NIS2 compliance: assessment, measures and evidence
Since 2026, the authorities have strictly applied the NIS2 requirements, and the accommodation period has ended.

NIS2 It is not solved by a standard document or a single product. Compliance requires governance, responsibilities, technical controls and the ability to demonstrate that they work.
GreenSoft supports organizations in assessing applicability, analyzing gaps and implementing technical and operational measures. The final legal framework must be confirmed by the organization together with legal specialists, based on the activity, size and role in the service chain.
The plan can cover risk management, incidents, continuity, supply chain, vulnerabilities, cryptography, access control, inventory and training. GreenSoft tracks verifiable results: control owners, deadlines, configurations, tests and records.
What does the service include?
- Preliminary analysis of applicability and scope
- Gap assessment against relevant requirements
- Risk register and treatment plan
- Policies, procedures and responsibilities
- Technical implementation, testing and evidence organization
Why GreenSoft
ISO/IEC 27001, IT outsourcing, networking and technical infrastructure competencies allow policies to be correlated with the systems that need to be actually configured and managed.
How the project is progressing
- Clarification of scope, services and assets
- Assessing differences and prioritizing risks
- Implementation of measures and documents
- Testing, reporting and improvement plan
For what types of goals
- Entities that may fall under the NIS2 framework
- suppliers in their supply chains and organizations that voluntarily adopt a more mature level of security
Request a priority- and evidence-driven NIS2 assessment to translate requirements into a realistic implementation schedule.
Useful resources
Frequently asked questions
What is the NIS2 directive and what types of companies in Romania fall under its mandatory scope?
NIS2 is the EU directive that extends cybersecurity requirements to a large number of organizations in essential and important sectors: energy, transport, health, water, digital infrastructure, manufacturing, services and administration. It covers companies of a certain size in these areas, plus their critical suppliers. We assess together whether and in which category you fall.
What are the financial sanctions provided for non-compliance with the requirements of the NIS2 directive?
NIS2 provides for significant fines, in the order of millions of euros or a percentage of turnover, plus possible management liability. Beyond the fine, an incident at a non-compliant company entails operational and reputational losses. Proactive compliance is much cheaper than the consequences.
What are the basic technical measures a company must implement for NIS2?
Among the basic requirements: risk analysis, access control, backup and continuity plan, update and vulnerability management, network security, encryption, multi-factor authentication and a clear incident reporting process. GreenSoft helps you implement these measures technically and procedurally. We start from an assessment of the current situation.
How does GreenSoft's ISO 27001 certification influence your NIS2 compliance process?
ISO 27001 covers a large part of the NIS2 requirements, so by working with an already certified partner you significantly shorten the path to compliance and reduce the risk in the supply chain. We apply internally tested practices to you. Basically, you benefit from an already mature framework, not improvisations.
What does cybersecurity incident management mean under the new regulations?
It means being able to detect, classify, contain and report an incident within the strict deadlines imposed by NIS2 (rapid initial notification, followed by detailed reporting). This requires monitoring, written procedures and clear roles. We help you build this process and test it, so you don't get caught off guard.
Can GreenSoft guarantee NIS2 compliance?
No. Compliance depends on the organization, governance, domain, implementation and authority assessment. GreenSoft can provide analysis and documented technical support.
Where does the project start?
With the domain: services, entities, assets, suppliers and responsibilities. Only then are the differences and measures evaluated.
Shall we discuss your project?
Free initial technical consultation and quote within 3–5 business days.









































