Enya Security
Request an audit
NIS2

How ready are you for NIS2?

The EU NIS2 directive raises cybersecurity requirements for a wide range of organisations across Europe. Each member state transposes it into its own national law, so the obligations and deadlines that apply to you depend on where you operate.

Regulatory
and governance duties
Risk management
and incident reporting
Training
and accountability

Overview

NIS2 aims to raise the common level of cybersecurity across the European Union. It distinguishes between essential and important entities, with obligations scaled accordingly and enforcement handled by each member state's national authority.

  • Directive (EU) 2022/2555, published 27 December 2022
  • Transposition deadline for member states: 17 October 2024
  • Penalties of up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities
Read the directive on EUR-Lex

Key obligations

  • Risk analysis and management
  • Appropriate and proportionate security measures
  • Reporting of significant incidents
  • Business continuity and crisis management
  • Governance and management-body accountability

Why a readiness assessment?

  • Clarify whether your organisation is in scope
  • Identify the main gaps against the requirements
  • Prioritise what needs attention first
  • Answer supply-chain security questionnaires with confidence
Request an assessment

What you receive

1

Scope qualification

An interview and questionnaire to establish which requirements apply to you.

2

Maturity report

A documented assessment of how far your current practices meet the requirements.

3

Prioritised action plan

Concrete recommendations, ranked by urgency and effort.

4

Debrief

A walkthrough of the findings and the next steps.

Take stock of your NIS2 readiness

Delivered remotely • Report in 5 to 10 business days • From €449

Request an assessment

Response within 24-48 business hours

Most small and medium-sized organisations are not directly in scope, but are increasingly asked for security guarantees by clients who are. A readiness assessment is useful either way.

Transparency

Enya Security is not a supervisory authority and does not issue NIS2 certifications. This service is a documentary gap analysis and a set of prioritised recommendations. It does not constitute an attestation of legal compliance, and it does not replace a nationally qualified audit provider where one is required.

Important: NIS2 is an EU directive, which means it takes effect through each member state's national transposition. Scope, registration duties and deadlines therefore differ from one country to another. Our assessment methodology is built on the French framework (ANSSI) and the Italian framework (ACN, Legislative Decree 138/2024). If your organisation is established elsewhere in the EU, tell us at first contact and we will confirm what we can usefully cover before quoting.

Source: Directive (EU) 2022/2555 — EUR-Lex.