Not merely a regulatory formality — a chance to make your organisation genuinely more resilient
The NIS2 Directive (2022/2555) sets stricter cybersecurity requirements for a wide range of organisations in Lithuania. It is implemented by the Lithuanian Law on Cyber Security (No. XII-1428, as amended in 2024) and the Description of Cyber Security Requirements (Government Resolution No. 818). In practice it is sometimes called TIS2. This is not only about avoiding fines — it is an opportunity to strengthen your organisation’s resilience to cyber threats in a systematic way.
NECT helps in practical terms — we do not only prepare the documents, we deploy real technical controls, train staff and management, and build processes that work every day, not just during an audit.
We establish whether your organisation falls within the scope of NIS2 (as an essential or an important entity) and which specific obligations apply.
We compare your current security maturity against the NIS2 requirements and identify the gaps. You see clearly where you are and where you need to be.
Systematic identification and assessment of your organisation’s cyber risks. A formalised process that satisfies the regulatory requirements.
EDR/XDR, access control, encryption, network segmentation — we deploy what your situation actually calls for. Not a bit of everything, but targeted measures.
Procedures for detecting and responding to cyber incidents and for notifying the National Cyber Security Centre (NKSC), so you know what to do when something happens.
Third-party risk management policies and assessment criteria. NIS2 requires you to assess not only your own security but that of your partners.
NIS2 requires management to be directly accountable and competent in cybersecurity. More about training →
Directors must be directly accountable and competent in cybersecurity — this is personal liability
Article 23(4) of NIS2 sets three stages: an early warning within 24 hours, a detailed notification within 72 hours and a final report within one month. Each of them needs procedures prepared in advance.
Essential entities: up to EUR 10 million or 2% of annual worldwide turnover. Important entities: up to EUR 7 million or 1.4%. The Lithuanian Law on Cyber Security also provides for personal liability of directors and possible disqualification.
Entities are added to the NKSC register of cyber security entities. The NKSC informs them.
The organisational requirements become mandatory: risk management, incident procedures, management accountability.
The technical requirements and the YSII/VII requirements become mandatory. From 2027, periodic NKSC audits every three years.
ISO 27001 is the international information security management standard that helps an organisation manage its information security risks systematically. The certificate is increasingly expected when bidding for public contracts, working with international partners or demonstrating NIS2 compliance.
Documenting information security policies, procedures and controls in line with ISO 27001:2022.
Internal audit, identifying and closing non-conformities. We get your organisation ready for the certification audit.
After certification we help maintain the system, run periodic reviews and prepare for surveillance audits.
NIS2 (Directive 2022/2555) is the EU cybersecurity directive that sets stricter requirements for a wide range of organisations. In Lithuania it is implemented by the Law on Cyber Security (No. XII-1428, as amended in 2024) and the Description of Cyber Security Requirements (Government Resolution No. 818). It is sometimes referred to locally as TIS2. Requirements differ for essential and important entities, so the first step is to establish whether the organisation falls within scope at all and which category it belongs to.
Lithuania applies three stages. On 17 April 2025 entities are added to the NKSC register of cyber security entities and informed accordingly. By 17 April 2026 the organisational requirements must be met: risk management, incident procedures, management accountability. By 17 April 2027 the technical requirements and the YSII/VII requirements must be met; from 2027 the NKSC carries out periodic audits every three years.
For essential entities, up to EUR 10 million or 2 % of annual worldwide turnover, whichever is higher. For important entities, up to EUR 7 million or 1.4 %. The Lithuanian Law on Cyber Security additionally provides for personal liability of directors and the possibility of disqualifying them.
Article 23(4) of NIS2 sets out three stages: an early warning within 24 hours, a detailed notification within 72 hours and a final report within one month. Reports go to the National Cyber Security Centre (NKSC). All three deadlines need procedures prepared in advance — you will not write them within 24 hours.
Yes. NIS2 requires management to be directly accountable and competent in cybersecurity — this is personal, not only organisational, responsibility. The Lithuanian Law on Cyber Security provides for personal liability of directors and the possibility of disqualification. That is why NIS2 training is aimed not only at IT staff but at leadership.
NIS2 is a binding legal requirement with penalties and supervision by the NKSC. ISO 27001 is a voluntary international information security management standard whose certificate is increasingly expected in public procurement and when working with international partners. They do not conflict: an information security management system built to ISO 27001 covers a large part of the organisational requirements of NIS2.
Scope assessment, gap analysis, risk assessment, deployment of technical controls (EDR/XDR, access control, encryption, network segmentation), incident management and NKSC notification procedures, supply chain security policies, and training for management and staff. NECT does not only produce documents — it deploys the technical controls and the processes that operate day to day, not just during an audit.
Not sure whether NIS2 applies to your organisation? We will help you find out.
Get in touch about NIS2 →