← 360 Gradus Design

// NIS2 · Directive (EU) 2022/2555

NIS2 readiness, assessed by engineers

Also available: Română · Italiano

NIS2 — Directive (EU) 2022/2555 — is now national law across the EU. It widens cybersecurity obligations to roughly 160,000 "essential" and "important" entities in 18 sectors, makes management personally accountable, and backs the requirements with fines of up to €10 million or 2% of worldwide turnover for essential entities (€7 million or 1.4% for important ones). Most in-scope organisations are not security companies — and the directive was written knowing that.

Who NIS2 applies to

Energy, transport, banking, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space — plus "important" sectors such as manufacturing of critical products, food, chemicals, waste, postal services, and digital providers. Size generally starts at 50 employees or €10M turnover, but supply-chain requirements pull smaller vendors in through their customers' contracts. If your customers are in scope, parts of NIS2 will arrive in your inbox as security questionnaires.

What the directive actually requires

Readiness assessment, done by engineers

Our assessment is not a questionnaire. It pairs document review with hands-on technical analysis — external attack surface, exposed services, DNS and email hygiene, patching posture, real-world exploitability — the methodology productised in RECON, the attack-surface management platform architected and development-led by this studio, which maps an organisation's full external footprint and auto-evaluates NIS2 technical coverage.

  1. Scope & classification — are you essential, important, or pulled in via supply chain; which national registration duties apply.
  2. Gap analysis — measured against the Article 21 measures, with evidence, not self-declarations.
  3. Remediation roadmap — prioritised by exploitability and cost, written for the people who will implement it.
  4. Re-measurement — the same scans re-run, so progress is a number, not an opinion.

Deadlines and penalties

Member states apply NIS2 through national law — in Romania supervision and registration run through DNSC, in Italy through ACN under D.Lgs 138/2024 — with registration windows, incident-reporting duties and sanctions already active. The pragmatic reading: regulators are prioritising entities that can show nothing. A measured baseline and a dated roadmap change your position entirely.

Fixed-scope engagements, delivered in English, Romanian or Italian. One conversation covers the technical and the commercial side — the same two principals answer for both.

[email protected]