What is the NIS2 directive?
NIS2 (Network and Information Systems Directive 2) is a European Union directive that sets stricter cybersecurity requirements for public and private organizations. It took effect on 16 January 2023, and Member States must transpose it into national law by 17 October 2024.
NIS2 replaces the earlier NIS directive (2016) and aims to:
- Strengthen organizations' resilience to cyber threats;
- Ensure fast detection of and response to incidents;
- Improve cross-sector cooperation across the EU;
- Expand the list of sectors to which requirements apply.
NIS2 Response & Incident Reporting Timelines to NKSC
Griežti incidentų valdymo terminai pagal ES NIS2 direktyvą.
Initial Notification
Initial notification (Early Warning) about the incident.
Detailed Assessment
Detailed incident assessment with impact and solutions.
Final Report
Final technical incident report and preventive measures.
Where & how to report incidents?
Significant cybersecurity incidents must be reported to the National Cyber Security Centre (NKSC) under the Ministry of National Defence.
Reporting procedure:
- •Within 24 hours – submit an initial notification (early warning).
- •Within 72 hours – submit a more detailed report with context, impact and temporary solutions.
- •Within 1 month – submit a final report with technical details and long-term measures.
Contacts
Who does NIS2 apply to?
Important Sectors
Medium and large companies in critical fields such as energy, transport, healthcare, finance, water, etc.
Digital Services
Organizations providing digital services including cloud computing, data storage, email services, and managed IT service providers.
IT Infrastructure
Companies maintaining IT infrastructure – even acting as subcontractors or operating under white label partnerships.
Not applicable to micro-enterprises (up to 10 employees and < €2m turnover), unless they operate in very critical areas. Non-compliance may incur fines up to €10m or 2% of annual turnover.
What are the key requirements?
Organizations must strictly adhere to the following:
- Implement cybersecurity risk management measures;
- Have effective incident detection, prevention and response;
- Appoint a responsible person for cybersecurity;
- Follow accountability – report serious incidents within 24 hours;
- Be prepared for audits and random inspections.
Why is it important?
NIS2 is not just regulation, but a guarantee of business continuity. Proper preparation brings clear advantages.
Operational Security
Reduces the risk of data loss or severe operational disruptions.
Avoid Fines
Helps avoid steep fines (up to €10m or 2% of annual turnover).
Strengthened Trust
Builds absolute trust among your clients and business partners.
New Opportunities
Opens opportunities to work with larger organizations requiring compliance.
Need help preparing for NIS2?
MB “MEIDIT” can help your company assess its existing IT infrastructure, identify cybersecurity gaps, and implement technical and organizational measures to meet NIS2 requirements. Contact us — let’s turn NIS2 compliance from a burden into a competitive advantage.
