northdan.
Vezi pagina în română

IT Glossary

What is NIS2?

NIS2 is the European directive on the security of network and information systems, obliging organizations in essential and important sectors to implement cybersecurity measures and report incidents.

Until recently, cybersecurity was, legally speaking, a problem belonging to banks and energy operators. NIS2 changes that perimeter radically. The European directive, transposed into national law across member states including Romania, extends security obligations to far more sectors — energy, transport, health, water, digital infrastructure and public administration, but also manufacturing, food, waste management and postal services — and lowers the threshold to medium-sized companies inside them. In practice the organizations covered must implement cyber risk-management measures: security policies, vulnerability management, business-continuity plans, supply-chain security, encryption and staff training, plus reporting of significant incidents to the competent authority within short deadlines fixed by the national transposition. The novelty that stings is that management bodies are personally liable for non-compliance, and penalties are calculated against turnover rather than against a flat schedule. And even where your own company falls outside the direct scope, your customer may well fall inside it — at which point they will ask you, as a supplier, for evidence of your security posture before renewing anything at all.

Let’s talk about your project

Message us on WhatsApp or send an email — you talk directly to a developer.

office@northdan.com · +40 752 070 247

Why it matters for your business

A clarified perimeter of obligations

A scoping analysis establishes in writing whether the company is an essential entity, an important entity, or merely a supplier to one — and which concrete requirements follow from each case.

Incidents managed, not improvised

The detection and reporting procedures NIS2 requires mean an attack is handled against a rehearsed plan, with notification deadlines met, rather than in panic with fines on top.

Commercial advantage in the supply chain

Regulated entities must vet their suppliers, so a company able to demonstrate NIS2-aligned measures passes procurement filters that competitors quietly fail.

Frequently asked questions

How do I know whether NIS2 applies to my company?

Check two criteria: the sector, since the directive’s annexes cover essential and important sectors ranging from energy and health to food production and digital services, and the size, with the general threshold aimed at medium and large companies inside those sectors. National transposition legislation details the classification and the registration process with the competent authority, and certain critical entities are covered regardless of headcount.

What concrete measures does NIS2 require?

A minimum set of risk-management measures: risk analysis and security policies, incident handling, business continuity and backup, supply-chain security, security in the acquisition and development of systems, evaluation of how effective those measures actually are, cyber hygiene and training, encryption, access control and multi-factor authentication where appropriate.

What are the penalties for failing to comply with NIS2?

The directive provides for substantial administrative fines, capped either as a fixed amount or as a percentage of worldwide turnover, with the exact thresholds set by each transposition law. Separately from fines, management bodies can be held personally liable, and the authority may impose corrective measures or, in serious cases involving essential entities, temporarily suspend certain certifications or management functions.