NIS2 compliance
The list of obligations, an assessment of where you stand, and paperwork that survives a regulator’s question.
For most companies NIS2 is not new software but a written record: who is responsible, what is monitored, how an incident is reported, and when the last restore test was run. Most of those controls already exist, they are simply not written down anywhere.
What the law requires
Croatia transposed the NIS2 directive through the Cyber Security Act (Zakon o kibernetičkoj sigurnosti). Entities in scope are classed as essential or important depending on sector and size, and they share the same core obligations:
- managing cyber risk through documented measures, from access control and backups to supplier security
- reporting significant incidents to the competent authority: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report after that
- management responsibility: the board approves the measures, oversees how they are carried out and answers for failures
Many companies are not in scope themselves but work for ones that are, so their clients send them security questionnaires asking the same things.
How we run the assessment
We start with a conversation with management and whoever runs IT. Then we look at how things actually are: who has administrator rights, where backups go and whether they have been tested, how systems are updated and which suppliers have access to the network. Each measure is compared with what exists, and the gap is written down.
Where a measure exists but is not documented, we document it. Where it does not exist, we propose the simplest way to put it in place.
We pay particular attention to suppliers: who maintains the accounting software, who has remote access to the till or the server, and on what terms. The law requires that risk to be assessed too, and it is exactly the part that often gets skipped.
What you end up with
A risk assessment, a list of measures and the people responsible for them, a remediation plan ordered by importance, and an incident reporting procedure with contacts and an early warning template. We try the procedure out in a short scenario exercise, to see who calls whom and how long it takes to gather the details for a report.
A legal opinion on whether you are in scope in borderline cases comes from a lawyer or the competent authority. We prepare the technical and organisational side.
Common questions
How do I know whether my company is in scope?
It depends on your sector and on company size by headcount and turnover, and some entities are in scope regardless of size. We go through the list of sectors with you, and for borderline cases we recommend checking with the competent authority.
Do we need ISO 27001 certification?
The law does not generally make it mandatory. ISO 27001 covers many of the same measures, so certified companies find it easier to show compliance, but what matters is that the measures are in place and documented.
How much does NIS2 preparation cost?
It depends on the size of the company, the number of systems and how much is already documented. After an initial conversation you get a quote for the assessment, and the scope of the remediation follows from its findings.