NIS2 in practice: where to start
The NIS2 directive widened the circle of companies that must manage cybersecurity systematically. What it means for management and which seven steps make sense first.

NIS2 is the European directive on cybersecurity (EU 2022/2555). In Croatia it was transposed by the Cybersecurity Act. Compared with the previous rules it covers considerably more sectors and companies, and it places responsibility for implementation explicitly on management.
This text is a practical overview, not legal advice. Whether you are in scope and in which category should be checked with the competent authority or a legal adviser.
What changes for management
- Security is no longer only an IT topic. Management approves the measures and is accountable for their implementation.
- Significant incidents must be reported within short deadlines: an early warning within 24 hours and a fuller notification within 72 hours of becoming aware.
- Obligations extend to suppliers. Your security also depends on the companies that have access to your systems.
- Non-compliance carries high fines, linked to total annual turnover.
Seven steps to begin
- Establish whether you are in scope. It depends on your sector and company size. Everything else follows from that.
- List what you have. Systems, applications, data and who has access. You cannot protect what you do not know exists.
- Assess the risks. What would happen if a key system stopped for three days or data leaked? Start with what would hurt most.
- Introduce basic measures. Multi-factor sign-in, regular security updates, tested backups and access based on real need stop a large share of common attacks.
- Write an incident plan. Who decides, who calls whom, how systems are isolated and restored. A plan that exists only in someone's head is worthless when that person is away.
- Review your suppliers. Who has access to your systems and data, and what the contracts say about security.
- Document. Compliance is demonstrated through records: decisions, assessments, implemented measures and training.
A common mistake
The most common mistake is to start with documentation rather than the actual state. Policies and rulebooks without implemented measures do not protect systems and do not pass a serious review. A better order: first establish where you are vulnerable, then close the biggest gaps, and only then describe it properly.
If you do not know where to start, an assessment and compliance plan gives you a list of priorities to work with.




