Preskočiť na obsah

Security · 08/04/2026 · 9 min read

NIS2 for mid-sized companies: what your software must do before the inspection comes

NIS2 extended the scope of regulated entities to thousands of Slovak companies — food production, logistics, waste, engineering from 50 employees up. Fines reach €10 million or 2 % of turnover. And auditors ask about your software too.

What the law expects from your software

Access management: an individual account per user, role-based permissions, logs of who changed what. Multi-factor authentication for administrators. Encryption in transit and at rest. Backups with tested restore — not just “we back up” but “we can be back in 4 hours”. And incident reporting within 24 hours, which is impossible without monitoring.

Where companies fail most often

On old internal systems: a shared “warehouse123” password, no logs, an unencrypted database on a server under the stairs. The paradox is that NIS2-driven modernisation usually pays for itself — the same changes the law requires also cut outages and error rates.

Who is liable — and why it's the management

NIS2 puts responsibility on the statutory body: management is personally liable for non-compliance, not “the IT guy”. The director must approve measures, prove training and know where the company stands — ignorance is no defence. That is why cybersecurity moves from the IT budget onto the board's agenda. An auditor is not looking for perfection, but for proof that management runs it and has a plan.

A timeline you shouldn't underestimate

Fixing software is not a week's work: introducing roles, logs, MFA and a tested restore takes months if done properly. Companies that wait for the first inspection end up doing everything at once, under pressure and at a premium. Whoever starts with a gap analysis today spreads both the cost and the risk — and has the documentation ready before anyone asks.

The sensible route: a gap analysis of your software against NIS2 requirements (part of our Audit 48), prioritisation by risk and a fixed remediation plan. Inspectors ask for documentation — have it before they ring.

Facing exactly this? Let's talk numbers.

An audit of your current solution within 48 hours — specific figures, no phrases.

← All articles