06 - NIS2 implementation

NIS2 is not just a legal folder. It is a technical implementation.

Policies are signed, documents archived - but when an auditor or incident arrives, the question is: is this actually implemented in the system? RBAC, MFA, audit trails, 24/72h reporting - we do this technically, not just on paper.

Send an enquiry

Similar challenge?

We respond within one business day.

Send inquiry
Why it hurts

Policies without implementation are not compliance. They are just paper.

NIS2 is an EU directive requiring organisations in critical sectors to establish technical and organisational security measures by the deadline set by national information security law.

up to €10m

Penalty for NIS2 violators at essential entities - or 2% of global annual turnover. Important entities face up to €7m or 1.4% of turnover. The supervisory authority actively checks this after incidents.

up to 60%

V10 co-financing (SPS) for ISO 27001 and NIS2 preparation covers up to 60% of eligible costs. Condition: the provider must be in the SPS catalogue. Available to Slovenian entities only — check current availability and deadlines at podjetniskisklad.si before including this in your financial plan.

24h / 72h / 30 days

NIS2 statutory incident reporting timeline: early warning within 24 hours, incident notification within 72 hours, final report within 30 days. Without audit trails and a technical detection system, you cannot meet these - regardless of how many documents you have signed.

What you get

NIS2 requirements - implemented, not just documented.

Access and role management (RBAC)
MFA for all users (where appropriate)
Audit trails and system logs
Secure offboarding - immediate deactivation
Backup management with verification
Incident reporting procedure (72h)
Review of existing infrastructure and gaps
Documentation for external audit
Detection of unauthorised access (system log review)
Periodic security status reports

Similar challenge?

We respond within one business day.

Send inquiry
Comparison

Before: a folder of policies. After: technical implementation with evidence.

Before
Policy folder Security policy ✓ Password policy ✓ MFA policy ✓ Offboarding procedure ✓ Technically: nothing implemented
After
Management system NIS2 ✓ RBAC accesses MFA all users Audit trails Security backups 72h reporting Offboarding procedure
Pricing

Two paths to NIS2 compliance.

Both paths start with a gap analysis (1,490 €, excl. VAT). Only after the review do we know exactly what needs to be done and which path fits your infrastructure and budget.

Recommended
Path A

Implementation + platform

Configuration in your infrastructure + access to our platform security module

Total (GAP + implementation)
from 4,000 €
excl. VAT · gap analysis 1,490 € + implementation from 2,510 €
Monthly subscription
from 90 €/mo
excl. VAT · platform + support + periodic reports
RBAC and MFA configuration in your infrastructure
Access to the platform module (audit trails, incident log)
Periodic security status reports
Documentation for external audit - yours to keep
Basic support included in the monthly fee
No access to platform source code
Enquiry for Path A
Path B

Implementation on your server

Custom-built tools deployed on your own infrastructure - no monthly subscription

One-time
from 12,000 €
excl. VAT · no monthly fee · SLA maintenance optional
Gap analysis and implementation on your infrastructure
Integration with existing AD, Google Workspace or proprietary systems
Custom-built tools and scripts - yours to keep
Security hardening and documentation for audit
No monthly platform subscription
The platform module (audit trails, incident log) is not included — that is exclusive to Path A. Equivalent custom development is possible within this package. After the 90-day warranty period, maintenance of the custom tools is your responsibility.
Enquiry for Path B

V10 voucher (SPS) — covers up to 60% of eligible ISO 27001/NIS2 implementation costs. Condition: the provider must be in the SPS catalogue. Available to Slovenian entities only. Check current programme availability and deadlines at podjetniskisklad.si before including this in your financial plan.

FAQ

Questions about NIS2 implementation.

Ownership & Terms

What is yours. What is not.

Configurations in your infrastructure remain your property. After the 90-day warranty period, maintaining those configurations is your responsibility. The platform module adds centralised audit trails and an incident log.

You receive
RBAC and MFA configuration in your existing infrastructure (Azure AD, Google Workspace, on-premise systems)
Access to the Iteca security module - audit trails, incident log, periodic security reports
Audit documentation for external review - all evidence remains your property
90-day warranty maintenance of configurations after implementation
Export of audit data in standard formats (CSV, JSON) at end of subscription
You cannot demand
Source code of the Iteca platform module - this is a SaaS component, not a software licence
Continued access to the platform module after subscription expiry without payment
Technical maintenance of your third-party infrastructure (Microsoft, Google) - that remains your responsibility
Transfer of platform access to a third party without written consent
Guarantee of NIS2 or ZInfV-1 compliance: compliance is your organisation's responsibility; we provide technical implementation support, not a legal compliance guarantee
Legal advice on interpreting regulatory requirements: consult a lawyer or dedicated NIS2 compliance specialist for that

NIS2 is not a bureaucratic obligation. It is a technical requirement - implement it properly.

Send an enquiry