Preparing for NIS2: Your Roadmap to Cybersecurity Compliance

18. 1. 2024 | 5 min read | author: Kateřina Vaňková

Over the past year, significant attention in the security community has been devoted to the European NIS2 Directive and its incorporation into national laws. This legislative change will affect a wide range of medium and large organisations. So whether you operate in the private or public sector, you should be interested in this topic.

What do NIS2 and related changes in national laws mean for your organisation? And how can you implement its requirements in practice? Read more.

Kateřina is a Security Consultant focusing on information security management system, risk management and business continuity. In ensuring compliance with standards and laws, she has experience in conducting maturity assessments and setting corrective measures, especially in the area of ISO 27001 and the Czech Act on Cyber Security.

What is NIS2?

NIS2 is a European Directive intended to establish uniform rules on cyber security in all EU Member States. This Directive should be fully implemented in the national legislation of all EU countries by October 2024.

The most significant change is the expansion of the scope from the seven sectors regulated initially to fifteen. Tens of thousands of entities will now have to comply with the requirements of the Directive and national laws.

The security measures required by the Directive are not significantly new compared to the NIS2 or the requirements of various information security standards such as ISO 27001. NIS2 is a natural evolution rather than a radical revolution in the understanding of expected cybersecurity measures. Nevertheless, it can still be a significant challenge for many organisations, especially those that have not yet considered implementing an information security management system.

Indicative Timetable for the New Legislation

How Does It Concern You?

NIS2 will affect medium and large organisations operating in defined sectors. NIS2 distinguishes between essential and important entities. Essential entities are defined as large organisations operating in the sectors listed in Annex I, as well as other entities identified as critical either directly by NIS2 or by a specific EU country. Important entities are medium-sized organisations from the sectors listed in Annex I, and large and medium-sized organisations from the sectors listed in Annex II.

getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Energy
Energy
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Transport
Transport
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Bankingandfinancialmarkets
Banking and financial markets
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Watersuppliersanddistributors
Water suppliers and distributors
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Digitalinfrastructure
Digital infrastructure
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_ManagedICTserviceproviders
Managed ICT service providers
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Publicservice
Public service
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Postalservice
Postal service
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Wastemanagement
Waste management
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Chemicalindustry
Chemical industry
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Foodindustry
Food industry
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Manufacturing
Manufacturing
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Digiserviceproviders
Digi service providers
getData?accessKey=66e3fa38c06ce05d38980e94e36f18d6.29435661.276b26f8c2f74cc3a9beb3dbb56589c42de3ed6d&clientAwid=815aa54079914c30ac2c132ae7c1e23f&dataKey=prod2-small_Research
Research

What Can You Do?

Whether you belong to organisations under lower (important entities) or higher (essential entities) obligations, some requirements are common to both groups. You must adopt appropriate and proportionate technical, operational, and organisational measures to ensure the security of the networks and information systems used in your activities or to provide your services. You also must take steps to prevent incidents or minimise their impact on the users of your services. And set up reporting of incidents to relevant authorities if it occurs.

What are the new or more challenging topics?

Management of Cyber Security

Especially for organisations that have not yet been required to address information security, the biggest challenge initially will be to set up the strategy, roles and responsibilities and an overall framework for information security within the company. They must set this up, even if they must fulfil only the lower requirements level.

All organisations must have implemented functional and adequate processes for Business Continuity, Incident Management, Disaster Recovery, Backup Management, Third Party Management, Basic Cyber Hygiene and more.

Education

There is a new obligation to educate members of the management body on cybersecurity to be able to consider and assess cybersecurity risks. The typical training methods are seldom interesting for this specific group and the specific training objective, and therefore, alternatives such as Round Table exercises should be considered. Round Table exercises utilise experienced experts to discuss selected topics (usually the actual threats and their potential impacts) with members of management.

Another option that companies appreciate is the Table-Top Exercise, where tailored scenarios of cyber incidents are addressed. Through Table-Top exercises, you can identify weaknesses in your organisation's security and incident response and management process. The Round Table and Table-Top exercises will significantly enhance cybersecurity awareness among the most important target group.

Risk Analysis

Organisations under the NIS2 Directive must implement fundamental measures to reduce risk as part of risk management and mitigation efforts. Risk analysis is the primary measure here, followed by the management of the identified risks. This involves monitoring assets, evaluating them, conducting risk assessments, and creating a plan to mitigate identified risks.

The risk analysis is crucial for properly managing the organisation's cybersecurity processes. It serves to pinpoint risks that could cause significant problems for your organisation. Incorporating risk analysis into the organisation's processes ensures that decisions about which measures to implement and at what level or which not to implement are entirely justifiable and make sense even from the standpoint of efficient financial management. By thoroughly understanding the risks, organisations can allocate their resources more effectively, avoiding unnecessary expenditures on low-impact risks and focusing on measures that yield the highest benefit in reducing vulnerability and exposure.

However, conducting a risk analysis that provides valuable outputs is not simple. It's necessary to consider the appropriate granularity of inputs to weigh up the methodology that will be feasible to carry out in a reasonable amount of time and yield meaningful results. From our experience, it happens all too often that a risk analysis carried out improperly results in hundreds of risks that do not allow for sensible strategic decisions in cybersecurity management.

Reporting Incidents

Essential and critical entities must notify their competent authority without undue delay of any significant incident. Where an incident is likely to affect adversely the provisioning of their services, they must also inform the recipients of those services without undue delay.

A significant incident is an incident which has caused or is likely to cause severe disruption to the operation of the services or financial loss to the organisation or which has affected or is likely to affect other natural or legal persons by causing them significant material or non-material damage. From this vague specification, it is quite clear that almost any incident can be categorised as significant.

Notifying an incident must be made immediately but no later than 24 hours after discovery. To meet this requirement, an organisation must set up processes, responsibilities, and tools to ensure timely incident reporting.

This mechanism helps ensure that the relevant authorities have timely and sufficient information about current incidents and threats to other entities. This information should then be provided to other actors to improve readiness and response to incidents in the EU.

What Are the Specifics for the Czech Republic?

The Czech Republic is updating the Act on Cyber Security to align with the NIS2 Directive. The current draft is available for review, although it may change the legislative process. Based on the existing draft of the updated Regulation on Regulated Services, organisations can determine whether they are classified as significant or essential entities and will thus be subject to distinct regulatory requirements. The revised legislation is expected to come into effect by October 2024.

In the Czech Republic, NÚKIB (National Cyber and Information Security Agency) estimates an increase in the regulated subjects from 400 to more than 6,000 entities. However, the final number may be even higher.

How to Implement NIS2 into Your Practice?

The first step is to conduct a gap analysis. This analysis assesses the current state of information security management and the measures implemented in your organisation against the legislation. Rather than the general NIS2 regulation, it is advisable to assess compliance with its local implementation in the country in which your organisation operates.

Once you know your gaps, you can propose and implement measures to address them. Without a quality gap and risk analysis, the implementation of measures lacks the necessary order and priorities.

NIS2 brings about significant qualitative changes in cybersecurity's legislative and procedural aspects. Learn more about our collaboration, and if you are still determining how NIS2 will affect you or need help knowing where to implement mandatory measures, feel free to contact us. We would be happy to assist you with its complete implementation.

Prepare for NIS2 in Time with Us

Right in Your Inbox

Stay up to date and get the newsletter. Every month, you can look forward to exclusive educational content and news from the infosec world.

Info
Zabýváme se informační bezpečností. Naším cílem je zabezpečit nejcennější informace klientů, a tím chránit jejich podnikání.

© 2026 Axelum s.r.o.

Kontakt

Axelum s.r.o.

IČO: 25639056

DIČ: CZ699004029

V Kapslovně 2767/2

130 00 Prague CZ

info@axelum.eu

+420 221 400 111


Vytvořeno pomocí uuWebKit
document_check.svg
Na těchto webových stránkách používáme soubory cookies k zajištění jejich funkčnosti a dále k personalizaci reklam, a to výhradně s vaším souhlasem a v souladu s našimi Pravidly pro užívání cookies.

Kliknutím na tlačítko „Přijmout soubory cookies“ udělujete souhlas s využívaním vybraných souborů cookies a souhlasíte s předáním údajů o chování na našich webových stránkách pro zobrazení cílené reklamy na sociálních a reklamních sítích. Můžete si zvolit, které informace s námi chcete sdílet kliknutím na tlačítko Nastavení cookies.