Aegis continuously gathers the evidence required by the NIS2 Directive (EU) 2022/2555 (e.g. in Croatia transposed via the national Cybersecurity Act) and helps you meet incident-notification obligations within the 24-hour, 72-hour and one-month deadlines.
NIS2 (Directive (EU) 2022/2555) is transposed into national law across the EU (e.g. in Croatia via the national Cybersecurity Act). It requires essential and important entities to have risk-management measures and — just as importantly — proof that those measures are genuinely in force.
Protection measures for networks and information systems appropriate to the risk, documented and monitored.
The procedure and deadlines for reporting significant incidents to the competent CSIRT.
An irrefutable record of events and actions as the foundation for proving compliance.
Continuous tracking of vulnerabilities and prioritization by real risk.
Detection, response and recovery that reduce downtime during an incident.
Visibility and controls that help monitor supply-chain risk.
For a significant incident, the directive prescribes strict deadlines for notifying the competent CSIRT. Aegis helps you meet those deadlines because the evidence already exists in the system.
Within 24 hours of becoming aware of a significant incident, an early warning is submitted to the competent CSIRT.
Within 72 hours, an incident notification is submitted with an initial assessment of severity and impact.
No later than one month after reporting, a final report is submitted with a detailed description of the incident and the measures taken.
Aggregated, anonymized and illustratively rounded production metrics.
NIS2 is a European Union directive (EU Directive 2022/2555) that raises the level of cybersecurity across a broad range of entities. It is transposed into national law by the Croatian Cybersecurity Act, with implementing details set out the Croatian Cybersecurity Regulation.
The legislation divides obligated organizations into essential and important entities, depending on sector and size. The obligations include risk management, incident reporting, supplier oversight and management accountability.
The competent authority is NCSC-HR (the National Cyber Security Centre), which also acts as the CSIRT and single point of contact. A national CERT is competent for some entities.
Through the Coverage Score and evidence pack, we show where you stand today against the NIS2 Directive (EU 2022/2555) and which evidence you already have and which still needs completing.