NIS2
NIS2 might already apply to you. Where do you start?
The directive is European. The obligation that reaches you is a national law, and that law decides whether you are in scope and by when. This page is the map: what NIS2 asks for, which of our services answers which part, and where to begin from wherever you already are.
Scope is decided nationally, not in Brussels
NIS2 is a directive, which means it binds member states rather than companies directly. Each state writes its own law to implement it, and that law is what decides whether you are in scope, which category you land in, and what the deadlines are. Two companies of the same size and sector in two member states can get different answers.
Austria: NISG 2026
The Austrian implementation is in force and we have worked through the statute itself. A structured check tells you which category you fall into and what follows from it.
Check Austrian scopeEverywhere else, including Hungary
We establish scope as the first step of the engagement, against the national law that actually applies to you, rather than having you guess it from a web page. It is a short conversation and it changes everything that comes after.
Talk it throughWhat it asks of you, and where we do it
NIS2 does not ask for a document. It asks that specific things are true of your organisation and that you can show they are. Each of these is somebody’s job on a Monday morning.
Somebody has to own security
The duty sits with management rather than with IT: approving how risk is treated, overseeing it, and being able to answer for it. A named owner with real authority, without creating a full-time executive post.
Risks named and ranked
Security policies and a risk picture that reflects the business rather than a generic severity score, in an order somebody senior has actually agreed to.
Controls that exist and still run
Access control, multi-factor authentication, logging, backup and hardening. Specified is not the same as built, and built is not the same as still working next quarter.
Something watching
Detection and response run by an analyst team. An incident you first hear about in a customer email is an incident nobody was monitoring.
A response somebody has rehearsed
Incident handling, crisis management and the reporting path to the authority, decided before the incident. The clock starts with the incident, not with the meeting about it.
Your suppliers, and theirs
Supply chain security is called out explicitly. Assessment and continuous monitoring of third parties, rather than a questionnaire filed once and never read again.
People who recognise it
Basic cyber hygiene and training are named obligations, and training for management is named on its own. Phishing is still the most-cited way in.
Where you are, and the programme that fits
Most of this work begins because something already happened. What that something was decides where you begin.
There is a date, and no audit yet
The 180-day programme: scope first, then the gaps that actually matter, then a mock audit that ends in a decision rather than a hope.
The auditor has been and gone
Findings already written down, and a deadline that was not yours to set. The fixes put in the order that reduces risk soonest, each with a name and a date against it.
A customer is asking you to prove it
You are somebody else’s supplier, and their regulator has reached you through the contract. The answers assembled once, in a form that survives the next questionnaire.
You are established in Austria
NISG 2026 is in force there, with registration duties and dates of its own. The Austrian material is written in German and English.
What we do not do
We do not give a legal opinion on scope
Whether a law applies to you is a legal question. We can show you what the statute says and how comparable organisations have read it; a binding answer comes from your own counsel.
We do not issue a compliance certificate
What we produce is evidence: policies, records, and a register showing that the controls operate. That is what an auditor or an authority asks to see.
Austrian dates as at 29.09.2026. The regulation setting out the registration form had not been issued at that review.
What the directive actually says
The purpose, the sectors it reaches, the reporting duty and the governance expectations, summarised alongside DORA and ISO 27001.
Frequently asked questions
The questions we hear most often from security and IT leaders.
Something not covered here? Ask us directly
We cannot answer that from a web page, and it is not being withheld from you: the answer is written in your national implementing law, which decides which activities count, how size is measured and how a group is added up. Two companies with the same headcount in the same sector in two member states can land on opposite sides of it. What we can do is work through what you actually do, entity by entity, against the law that applies to you, and say which reading it supports and where it is genuinely borderline — a binding answer is your own counsel’s to give. Most companies find the more useful question is the next one: which of these obligations would we fail if we were in scope, because that work has to happen before the deadline either way.
For your Austrian entity, today and at no cost: the scope check on our Austrian page follows the statute’s own order, runs anonymously without registration, and shows you the provisions each answer rests on. For the Hungarian side the first step is sold as a piece of work on its own, and what it produces is a scope statement — the document that names the entity, the systems and where the boundary runs, approved by your management rather than asserted by us. That is the paper you put in front of your owners, and a gap analysis against it is the natural second half. The quote follows the first conversation and holds for thirty days.
Every member state has to name a supervisory authority, provide for administrative fines, and put the duty on the management body — approving the risk treatment, overseeing it and answering for it, including training that cannot be handed down to IT. That shape is the same across the EU because the directive sets it; the authority, the figures and the procedure are national. Austria’s are on our Austrian page with the provisions they rest on, and for your own jurisdiction we go through them with you rather than printing one country’s numbers on a page read in three — a binding view on your own exposure is your counsel’s to give. What we will say about the cost of doing nothing is that it tends to arrive commercially before it arrives legally: regulated customers have to account for their suppliers, and that reaches you as a questionnaire with a return date long before any inspector does.
One programme, with the Austrian entity handled inside it under Austrian law and the Hungarian entity under Hungarian law — that much is not a judgement call, and the registration, the dates and the reporting path are set per country. Whether fifteen people in Austria carry a duty of their own depends on the size rule and on how the statute counts a parent’s figures towards a subsidiary; the Austrian check walks exactly that, in the statute’s order, so you can have half the answer this afternoon by running it for the subsidiary. What you should not assume is that the Austrian answer transfers to the Hungarian company or the reverse. Assuming it does is the single most common mistake we see in groups that straddle a border.
For Austria, two dates come first and both are on our Austrian page with the provisions behind them: the law takes effect on 01.10.2026, and registration with the federal cybersecurity authority is due within three months of that, by 31.12.2026. The route is the business service portal, and at our last source review the regulation setting out the registration form itself had not been issued — so the window is open rather than missed, and the detail is still moving. Dates for the other member states we work in we go through with you against the implementing law that binds your own entities, because a date printed here for one country is the wrong date for a reader from another. Either way the work that has to be finished before a deadline is longer than the notice a deadline gives you, which is the practical argument for settling scope now rather than in the quarter the date falls.
With the scope question, which is a short conversation and the cheapest item on this page. The four situations above describe what usually triggers the call, not who is eligible; being told at an event that this probably applies to you is an entirely ordinary enquiry, and arguably the one best placed to plan calmly instead of against somebody else’s date. Mechanically: the button opens a short form, we usually reply within one working day, and the conversation itself is twenty minutes online — enough to establish whether and how we can help, and not enough to be a classification opinion or a plan, so please do not budget it as one. If the Austrian entity is your more urgent half, run the Austrian check first and bring the result with you.
Ours, as a service you buy from us; the card names the obligation and the link under it goes to how we meet it. It is delivered around the clock from our partner’s security operations centres under our contract, operating the Microsoft tooling you already license, and your logs stay inside your own tenant rather than being copied into ours. It runs on a recurring fee and for most clients it is the largest recurring line of the whole programme, so it belongs in a budget as its own item and not inside a compliance project. We do not run our own round-the-clock operations centre, and would rather say so than imply a building we do not have.
Some of it, and no. Multi-factor sign-in, logging, backup and monitoring have to exist and keep working, and whether you already own them usually turns on what your existing licensing includes rather than on anything we sell. Where a purchase is genuinely needed it is yours: licences, ingestion and consumption are billed to you by the vendor directly, and neither the products nor the technical remediation sit inside an advisory fee. That separation is deliberate — we hold no margin in your licence spend, which is the only honest basis on which anybody can tell you that you do not need a tool.
The professional role can sit outside your payroll — an external mandatee is permitted where the applicable implementation allows one, and in our markets it does — but the duty to approve risk treatment, oversee it and answer for it sits with your management body and cannot be delegated downwards to IT. So the usual answer is no for the accountable part and yes for the working part; putting the liability on three occupied IT staff is not an arrangement that survives scrutiny. On hours, for the 180-day programme specifically: an executive sponsor spends a couple of hours a month on approvals and the report, whoever owns the project internally spends a few hours a week, and IT operations carry the peak for the first five months because controls have to be built and then demonstrated. We put those numbers against your own scope before you sign.
Ready to get started?
Partner with Spirity Enterprise to implement the right security and IT solutions for your organization.