Personal liability for management.
NIS 2 doesn't stop at the legal entity. Non-compliance creates direct liability for the company's management, so administrators can be suspended from their management duties.
You are in scope through your clients too.
Even if you don't fall directly within scope, regulated entities have supply-chain obligations. Their suppliers — perhaps your company — will get the questions sooner or later, in the form of questionnaires and contractual clauses.
Fines that show up on the balance sheet.
Up to 10 million euros or 2% of annual global turnover — whichever is higher. This is not a fine that fits under “other expenses”; it is a figure that changes the financial year.
How can you tell whether the NIS2 law applies to you?
If you recognize your company in one or more of the following situations, there is a good chance you fall within the scope of this legislative framework:
We operate in one of the following sectors: energy, transport, health, industrial manufacturing, digital infrastructure, postal services, waste management or the food industry.
We have at least 50 employees or over EUR 10 million in annual turnover.
We have clients or partners operating in the sectors above who already send us security questionnaires.
We haven't gone through the registration and self-assessment process in the DNSC tools.
We don't have a tested incident-response procedure — or it has never been tested under pressure.
Request a consulting session to find out for certain your company's current situation.
Compliance that can't be solved with a binder
What sets NIS 2 apart from any previous framework: it doesn't ask for a security policy, it asks for proof that security works — technically, preventively and operationally. We've worked in enough IT environments to know there is almost always a gap between a company's real IT situation and the level of security the company believes it has. We help you close this gap before someone else discovers it: an auditor, an incident or a supervisory authority.
How we support you toward compliance
NIS 2 gap analysis.
We assess the company's current position against the legal requirements and pinpoint exactly where the compliance vulnerabilities are. The result: a gap-analysis report, a risk matrix and a prioritized remediation plan with realistic deadlines.
A technical assessment, not a bureaucratic one.
Carried out according to DNSC guidelines and methodologies — we actually test the technical and organizational measures, not just their existence on paper. The difference between “we have a firewall” and “the firewall stops what it should” is exactly the difference we measure.
Support for the DNSC tools.
We guide you step by step through registration, the self-assessment questionnaires and the reporting flow to the National Cyber Security Directorate — a process you don't want to discover on your own, against the clock.
Correct documentation: technical and legal.
We assess existing policies, procedures, continuity and incident-response plans, then draft what's missing — together with lawyers specialized in IT security legislation, so you avoid the classic situation: a technically perfect report that isn't legally compliant. Or vice versa.
Preparation for incident reporting.
The legal deadlines are strict — early warning, update, final report — and they don't forgive improvisation. We build the internal flow before you need it. Our 20 years of activity have given us the experience to assist clients in the event of an incident, too.
Implementation, not just recommendations.
We support you in implementing the technical and organizational measures that result from the analysis, prioritized by risk and available budget. We don't just deliver a report — we deliver a plan you can execute, with verifiable evidence at each step.
Support for maintaining compliance.
Not just the initial implementation, but the ongoing activities after you've reached compliance. In-scope entities must carry out assessments of cybersecurity risks and of the potential impact of service disruptions. It's not a one-off assessment — it is redone periodically, as infrastructure or threats change. Among these activities: reviewing policies and procedures, updating the Risk Register, staff training, assessing critical suppliers, periodic internal technical audits, vulnerability scans on critical systems, incident-response simulations, action plans and service outsourcing.
Why ITPS?
20+ years in critical infrastructure.
We have a track record of projects where an incident or an hour of downtime truly matters — 868+ completed projects, across 12 industries.
We have clients in the sectors in scope.
Energy, health, industrial manufacturing, digital infrastructure, public administration / public institutions — sectors we've worked in for years, with the specifics, auditors and regulations of each.
Technical and legal, at the same table.
The technical team and lawyers specialized in IT governance work integrated into the project — recommendations are both operationally sound and legally defensible. Most offerings on the market cover only one of the two halves.
We apply to ourselves what we recommend.
We operate a Tier III datacenter certified by ADR, carrier-neutral, insured for 1 million euros. We are also ISO 27001-certified for information security. Compliance isn't a service we sell — it's a regime we live in and that is audited periodically.
Frequently asked questions
The NIS2 law has no ambiguous provisions. The technical mechanisms a company must meet are very clearly formulated. The difference lies in the technology used to meet the legal compliance requirements, and that is reflected in the cost and duration of implementation.
A 30-minute conversation with a specialized team tells you whether you're within scope and where your major exposure lies.
The conversation offers guidance and does not constitute legal advice.
