FAQ

Frequently asked questions about NIS2

Quick answers to the topics that come up most often when preparing for NIS2 — from whether the directive applies to you, to the details of reporting an incident to NBÚ or NÚKIB.

NIS2 basics

What is NIS2 and who does it apply to?

+

NIS2 (Network and Information Security Directive 2) is EU Directive 2022/2555. It obliges medium and large organisations in critical sectors to adopt cybersecurity measures. It covers 18 sectors — energy, transport, banking, healthcare, water, digital infrastructure, public administration, pharmaceuticals, postal and courier services and more. In the SK and CZ markets, roughly 10,000–12,000 companies will be in scope (compared to ~500 under NIS1).

Sources: Directive (EU) 2022/2555 · SK: Act 366/2024 Coll. · CZ: Act 264/2025 Sb.

What's the difference between Essential and Important entities?

+

Essential entities are large firms in the most critical sectors (Annex I — energy, transport, banks, healthcare, water, DNS, cloud…). Important entities are medium firms in Annex I or any medium/large firms in Annex II (postal, chemicals, pharmaceuticals, food, manufacturing, courier…). Essential faces stricter supervision (proactive audits), higher fines (up to €10M / 2% turnover vs €7M / 1.4% for Important) and personal liability for management.

Sources: NIS2 Art. 3, 23, 33-34 · Annex I and II

When did NIS2 take effect in Slovakia and Czechia?

+

The directive had to be transposed by 17 October 2024. Slovakia transposed it via Act 366/2024 Coll. (amending Act 69/2018) effective 1 January 2025, with NBÚ implementing decree 227/2025 in force from 1 September 2025. Czechia transposed it via Cybersecurity Act 264/2025 Coll., effective 1 November 2025 (replacing Act 181/2014 Coll.). Deadlines: in SK, notify NBÚ within 60 days of starting the activity (§ 17(2) of Act 69/2018) and implement measures within 12 months of entry in the register (§ 19(1)); in CZ, notify NÚKIB within 60 days of meeting the conditions (§ 6(1) of Act 264/2025 Coll.) and implement measures within 1 year of the registration decision (§ 13(4)).

Sources: SK Act 366/2024 · NBÚ Decree 227/2025 · CZ Act 264/2025 Sb.

Who regulates NIS2 in Slovakia and Czechia?

+

Slovakia: National Security Authority (NBÚ) via SK-CERT — entity registration, incident reporting, audits, fines. Reports go through the Unified Cybersecurity Information System (jiskb.nbu.gov.sk), or the form on sk-cert.sk without access. Czechia: National Cyber and Information Security Agency (NÚKIB); incidents in the lower-obligations regime go to the National CERT. Portal: portal.nukib.gov.cz. Both agencies issue sector guidance and risk assessment methodologies, and can fine directly without a court.

Sources: SK: nbu.gov.sk · CZ: nukib.cz · ENISA (EU Agency for Cybersecurity)

Scope and categorisation

How do I know if my company falls under NIS2?

+

Three criteria apply together: (1) your NACE sector must be in Annex I or II, (2) your company size must be medium or large (50+ employees, OR both annual turnover and annual balance sheet above €10M), (3) you must operate in the EU. Some companies are in scope even when smaller (size-cap exceptions) — for example public electronic communications providers, TLD registries, qualified trust service providers. The NISMap scope engine checks this automatically from your company ID via the public business register in 10 seconds.

Sources: NIS2 Art. 2(1) and 2(2) · Annex I and II · Commission Recommendation 2003/361/EC (SME definition)

Which sectors does NIS2 cover?

+

Annex I (11 Essential/Important sectors): energy (electricity, oil, gas, hydrogen), transport (aviation, rail, water, road), banking, financial markets, healthcare, drinking water, waste water, digital infrastructure, ICT service management, public administration, space. Annex II (7 Important sectors): postal and courier services, waste management, chemicals, food production and distribution, manufacturing (pharmaceuticals, medical devices, electronics, machinery, motor vehicles), digital providers (online marketplaces, search engines, social networks), research organisations.

Sources: NIS2 Annex I + II (18 sectors total)

How is company size calculated for NIS2?

+

The directive uses the SME definition from Commission Recommendation 2003/361/EC. Medium-sized enterprise (Article 2(1) of the Annex): fewer than 250 employees and annual turnover up to €50M or balance-sheet total up to €43M. Small enterprise: fewer than 50 employees and annual turnover or balance-sheet total up to €10M. The size condition of Article 2(1) NIS2 is met by enterprises that are at least medium-sized, i.e. 50 or more employees, or both turnover and balance-sheet total above €10M. A large enterprise has 250 or more employees, or turnover above €50M and at the same time a balance-sheet total above €43M. Note: for a corporate group, data of partner and linked enterprises count too (Articles 3 and 6 of the Annex). NISMap takes the company's own figures from public registers where available but does not aggregate group data; that has to be assessed manually.

Sources: Recommendation 2003/361/EC Art. 2-6 · NIS2 Art. 2(1)

I'm a subcontractor or a SaaS — does NIS2 apply to me?

+

Two scenarios. (A) If you are directly in Annex I/II and you are a medium/large firm — the full obligations apply to you. (B) If you are out of scope but you are a supplier to an Essential/Important entity, your customers are obliged under NIS2 Art. 21(2)(d) to audit you, require security clauses in contracts and report incidents. In practice even small SaaS/ICT suppliers are getting questionnaires, DPA requests, pentests. The NISMap vendor audit module helps you prepare and distribute your security posture to your customers.

Sources: NIS2 Art. 21(2)(d) supply chain security · NBÚ Decree 227/2025 § 7(2)

Duties, incidents, fines

What are the main obligations under NIS2 Art. 21?

+

Art. 21(2) lists 10 mandatory policy areas: (a) risk analysis policies, (b) incident handling, (c) business continuity (BCP/DRP, backups), (d) supply chain security, (e) development and maintenance security, (f) effectiveness assessment, (g) cyber hygiene and training, (h) cryptography, (i) HR security and access control, (j) multi-factor authentication, secure communications. Plus: registration with NBÚ/NÚKIB (Art. 3), incident reporting (Art. 23), management accountability (Art. 20). NISMap maps each of the 10 areas to specific questions and recommendations.

Sources: NIS2 Art. 20, 21, 23 · SK Act 69/2018 § 20 · CZ Act 264/2025 Coll. §§ 13-14

When do I have to report an incident and what are the deadlines?

+

NIS2 Art. 23 defines a 3-step timeline: Early warning within 24 hours of detecting a significant incident (whatever you know at that point), notification within 72 hours (expanded details + initial assessment), final report within 1 month (root cause analysis + measures). Recipient: SK — SK-CERT via the Unified Cybersecurity Information System (jiskb.nbu.gov.sk). CZ — NÚKIB (higher-obligations regime) or the National CERT (lower-obligations regime) via portal.nukib.gov.cz; in CZ the final report is due within 30 days of the notification (§ 16(3) of Act 264/2025 Coll.). A "significant" incident causes serious operational disruption or financial loss, or affects other natural/legal persons with considerable material or non-material damage.

Sources: NIS2 Art. 23(3) and 23(4) · SK Act 69/2018 § 24 · CZ Act 264/2025 Coll. §§ 15-16

What are the maximum fines for NIS2 breaches?

+

Under NIS2 (Art. 34): essential entity up to €10,000,000 or 2% of global annual turnover (whichever is higher), important entity up to €7,000,000 or 1.4% of turnover. In SK (§ 31 of Act 69/2018): up to €10,000,000 or 2% only for operators of a critical essential service, other operators of essential services up to €7,000,000 or 1.4%, selected duties €300 to €500,000. In CZ (§ 59(4) of Act 264/2025 Coll.): up to CZK 250,000,000 or 2% (higher-obligations regime), up to CZK 175,000,000 or 1.4% (lower-obligations regime). Fines stack with GDPR (up to €20M / 4% turnover) — concurrent breaches can add up. Fines are administrative and imposed directly by NBÚ/NÚKIB without a court. For essential entities, where other measures are ineffective, the regulator can suspend a certification or authorisation and request a temporary ban from management functions (NIS2 Art. 32(5); SK § 29j(4) of Act 69/2018, CZ § 58 of Act 264/2025 Coll.).

Sources: NIS2 Art. 32 and 34 · SK § 31 Act 69/2018 · CZ § 59 Act 264/2025 Coll.

Can members of management be personally liable?

+

Partly. NIS2 Art. 20 requires management bodies to approve cybersecurity measures, oversee their implementation and undergo training; they must be liable for breaches of Art. 21 under national law. Neither NIS2 nor the SK and CZ acts provide for a fine imposed directly on a board member — fines under § 31 of Act 69/2018 and § 59 of Act 264/2025 Coll. are imposed on the entity. The personal consequence is a temporary ban from office: NIS2 Art. 32(5) for essential entities, in SK the statutory body of an operator of a critical essential service (§ 29j(4) of Act 69/2018), in CZ a statutory-body member of a higher-regime provider (§ 58 of Act 264/2025 Coll.). Liability towards the company itself follows corporate law. The NISMap board-liability calculator shows where your gaps are.

Sources: NIS2 Art. 20 and Art. 32(5) · SK § 20(4)(h) and § 29j(4) Act 69/2018 · CZ §§ 14 and 58 Act 264/2025 Coll.

Self-assessment and audit

Is a NISMap self-assessment legally valid?

+

NISMap generates documents and assessments that you can use as input for your internal documentation and for communication with NBÚ/NÚKIB. For a binding entity categorisation (Essential vs Important), however, you must contact NBÚ SR (jiskb.nbu.gov.sk) or NÚKIB (portal.nukib.gov.cz) and register. In practice: a NISMap report helps you prepare for proactive audits (Essential), reactive post-incident investigations, or customer due diligence. For ISO 27001/27002 certification you need an external accredited auditor.

Sources: Directive 2022/2555 has no formal certification scheme · NBÚ and NÚKIB as binding authorities

When do I need an external auditor and what does it cost?

+

An external auditor is useful in 3 scenarios: (1) your customer requires it in a tender or contract (typical for banks, telcos, public sector), (2) you want an ISO 27001 certificate as a competitive edge, (3) after a serious incident you need credible confirmation that remediation was done properly. External audit price in SK/CZ: small firm €3-8k, medium €10-25k, large €30-60k+ (plus annual recertification). The Documentation prepared in NISMap can shorten the auditor's preparation; our auditor marketplace is in preparation.

Sources: ISO 27001 accreditation (SNAS, ČIA) · NISMap (auditor marketplace in preparation)

What's the relationship between NIS2 and ISO 27001?

+

ISO 27001 is an international standard for an Information Security Management System (ISMS). NIS2 is an EU legal regulation. Their topics largely overlap: both require risk analysis, access control, incident reporting, training, business continuity. Differences: NIS2 has concrete sector-specific obligations (postal, manufacturing…) + incident reporting deadlines + personal management liability — ISO doesn't. Conversely ISO requires a formal Statement of Applicability, external audit and a 3-year certification cycle. Ideal setup: ISO 27001 as the base + NIS2 add-on for sector specifics.

Sources: ISO/IEC 27001:2022 · NIS2 Art. 21(2) · ENISA NIS2 Technical Implementation Guidance, mapping table (June 2025)

NISMap product

How much does NISMap cost?

+

Public surfaces (NIS2 map, scope-check, frameworks crosswalk, policy metadata library) are freely available without registration. Pro €99/mo — unlimited scans, AI reports, document generation, AI pre-fill of the NIS2 questionnaire, GDPR suite, compliance tracking. Business €249/mo — full multi-framework (NIS2 + GDPR + DORA + ISO), supply chain audit, multi-user RBAC, audit sharing. Auditor €499/mo — multi-tenant up to 25 clients, white-label, marketplace listing. Enterprise from €1,499/mo — banks, insurers, terms by agreement (sales-call gated). Holding tier €49/entity/mo from 4 entities, single contract. NIS2 readiness bundle €49/mo — standalone bundle (not an add-on to a tier). Paid plans are ordered via sales@nismap.com; there is no trial. Current pricing: /pricing.

Sources: /pricing · Stripe billing in EUR

How does NISMap protect my data?

+

Data is hosted in the EU (Supabase Frankfurt, AES-256 at rest, TLS 1.3 in transit). Sensitive PII fields are encrypted per-row via Supabase Vault. Before data is sent to AI (Claude by Anthropic) we automatically remove company IDs, company names, contact details and recognised personal names and addresses (names and addresses heuristically, without a guarantee). Transfers outside the EU rely on Schrems II safeguards: Supabase SCC Module 2, Anthropic SCC (Modules 2 and 3), Stripe SCC + PCI-DSS Level 1. Full sub-processor list + DPA links at /sub-processors. Zero tracking cookies, GDPR-first architecture.

Sources: /privacy · /sub-processors · /security

Can I try NISMap for free?

+

Yes, immediately — just enter a domain or company ID on the homepage. Within 30 seconds you get (a) NIS2 scope check (Essential / Important / out of scope), (b) technical security scan (TLS, headers, DNS, CMS CVE), (c) compliance score estimate. Public tools require no registration and no credit card. To save your results and scan history, a free e-mail registration is enough; trend tracking and the AI report are part of the paid plans. No commitment, cancel any time.

Sources: Scope engine, Free tools

How do I issue a NIS2 certificate and web badge for my company website?

+

After completing the NIS2 assessment (scope check + questionnaire), go to dashboard → Certificates and issue a 12-month self-assessment certificate. You receive a public verification URL + SVG badge in 3 sizes (sm / md / lg) with an HTML embed snippet. The badge on your company website acts as a marketing signal for clients during tenders or vendor onboarding — every click leads to a verification page showing the current certificate status. Free without registration. Competing platforms (NIS2-Conform.eu) charge €980/year for the same service. Details: /certificates.

Sources: /certificates · /dashboard/certificates · NIS2 Directive 2022/2555

What is the cross-framework crosswalk and how does it help me?

+

The crosswalk is a matrix of 10 NIS2 areas × 6 frameworks (NIS2, GDPR, DORA, ISO 27001, NIST CSF 2.0, CIS Controls v8). For each combination it shows the closest article or control and a qualitative link level (partial link / no link), without percentages — it is our own comparison of the texts, not the result of a study. Most NIS2 areas have a partial counterpart in ISO 27001, NIST CSF, CIS Controls and DORA, and in GDPR only where personal data is involved. The matrix shows where one process can serve several frameworks and what each of them still needs. Free at /frameworks/crosswalk.

Sources: /frameworks/crosswalk

How does NISMap detect concentration risk in the supply chain?

+

NISMap automatically analyses your suppliers via RPVS (SK), RPO (CZ), ARES and Entyrix. No manual entry — just the supplier's company ID, and we fill in UBO, ownership structure, credit scoring and sanction lists. Graph-based detection looks for hidden links: shared beneficial owners (UBO), shared corporate parents, shared banks/IBAN, geographic concentration. Alert when 2+ suppliers share a node — NIS2 Art. 21(2)(d) + Art. 29 DORA concentration risk monitoring. Details: /supply-chain.

Sources: /supply-chain · NIS2 Art. 21(2)(d) · Art. 28-30 DORA · RPVS/RPO/ARES

How does NISMap track regulatory incident deadlines?

+

The dashboard shows a unified countdown across all frameworks — DORA 4h initial classification, NIS2 24h early warning, NIS2 72h incident report, NIS2 final report within 1 month (CZ: 30 days), GDPR 72h supervisor notification. When you open an incident, deadlines for applicable frameworks are calculated automatically. States: pending (green) / due_soon (amber, last 25% of the window) / overdue (red). Each deadline links to its legal basis (NIS2 Art. 23, Art. 19 DORA, Art. 33 GDPR + SK 69/2018 § 24, CZ 264/2025). Email notifications and auto-escalation in Pro tier.

Sources: NIS2 Art. 23 · Art. 19 DORA · Art. 33 GDPR · /dashboard/incidents

Check your company's NIS2 status

Enter your company ID and within 10 seconds you'll know whether you are Essential, Important or out of scope.

Check free by company ID

Answers are indicative. For a binding scope determination contact NBÚ SR (sk-cert.sk) or NÚKIB ČR (nukib.cz), or a certified auditor.