Entity classification
Determine whether your organization qualifies as an Essential or Important Entity under NIS2 based on sector, size, and economic role.
- Essential
- Important
- 18 sectors
Entity classification, gap analysis, and implementation planning for NIS2 obligations — across governance, risk management, supply chain security, and incident reporting.
NIS2 widens the scope of EU cybersecurity regulation to 18 sectors and introduces stricter obligations: documented risk management measures, supply chain security, incident reporting within tight timelines, and personal accountability for management bodies. ShadowCore’s NIS2 service helps organizations confirm whether they qualify as an Essential or Important Entity, identify the controls that need to change, and reach a defensible compliance position.
The engagement starts with scope and entity classification, followed by a structured gap analysis against the directive’s ten risk-management areas. Each gap is paired with a remediation action, an owner, and the evidence the supervisory authority is likely to ask for. Where an ISO 27001 ISMS is already in place, work focuses on the delta between existing controls and NIS2-specific obligations.
NIS2 typically runs alongside other frameworks. See GRC & Compliance for multi-framework coordination, ISO 27001 for a control baseline that satisfies most NIS2 expectations, and Incident Response for the operational capability required by the directive’s reporting obligations.
Determine whether your organization qualifies as an Essential or Important Entity under NIS2 based on sector, size, and economic role.
Assessment of current controls against NIS2 obligations for risk management, incident handling, business continuity, and supply chain security.
Workflows for the 24-hour early warning, 72-hour incident notification, and final report — including evidence trails and decision logs.
Prioritized implementation plan with owners, evidence requirements, timelines, and management-body briefings for personal-liability obligations.
A practical compliance program built for evidence, accountability, and audit readiness.
Comprehensive assessment of your current posture against NIS2 requirements with a prioritized remediation roadmap.
Determine whether your organization qualifies as an Essential or Important Entity under the directive.
Map current controls against NIS2 obligations for incident handling, business continuity, and supply chain security.
Prepare leadership for governance duties, approval workflows, evidence trails, and supervisory expectations.
Build the processes required for 24-hour early warnings, 72-hour notifications, and final incident reporting.
Prioritized implementation plan with owners, evidence requirements, timelines, and audit-ready deliverables.
Determine if your organization falls under NIS2 as an Essential or Important Entity.
Key changes and escalated requirements under the NIS2 directive.
| Aspect | NIS1 | NIS2 |
|---|---|---|
| Scope | OES + DSP (limited sectors) | Essential + Important Entities (18 sectors) |
| Fines | Member state defined | EUR 10M or 2% worldwide turnover (Essential) |
| Management Liability | No personal liability | Personal liability for management bodies |
| Incident Reporting | Undue delay | 24h early warning, 72h full report |
| Supply Chain | Not addressed | Mandatory supply chain risk management |
| Enforcement | Reactive | Proactive audits + on-site inspections |
Parent program coordinating NIS2 with ISO 27001, GDPR, and other applicable frameworks.
An ISMS built on ISO 27001 supplies most of the control evidence NIS2 supervisors expect.
Retainer-backed response capability that supports NIS2 incident handling and reporting obligations.
Free initial consultation. We'll assess your current posture and map a remediation plan.
Contact Us