Not every company is in scope, and obligations scale with your size and sector. Before anything else, check where your country stands and whether NIS2 applies to you. It takes minutes, not a project — and if you're out of scope, you're done.
It's a checklist, not an ocean. At its core, NIS2 asks for a handful of things:
Risk-management measures — a baseline of cybersecurity practices: policies, access control, backups, encryption, supplier security, training.
Incident reporting — notify your authority on a clear clock: early warning within 24h, full notification within 72h, final report within a month.
Governance — your management approves and oversees the measures. It's a board topic, not only an IT one.
Registration — register your entity with your national authority (the tracker shows yours).
Supply-chain security — account for the security of your key suppliers and service providers.
That's the shape of it — daunting as a blank page, very manageable with a plan.
Reglyze turns NIS2 from a research project into a guided workflow — using AI to make your company compliant easily and quickly.
Most teams go from zero to a concrete compliance work plan in about 30 minutes.