NIS2 compliance and ISO 27001

Not merely a regulatory formality — a chance to make your organisation genuinely more resilient

The NIS2 Directive (2022/2555) sets stricter cybersecurity requirements for a wide range of organisations in Lithuania. It is implemented by the Lithuanian Law on Cyber Security (No. XII-1428, as amended in 2024) and the Description of Cyber Security Requirements (Government Resolution No. 818). In practice it is sometimes called TIS2. This is not only about avoiding fines — it is an opportunity to strengthen your organisation’s resilience to cyber threats in a systematic way.

NECT helps in practical terms — we do not only prepare the documents, we deploy real technical controls, train staff and management, and build processes that work every day, not just during an audit.

How NECT helps with NIS2

Scope assessment

We establish whether your organisation falls within the scope of NIS2 (as an essential or an important entity) and which specific obligations apply.

Gap analysis

We compare your current security maturity against the NIS2 requirements and identify the gaps. You see clearly where you are and where you need to be.

Risk assessment

Systematic identification and assessment of your organisation’s cyber risks. A formalised process that satisfies the regulatory requirements.

Technical controls

EDR/XDR, access control, encryption, network segmentation — we deploy what your situation actually calls for. Not a bit of everything, but targeted measures.

Incident management procedures

Procedures for detecting and responding to cyber incidents and for notifying the National Cyber Security Centre (NKSC), so you know what to do when something happens.

Supply chain security

Third-party risk management policies and assessment criteria. NIS2 requires you to assess not only your own security but that of your partners.

Training for management and staff

NIS2 requires management to be directly accountable and competent in cybersecurity. More about training →

Worth knowing about NIS2

👔

Management accountability

Directors must be directly accountable and competent in cybersecurity — this is personal liability

Reporting deadlines

Article 23(4) of NIS2 sets three stages: an early warning within 24 hours, a detailed notification within 72 hours and a final report within one month. Each of them needs procedures prepared in advance.

💷

Penalties

Essential entities: up to EUR 10 million or 2% of annual worldwide turnover. Important entities: up to EUR 7 million or 1.4%. The Lithuanian Law on Cyber Security also provides for personal liability of directors and possible disqualification.

Key dates in Lithuania

📝 17 April 2025

Entities are added to the NKSC register of cyber security entities. The NKSC informs them.

⚡ 17 April 2026

The organisational requirements become mandatory: risk management, incident procedures, management accountability.

🔧 17 April 2027

The technical requirements and the YSII/VII requirements become mandatory. From 2027, periodic NKSC audits every three years.

ISO 27001

ISO 27001 is the international information security management standard that helps an organisation manage its information security risks systematically. The certificate is increasingly expected when bidding for public contracts, working with international partners or demonstrating NIS2 compliance.

Building the ISMS

Documenting information security policies, procedures and controls in line with ISO 27001:2022.

Preparing for certification

Internal audit, identifying and closing non-conformities. We get your organisation ready for the certification audit.

Ongoing support

After certification we help maintain the system, run periodic reviews and prepare for surveillance audits.

Frequently asked questions about NIS2

What is NIS2 and who does it apply to in Lithuania?

NIS2 (Directive 2022/2555) is the EU cybersecurity directive that sets stricter requirements for a wide range of organisations. In Lithuania it is implemented by the Law on Cyber Security (No. XII-1428, as amended in 2024) and the Description of Cyber Security Requirements (Government Resolution No. 818). It is sometimes referred to locally as TIS2. Requirements differ for essential and important entities, so the first step is to establish whether the organisation falls within scope at all and which category it belongs to.

When do the NIS2 requirements become mandatory?

Lithuania applies three stages. On 17 April 2025 entities are added to the NKSC register of cyber security entities and informed accordingly. By 17 April 2026 the organisational requirements must be met: risk management, incident procedures, management accountability. By 17 April 2027 the technical requirements and the YSII/VII requirements must be met; from 2027 the NKSC carries out periodic audits every three years.

What penalties apply for failing to meet NIS2 requirements?

For essential entities, up to EUR 10 million or 2 % of annual worldwide turnover, whichever is higher. For important entities, up to EUR 7 million or 1.4 %. The Lithuanian Law on Cyber Security additionally provides for personal liability of directors and the possibility of disqualifying them.

How quickly must a cyber incident be reported?

Article 23(4) of NIS2 sets out three stages: an early warning within 24 hours, a detailed notification within 72 hours and a final report within one month. Reports go to the National Cyber Security Centre (NKSC). All three deadlines need procedures prepared in advance — you will not write them within 24 hours.

Is the managing director personally accountable for NIS2 compliance?

Yes. NIS2 requires management to be directly accountable and competent in cybersecurity — this is personal, not only organisational, responsibility. The Lithuanian Law on Cyber Security provides for personal liability of directors and the possibility of disqualification. That is why NIS2 training is aimed not only at IT staff but at leadership.

How does NIS2 differ from ISO 27001?

NIS2 is a binding legal requirement with penalties and supervision by the NKSC. ISO 27001 is a voluntary international information security management standard whose certificate is increasingly expected in public procurement and when working with international partners. They do not conflict: an information security management system built to ISO 27001 covers a large part of the organisational requirements of NIS2.

What exactly does NECT do when preparing for NIS2?

Scope assessment, gap analysis, risk assessment, deployment of technical controls (EDR/XDR, access control, encryption, network segmentation), incident management and NKSC notification procedures, supply chain security policies, and training for management and staff. NECT does not only produce documents — it deploys the technical controls and the processes that operate day to day, not just during an audit.

Not sure whether NIS2 applies to your organisation? We will help you find out.

Get in touch about NIS2 →