Solution · By goal

NIS2 readiness

It usually starts with a questionnaire. A major customer asks how you handle security incidents, who can reach your servers and whether your directors have signed off on any of it. Sometimes the push comes from inside, after someone reads about the Austrian NIS Act. The NIS2 Directive does not ask essential and important entities for a certificate. It asks for risk management that can be traced, reporting lines that work under pressure and a management body that owns the outcome. We sort out the technical side and write the paperwork that goes with it, entirely by remote access. Whether your organisation is legally in scope is a question for your lawyer; we give them solid facts to work from.

2
categories, essential and important entities, each with its own level of supervision
24 h
to send an early warning after a significant incident under the NIS2 Directive
72 h
to file the notification itself, with a first assessment of what happened
100 %
of the review, roll-out and drills handled remotely and over video calls

What we put in place with you

Most of NIS2 is organisation and a smaller share is technology. The two have to fit together. A policy nobody follows is as useless in an inspection as a firewall nobody has documented.

Send an enquiry

Scope and starting point

We gather what your legal adviser needs to classify you: sector and activities, headcount, turnover, group structure and critical services. Alongside that we record systems, accounts, interfaces and suppliers. You end up with a gap list measured against the baseline measures in the Directive, ranked by effort and impact.

Risk management that means something

Risk analysis, security policies, an access model, vulnerability handling, encryption, backup and continuity planning. Each document short enough that people read it and specific enough that an auditor can test it. ISO 27001, BSI IT-Grundschutz and the Austrian Information Security Handbook serve as reference points, without a 300-page binder landing on your desk.

Reporting lines that survive a real incident

Who spots an incident, who judges how serious it is, who signs the report and where does it go? We assign roles and deputies, prepare templates for the early warning, the notification and the final report, and confirm how to reach CERT.at and the competent authority. We also line this up with the GDPR breach notice to the DSB whenever personal data is involved.

Supply chain security

Your payroll provider, the machine builder's maintenance login, whoever hosts your web shop: each is a way in. We draw up a list of critical suppliers, a short security questionnaire and contract clauses covering incident notice and access rights. If you are a supplier yourself, we help you answer the questionnaires your own customers send.

Technical groundwork

Multi-factor sign-in on every account, separate admin identities, patching with evidence, EDR on laptops and servers, central logging and backups that ransomware cannot touch. In Microsoft 365 we build this with Entra ID, Intune and Defender; elsewhere we use the tools you already hold licences for.

Directors and staff training

The management body has to approve the measures, keep an eye on how they are carried out and take part in training. Directors get a compact video session built around the decisions that genuinely sit with them. Everyone else gets short modules on phishing, passwords and what to do when something looks wrong.

How the work runs

Not everything has to happen at once. A company with multi-factor sign-in and a clean reporting chain is far better placed than one with a flawless policy folder and admin logins left wide open.

01

Review

Interviews over video, configuration read-outs through remote access and a look through the documents you already have. The result is a gap list and a rough estimate of effort.

02

Roadmap

Management decides on priorities and budget. We write down what starts now, what follows next quarter and which risks are knowingly accepted.

03

Roll-out

Technical measures go in remotely, with changes to live systems made in maintenance windows agreed with you in advance. Policies and templates are drafted in parallel and agreed with you.

04

Rehearse and evidence

A tabletop exercise walking through an incident, a restore test and a phishing simulation. Findings feed an annual review cycle so the documents never go stale.

Even firms outside NIS2 end up feeling it. Picture a joinery in the Mühlviertel with 30 staff that fits out interiors for a large hospital operator. The joinery is probably not an entity under the law, but the hospital operator is, and it has to secure its supply chain. So a questionnaire arrives asking about multi-factor sign-in, backups and reporting deadlines. A supplier that can already show a brief security policy and a tested backup is in a much stronger position.

Frequently asked questions

Two questions matter most. Does your activity fall within one of the sectors the Directive lists, such as energy, transport, health, digital infrastructure, waste, food or certain kinds of manufacturing? And does your company reach the size thresholds? Roughly speaking, medium-sized and large firms in those sectors are usually covered and small ones only in special cases. The legal assessment under the NISG is up to your legal adviser. We supply the facts about activities, systems and group structure.

The duties around risk management and incident reporting are largely identical for both. The difference lies mainly in supervision. The competent authority can inspect essential entities proactively, whereas important entities tend to be checked after the fact, once there is a sign that something is wrong. For practical preparation, the label changes very little.

The Directive does not require any particular certificate. An information security management system built on ISO 27001 does cover much of what is asked, which makes it a sensible framework. We follow its principles and can help you prepare if you decide to certify. The audit itself is carried out by an accredited certification body, not by Apply.

The Directive puts explicit duties on the management body: approving the measures, overseeing them and answering for breaches. How Austrian law spells this out in detail is something your lawyer should confirm. From our side, what counts is that resolutions, training sessions and reviews are recorded, so directors can show they acted with due care.

Not at all. We can take on the whole programme, or just the review, the documentation and the drills while your current provider keeps running day-to-day operations. In that case they become part of your supply chain, and we go through access, logging and response times with them. Anything that needs hands on site is done by your team or that provider; we work remotely only.

Where does your company stand on NIS2?

Tell us briefly about your sector, size and IT set-up, and whether customers have already sent security questionnaires. We will reply within one working day with a proposal for the review.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.