NIS2 · compliance and evidence

NIS2 compliance —
from monitoring to evidence

Aegis continuously gathers the evidence required by the NIS2 Directive (EU) 2022/2555 (e.g. in Croatia transposed via the national Cybersecurity Act) and helps you meet incident-notification obligations within the 24-hour, 72-hour and one-month deadlines.

EU NIS2 Directive (2022/2555) Deadlines 24h / 72h / 1 month Audit trail ready for review
What NIS2 requires

Obligations you must prove, not just meet

NIS2 (Directive (EU) 2022/2555) is transposed into national law across the EU (e.g. in Croatia via the national Cybersecurity Act). It requires essential and important entities to have risk-management measures and — just as importantly — proof that those measures are genuinely in force.

Risk management

Protection measures for networks and information systems appropriate to the risk, documented and monitored.

Incident reporting

The procedure and deadlines for reporting significant incidents to the competent CSIRT.

Audit trail

An irrefutable record of events and actions as the foundation for proving compliance.

Vulnerability management

Continuous tracking of vulnerabilities and prioritization by real risk.

Continuity

Detection, response and recovery that reduce downtime during an incident.

Supplier security

Visibility and controls that help monitor supply-chain risk.

INCIDENT NOTIFICATION DEADLINES

24 hours, 72 hours, one month

For a significant incident, the directive prescribes strict deadlines for notifying the competent CSIRT. Aegis helps you meet those deadlines because the evidence already exists in the system.

24 h
Early warning signal

Within 24 hours of becoming aware of a significant incident, an early warning is submitted to the competent CSIRT.

72 h
Incident notification

Within 72 hours, an incident notification is submitted with an initial assessment of severity and impact.

1 mo
Final report

No later than one month after reporting, a final report is submitted with a detailed description of the incident and the measures taken.

Why this is hard without tools: within 24 hours it's hard to reconstruct what happened if data wasn't collected in advance. Aegis continuously records events and an audit trail, so the report is a matter of export, not an overnight investigation.
How Aegis helps

The evidence collects itself while the platform runs

NIS2 Evidence PackA readiness pack with control evidence, measures and compliance status — audit-ready, with no manual assembly.
Continuous monitoring (SIEM)Ongoing monitoring and logging of security events proves that the organization watches over its system.
Full audit trailEvery action in the platform is logged and searchable — an irrefutable trail for audits and incident reconstruction.
ISO 27001 and GDPR moduleMapped controls and records that guide you through preparation and GDPR obligations.
Coverage Score as proof of measuresA measurable score of 0–100 shows your posture over time and concrete steps for improvement.
Built-in testingPenetration testing i Vulnerability assessment provide proof that the measures have actually been tested.
1,1M+
audit events recorded
13.000+
detection rules
19.000+
cases processed
380M+
logs processed

Aggregated, anonymized and illustratively rounded production metrics.

Basics

What NIS2 is and who is in scope

NIS2 is a European Union directive (EU Directive 2022/2555) that raises the level of cybersecurity across a broad range of entities. It is transposed into national law by the Croatian Cybersecurity Act, with implementing details set out the Croatian Cybersecurity Regulation.

Essential and important entities

The legislation divides obligated organizations into essential and important entities, depending on sector and size. The obligations include risk management, incident reporting, supplier oversight and management accountability.

Competent authorities in Croatia

The competent authority is NCSC-HR (the National Cyber Security Centre), which also acts as the CSIRT and single point of contact. A national CERT is competent for some entities.

Note: Aegis provides tools, controls and records for compliance, but does not issue certificates or give legal advice. Certification (e.g. ISO 27001) is carried out by an accredited certification body — Aegis currently holds no certificates (ISO 27001 in preparation). For interpreting your obligations, consult your legal team or the competent authority.
Frequently asked questions

NIS2 — frequently asked questions

What are the incident reporting deadlines under NIS2? +
For a significant incident: an early warning within 24 hours, an incident notification within 72 hours and a final report no later than one month after notification, to the competent national CSIRT.
Which regulations govern NIS2 in your country? +
The EU NIS2 Directive (2022/2555) and its national transposition, which set the cybersecurity obligations and implementing details for essential and important entities.
Does Aegis make us automatically compliant? +
No tool by itself guarantees compliance. Aegis provides measures, controls and evidence (Evidence Pack, audit trail, continuous monitoring) that greatly ease and speed up the path to compliance, but responsibility and interpretation of obligations remain with the organization.
Do you have ISO 27001 certification? +
Aegis currently holds no certificates; ISO 27001 is in preparation. The platform includes an ISO/GDPR module with mapped controls that supports your own preparation for certification.
RELATED

Keep exploring the platform

Check your NIS2 readiness

Through the Coverage Score and evidence pack, we show where you stand today against the NIS2 Directive (EU 2022/2555) and which evidence you already have and which still needs completing.

Odgovaramo isti radni dan · info@aegis.hr