Yes. Under NIS2, management bodies approve the cybersecurity risk management measures, oversee their implementation and can be held liable for failures. Board members are also required to take part in cybersecurity training.
KSC 2.0 is the amendment to the Polish National Cybersecurity System Act that transposes NIS2 into Polish law. It defines which entities are covered, their registration, obligations and the penalties enforced by Polish authorities.
Not as such. In the digital area NIS2 covers online marketplaces, search engines and social networking platforms, as well as cloud, data center and managed IT service providers. A regular online shop is usually covered only if it falls into another sector, such as food distribution or manufacturing, and meets the size threshold.
A classification of your organization, a maturity assessment against the 10 measures of Art. 21, a gap report with priorities and an implementation plan — typically for the next 90 days — plus, if you continue with us, the documentation and evidence for the supervisory authority.
Financial entities covered by DORA follow DORA as the more specific law for ICT risk. ISO 27001 is not required by NIS2, but an existing ISMS covers a large part of its measures and makes compliance much easier — we take it into account in the gap analysis.
Yes. We implement the missing measures, run penetration tests and vulnerability scanning, provide a vCISO to lead security on an ongoing basis and repeat audits periodically.
Related services
First step
30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.
A proposal with scope and pricing within 48 hours of the call.
Go to contact