NIS2 compliance, turned into audit-ready evidence

The NIS2 Directive (EU) 2022/2555 is the EU's cybersecurity baseline for essential and important entities. It replaces the original NIS Directive, dramatically widens the range of organisations in scope, and — for the first time — makes management bodies personally accountable for cybersecurity risk management.

RASDefense exists for exactly this obligation. We are the cybersecurity arm of RAS Institute, vetted through competitive EU procurement to hold three framework contracts with ENISA, the European Union Agency for Cybersecurity. That vetting is not an endorsement — it is independent, documented proof that our methodology withstood EU-grade scrutiny. We apply the same rigour to your NIS2 programme.

Who is in scope

NIS2 distinguishes essential entities (Annex I sectors of high criticality: energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space) and important entities (Annex II: postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research).

As a rule of thumb, you are in scope if you operate in one of those sectors and are at least a medium-sized enterprise — 50+ employees or more than €10 million annual turnover. Some entities (e.g. parts of digital infrastructure) are covered regardless of size, and member states may designate additional entities. If your customers are in scope, expect their supply-chain security requirements to reach you contractually even if the law does not.

Working in transport or logistics? See our dedicated guide for road transport and logistics.

What NIS2 actually requires

Article 21 requires an "all-hazards" set of cybersecurity risk-management measures:

  • risk analysis and information system security policies,
  • incident handling,
  • business continuity — backups, disaster recovery, crisis management,
  • supply chain security, including your direct suppliers' security posture,
  • security in network and system acquisition, development and maintenance,
  • policies to assess the effectiveness of the measures (this is where evidence lives),
  • cyber hygiene practices and cybersecurity training,
  • cryptography and, where appropriate, encryption,
  • HR security, access control and asset management,
  • multi-factor authentication and secured communications.

Article 23 sets the reporting clocks for significant incidents: early warning within 24 hours, incident notification within 72 hours, final report within one month.

Article 20 places the duty on management: the board approves the measures, oversees their implementation, must be trained — and can be held liable for infringements. Fines reach at least €10 million or 2% of worldwide turnover for essential entities (€7 million or 1.4% for important entities).

The hard part is not the checklist — it's proving it, continuously

Most organisations can produce a policy binder. What supervisors and auditors increasingly ask for is current evidence that the controls actually operate: this quarter's access reviews, last week's backup restore test, today's MFA coverage.

That is the problem RASDefense automates:

  1. Assess — an expert-led gap assessment sets your NIS2 baseline: scope, materiality, and where you actually stand.
  2. Evidence — our platform continuously checks your technical controls against the NIS2 control set using deterministic rules, not AI verdicts, and drafts an audit-ready evidence pack. An RAS expert reviews the exceptions and counter-signs every cycle.
  3. Respond — if a significant incident hits, the software runs the 24h / 72h / 30-day reporting clocks and assembles evidence; our experts and your team make every call and sign every submission.
  4. Assure — penetration testing, exercises and governance oversight, delivered by the senior specialists whose disciplines cleared ENISA's procurement vetting.

The same engine maps your controls once and reuses the evidence across ISO/IEC 27001, SOC 2 and the NIST Cybersecurity Framework — see our cybersecurity compliance hub.

National transposition: the deadlines are here

NIS2 applies through national law, and most member states have now transposed it. In Poland, the amended Act on the National Cybersecurity System (ustawa o KSC) entered into force on 3 April 2026: in-scope entities must register by 3 October 2026 and implement the required measures within 12 months. We cover the Polish regime in detail — in Polish — in our guide to NIS2 and the ustawa o KSC.

FAQ

Who is in scope of NIS2?

NIS2 covers essential and important entities in the sectors of Annex I (energy, transport, banking, health, digital infrastructure and more) and Annex II (postal and courier services, manufacturing, digital providers and more). As a rule, medium-sized and larger organisations — from 50 employees or €10 million turnover — active in those sectors are in scope, with some entities covered regardless of size.

What are the NIS2 incident reporting deadlines?

An early warning within 24 hours of becoming aware of a significant incident, a full incident notification within 72 hours, and a final report within one month. Intermediate updates can be requested at any time.

What fines can be imposed under NIS2?

Essential entities face administrative fines of up to at least €10 million or 2% of global annual turnover, whichever is higher; important entities up to at least €7 million or 1.4%. Management bodies can be held personally liable, and supervisors can order compliance measures and audits.

Is NIS2 already enforceable?

NIS2 is an EU directive: it applies through national transposition laws, and enforcement follows each member state's law. Most member states have adopted theirs — Poland's amended Act on the National Cybersecurity System, for example, entered into force on 3 April 2026 with registration required by 3 October 2026.

Make your compliance defensible.

Tell us where you are on the journey — we'll show you the fastest credible route to readiness, built on an EU-vetted methodology and agentic AI.

Email us