731 901 601

NIS-2 Cybersecurity obligations

With our help, you will implement NIS-2

Czas Fast implementation
Puzzle Tailored to your company's needs
Bez papierologii No unnecessary paperwork

Over 5,000 small, medium, and large companies have trusted us over 25 years:

Request a free quote

fill out the form or call us

787 974 136 731 901 601
Certificate guarantee

Implementation Methodology

Discover our unique implementation methodology that guarantees
successful certification.

1
Development of a policy for the acquisition, development, maintenance and operation of the information system
Step 1:
2
Development of a physical and environmental security policy
Step 2:
3
Development of a human resources security policy
Step 3:
4
Development of a policy for continuous system monitoring
Step 4:
5
Development of a policy for assessing the effectiveness of security measures
Step 5:
6
Development of a cybersecurity training policy
Step 6:
7
Development of a cyber hygiene policy
Step 7:
8
Developing a policy on the use of cryptography
Step 8:
9
Developing a communication policy
Step 9:
10
Developing a policy on the inventory of information assets
Step 10:
11
Developing an access control policy
Step 11:
12
Developing a threat analysis policy
Step 12:
13
Developing a risk assessment procedure, including a sample risk assessment form
Step 13:
14
Developing a business continuity management procedure
Step 14:
15
Developing a disaster recovery policy
Step 15:
16
Development of an incident management procedure
Step 16:
17
Development of a supply chain management policy
Step 17:
18
Conducting online training on the organisational aspects of cybersecurity as defined in Article 6(3) of the NIS-2 Directive
Step 18:

What We Provide to Our Clients

Procedury
Development of all procedures and instructions
Zegar
Efficient and rapid preparation of documentation
Certyfikat
Training (confirmed by the issue of personalised certificates)

NIS 2 Directive – new cybersecurity obligations

The NIS 2 Directive (EU 2022/2555) is a set of EU regulations aimed at significantly raising the level of cybersecurity in organisations critical to the functioning of the economy and society. It replaces the previous NIS Directive, expanding both the scope of entities covered by the regulation and the list of obligations.

NIS 2 introduces uniform standards for information security management and cyber incident response across all EU Member States.

Who is affected by NIS 2?

The Directive covers a much wider range of organisations than before, including, amongst others:

  • energy, transport, banking and financial infrastructure,
  • healthcare and pharmaceuticals,
  • digital and IT service providers,
  • telecommunications, water supply and waste management,
  • industrial manufacturing, logistics and the food sector.

It is not only the sector that is key, but also the size of the organisation and its role in supply chains.

Key obligations under NIS 2

Organisations covered by NIS 2 must implement, among other things:

  • a systematic approach to cybersecurity risk management,
  • appropriate technical and organisational measures,
  • incident response and business continuity procedures,
  • an obligation to report incidents within strictly defined timeframes,
  • management oversight of cybersecurity (accountability of senior management).

The Directive places strong emphasis on management responsibility and the effective enforceability of the provisions.

Penalties for non-compliance

Failure to comply with the NIS 2 requirements may result in:

  • heavy financial penalties,
  • administrative sanctions,
  • personal liability of senior management,
  • loss of trust among customers and business partners.

Testimonials

See what our clients say about our implementations

AGH
Main Library of the Stanisław Staszic University of Science and Technology in Kraków
"The Main Library of the Stanisław Staszic University of Science and Technology in Kraków confirms that in 2011, DJB Doradztwo Marcin Chorąży provided a service at the Main Library of the University of Science and Technology consisting of the implementation of an information security management system compliant with the PN-ISO/IEC 27001 standard. The subject of the contract was performed with due diligence, in accordance with professional expertise and within the timeframe specified in the contract.

We particularly appreciate the delivery of a series of training sessions on the ISO 27001 standard for staff and management, which enabled us to organise proper oversight of the information security management system and its continuous development."
AGH BIBLIOTEKA GŁÓWNADr Jerzy Krawczyk
Deputy Director of the Main Library
DIRECT COMMUNICATION Sp. z o.o.
"Working with DJB Doradztwo enabled us to quickly implement the ISO 27001 system, provide professional training for our staff, and efficiently obtain the system certification required by our business partners.

Professionalism, flexibility and punctuality – these are the qualities that set DJB Doradztwo's staff apart. Thanks to them, the process of implementing the ISO 27001 system did not place an additional burden on our staff and allowed them to carry out their daily duties."
DIRECT COMMUNICATION Sp. z o.o.Krzysztof Kunowski
IT Director
PRIME FORCE Sp. z o.o.
"DJB Doradztwo Marcin Chorąży carried out a project for our organisation to implement the ISO 9001:2015 and ISO 27001:2017 standards in a professional and reliable manner, which enables us to recommend their services to all interested clients.

The implementation objectives were achieved to a high standard in terms of both content and organisation. The company developed excellent training materials tailored to our needs."
PRIME FORCE Sp. z o.o.Kazimierz Konarski
Commercial Director
SANDS PARTNERS Sp. z o.o.
"SANDS PARTNERS Sp. z o.o., based in Wrocław, would like to extend its sincere thanks to DJB Doradztwo Marcin Chorąży for their assistance in implementing the Information Security Management System (ISO 27001). The implementation of the System was carried out in a professional and timely manner, demonstrating excellent knowledge of the subject matter and an appropriately chosen approach. We rate our cooperation with the staff of DJB Doradztwo Marcin Chorąży very highly, both during the organisational phase and following the successful implementation of the System."
SANDS PARTNERS Sp. z o.o.Bartosz Strożek, Grzegorz Struś
Management Board of Sands Partners Sp. z o.o.