NIS2 requirements: does it apply to your company and how to prepare

NIS2 is the European Union cybersecurity directive that significantly widens the circle of companies obliged to manage cyber risks, report incidents and ensure that top management is accountable for security. In Lithuania, the directive’s requirements have been transposed into the national Cybersecurity Law, so for a large group of Lithuanian companies this is no longer a recommendation but a legal obligation. Whether it applies to your company depends on two things: the sector you operate in and the size of your organisation — the directive targets medium-sized and large organisations in important and critical sectors, as well as their supply chains.

The good news: NIS2 does not demand miracles, only orderly, documented cybersecurity hygiene — risk assessment, protective measures, incident management and training. The less good news: preparation takes time, so it is worth starting before the supervisory authority takes an interest or a client sends you a compliance questionnaire. In this guide we explain who the directive applies to, what it requires and where to begin.

What NIS2 is and how Lithuania implements it

NIS2 replaced the earlier, narrower directive on the security of network and information systems. The fundamental change is scope: where the old rules covered a relatively small circle of operators, the new ones span far more sectors and automatically include companies based on size criteria. In Lithuania the directive is implemented through the Cybersecurity Law, with supervision by the National Cyber Security Centre (NKSC), which maintains the registers of covered entities and receives incident notifications.

In plain terms: the state compiles a list of organisations whose disruption would harm society or the economy, and obliges them to manage cybersecurity in a structured way — with personal accountability of executives for making sure the requirements are actually implemented.

Who is covered: entities, sectors, size criteria

The directive distinguishes two categories of entities — essential and important. What differs is not so much the requirements themselves as the intensity of supervision: essential entities are supervised proactively (planned audits and inspections), important entities reactively — in response to incidents or complaints.

Criterion Essential entities Important entities
Typical sectors Energy, transport, banking and financial market infrastructure, healthcare, drinking water and wastewater, digital infrastructure, public administration, space Postal and courier services, waste management, chemicals and food production, manufacturing (electronics, machinery, vehicles, medical devices), digital service providers, research
Indicative size Generally large companies in critical sectors (from 250 employees or the corresponding turnover thresholds) Generally medium-sized companies (from 50 employees or the corresponding turnover thresholds) in the listed sectors
Exceptions regardless of size Some entities are included even when small — for example certain digital infrastructure providers or organisations whose services are critical to the state; the final lists are determined by the responsible authorities

Just as important, NIS2 works through the supply chain: even if your company does not formally appear on any list, but you provide services to an essential or important entity, your client will be obliged to assess your security — and in practice the requirements will flow down to you through contracts and questionnaires. The most reliable way to establish your status is to check the information published by NKSC or run a scoping assessment with specialists.

The core NIS2 requirements

  • Risk management. The organisation must regularly assess its cyber risks and implement proportionate technical and organisational measures: access control, multi-factor authentication, encryption, network segmentation and vulnerability management.
  • Incident management and reporting. There must be a clear process for detecting, containing and reporting incidents — significant incidents are reported to the authorities in stages: an early warning within a short window, followed by more detailed reports within the deadlines set by law.
  • Management accountability. Company leadership is responsible for implementation — it must approve the security measures, take part in training, and cannot simply delegate accountability to the IT department.
  • Business continuity. Backups, recovery plans and crisis management procedures are required — we cover this in more depth on the page about backups and business continuity.
  • Supply chain security. You must assess the security of your direct suppliers and service providers — including IT partners. What to include in those contracts is covered in our guide on what an IT support contract should include.
  • Training and hygiene. Regular cybersecurity training for staff and management, and baseline hygiene practices across the whole organisation.

Non-compliance carries financial penalties calculated as a share of company turnover, as well as personal liability for executives — the exact figures are set by legislation, but the essential message is simple: non-compliance costs more than preparation.

Preparation steps

  1. Gap assessment. Establish whether and to what extent NIS2 applies to your company, then compare your current security maturity against the requirements: which measures are already in place, what is documented, where the gaps are. A natural starting point is an IT infrastructure audit, which shows the real state of your infrastructure and processes.
  2. Remediation plan. Rank the gaps by risk and draw up an implementation plan with owners, deadlines and budget. The plan must be approved by management — that is not a formality but a direct NIS2 requirement.
  3. Implementation. Deploy the technical measures (access control, monitoring, backups, network protection), write and approve the procedures (incident management, continuity, supplier assessment), and run the training.
  4. Ongoing monitoring. Compliance is not a one-off project: it requires continuous systems monitoring, periodic risk reviews, incident exercises and up-to-date documentation. This is where automated systems monitoring and regular reporting help.

How an external IT partner with ISO 27001 helps

For most mid-sized companies, achieving NIS2 compliance with internal resources alone is difficult — what is missing is not willingness but security expertise, security tooling and time. An external IT partner that itself operates under the ISO 27001 information security standard reduces this burden substantially: a large share of the practices NIS2 requires (risk management, access control, incident logging, documentation) already runs inside the partner’s processes, so you do not need to build them from scratch. A certified partner also simplifies your own supply chain assessment — you can show clients and auditors independently verified evidence that your IT service provider manages security systematically. Read about our security services on the IT security page, and about the wider context on the IT support services page.

Why Altic IT

Our NIS2 readiness work is grounded not in theoretical recommendations but in practices we apply daily in our own certified operations and in client environments — including organisations subject to the strictest security requirements.

  • ISO 27001 (information security), ISO 20000 (IT service management) and ISO 14001 certifications;
  • professional liability and cyber risk insurance of EUR 2 million;
  • 180+ clients served, ~350 servers and ~3,500 computers and mobile devices under management;
  • clients include the Bank of Lithuania, the State Tax Inspectorate, Vilnius City Municipality, Turto bankas, Bitė Lietuva and Tele2;
  • IT operations managed according to ITSM, ITIL and COBIT practices, with TOGAF used in consulting;
  • continuous automated systems monitoring and regular reports — the evidence needed for compliance accumulates as a by-product;
  • every client gets an experienced external IT manager who also coordinates third-party suppliers as a single point of contact;
  • Microsoft Solutions Partner for Data & AI and Sophos Gold Partner statuses; the vast majority of clients come through referrals.

Frequently asked questions

  • How do I find out whether NIS2 applies to my company?

    Assess two criteria: whether you operate in one of the sectors listed in the directive, and whether you meet the size thresholds (indicatively, from a medium-sized company upwards). In Lithuania, the final register of covered entities is maintained by the National Cyber Security Centre. If in doubt, the fastest route is a short scoping assessment with specialists. Link to the requirements in Lithuanian legislation: https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/1a8657f2427a11efb121d2fe3a0eff27?jfwid=1670mmovyr

  • My company is small — can I ignore NIS2?

    Not necessarily. Some entities are included regardless of size, and more importantly, the requirements spread through the supply chain: if your clients are essential or important entities, they will be obliged to assess your security. Well-managed security becomes a competitive advantage even for companies with no formal obligation.

  • Is an ISO 27001 certificate mandatory for NIS2 compliance?

    No, the law does not require certification. However, ISO 27001 covers a large share of the practices NIS2 demands, so operating to the standard makes demonstrating compliance far easier. It also helps if your IT partner is certified — that simplifies your supply chain assessment.

  • Where should we start if we have done nothing yet?

    With a gap assessment: clarify the scope of application and compare your current state against the requirements. Then draw up a management-approved remediation plan and implement it in stages, ordered by risk. Starting early pays off — some measures (procedures, training, monitoring) need time to bed in.

  • What is management’s responsibility under NIS2?

    Leadership must approve the cybersecurity measures, oversee their implementation and personally take part in training. Non-compliance also carries personal liability for executives, which makes security a board-level matter rather than solely an IT department concern.

Book a NIS2 readiness consultation

Want a clear answer on whether NIS2 applies to your company and which measures you actually lack? Book a readiness consultation: we will assess the scope of application, run a gap analysis and deliver a remediation plan ranked by priority. Reach us via the contact page or by phone at +370 5 2032018.

Contact Altic IT

IT paslaugos verslui - Altic.lt
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Read more information about our Privacy policy