EU NIS 2 · For US companies

You are not an EU company. NIS 2 can still reach you through your EU footprint.

The EU's NIS 2 Directive binds essential and important entities to register with a national authority, implement cybersecurity measures and report incidents against fixed deadlines. For a US business it arrives through an EU subsidiary, services delivered into the EU, or — most often — an EU customer passing the obligation down the supply chain. We handle the EU side so your team does not have to learn it.

Directive (EU) 2022/2555 · transposed by each EU member state

No strings attached Reply within 15 minutes NDA on request

€10m
maximum fine for essential entities — or 2% of global annual turnover, whichever is higher
€7m
maximum for important entities — or 1.4% of global annual turnover
27 states
each EU member state has its own authority, registration platform and enforcement practice
The board
of the in-scope entity approves the measures, must undergo training and is personally accountable

Quick check

Does NIS 2 reach your business?

Three questions, thirty seconds. Tap every statement that is true for your company.

This result is indicative and does not constitute legal advice. The official classification is made by the entity itself, on its own responsibility, through the relevant national authority.

Classification is not paperwork. It changes everything that follows.

The difference between "essential" and "important" changes the fine ceiling, the supervisory regime and the consequences for the board of your EU entity. Getting it wrong costs in both directions: penalties for obligations you missed, or money spent on measures you never needed.

Essential entities

Fine
up to €10m or 2% of global turnover
Supervision
proactive, including planned inspections
Management
may be temporarily suspended from duties

Important entities

Fine
up to €7m or 1.4% of global turnover
Supervision
ex-post — on complaint, incident or evidence of non-compliance
Management
accountable for approving and overseeing the measures

How it reaches you

Three routes from Brussels to a US business

NIS 2 does not regulate American companies as such. It regulates entities operating in the European Union — and then makes those entities answerable for the security of everyone who supplies them.

Through an EU entity

A subsidiary, branch or acquired company operating in a covered sector is an in-scope entity in its own right, with its own registration, reporting duties and board accountability.

Through services delivered into the EU

Certain digital providers — cloud, data centers, managed services, marketplaces, search, social platforms — fall under the directive based on where the service is offered, not where the company is incorporated.

Through your EU customers

The route that catches the most US companies. In-scope entities must manage supply chain security, so the requirement arrives as a contract clause, a questionnaire or an audit right — with the renewal at stake.


The obligations

What the directive asks of the in-scope entity

This is not a list of good practice but a set of obligations with deadlines. Two of them start a clock you cannot stop: registration and incident reporting.

30 days

Register with the authority

Enroll the entity on the national platform of the member state, with contact details and sector.

Stage 2

Risk assessment

Assess security risks and self-assess maturity against the national methodology.

Stage 3

Security measures

Policies, access control and multi-factor authentication, encryption, backup, business continuity and supply chain security.

24h / 72h / 1 month

Incident reporting

Early warning, full notification and final report to the authority, for every significant incident.

Ongoing

Audit and training

Periodic security audits and mandatory management training, with the documentation that evidences both.


How we help

Our NIS 2 services. From EU exposure to demonstrable compliance.

Take the services separately or the whole path, run by one team. The difference from pure consulting: the measures we recommend, we also implement — and then monitor.

EU exposure assessment and registration

We map which of your entities are in scope, in which member state, and prepare the entity file.

  • Sector and size threshold analysis per entity
  • Registration on the national platform
  • Appointment of the security officer

Maturity assessment and gap analysis

We map what you already run under SOC 2 or NIST onto what the directive requires, and price the delta.

  • Risk assessment against the methodology
  • Control mapping from your existing frameworks
  • Remediation plan with effort and budget estimates

Implementing security measures

The controls required by Article 21, actually put into operation — not merely written into procedures.

  • EDR/XDR, next-gen firewall, network segmentation
  • Multi-factor authentication and access control
  • Immutable backup and continuity planning

Security officer as a service

An external security officer for the EU entity, in the same time zone as the authority it reports to.

  • Maintaining compliance and documentation
  • Day-to-day relationship with the authority
  • Periodic reporting to US headquarters

Monitoring and incident response

We detect, contain and prepare the notification file within the legal deadlines.

  • 24/7 SOC monitoring
  • Vulnerability scanning and penetration testing
  • Notification procedures at 24h, 72h and one month

Compliance audit and training

Periodic verification of compliance and the mandatory training for the management body.

  • NIS 2 audit with report and action plan
  • Training for members of the management body
  • Phishing simulations for employees

What delay costs you

Essential entities€10m / 2% The higher of the fixed amount and the percentage of global annual turnover applies — and global means group-wide, not EU-only.
Important entities€7m / 1.4% The same mechanism with lower ceilings, applied to the same category of mid-sized entities.
Managementpersonal liability Members of the management body are accountable for approving and overseeing the measures. For essential entities the authority may temporarily suspend individuals from their duties.
Lost contractsthe usual first hit Long before a regulator notices, an EU customer will. Supply chain clauses are already appearing in renewals — without evidence of compliance you lose the account, not just the audit.

Why iTech Media

You need a partner on the European side of this — one who understands both the directive and the infrastructure it lands on, and who is awake when the authority is.

  • An EU-based team for an EU obligation. We work from Romania, in the same regulatory space and time zone as the authority your entity reports to.
  • Advice and implementation from one supplier. We put the recommended measures into operation ourselves — you are not left holding a report and the job of finding someone to execute it.
  • 17+ years of combined experience in IT infrastructure and security across the US, the UK and Romania.
  • It builds on what you have. SOC 2, ISO 27001 and NIST controls get mapped and reused instead of rebuilt from scratch.

Frequently asked

What US executives ask us most

Not because you are American, but because of where you operate. NIS 2 reaches a US company through three routes: an EU subsidiary or branch in a covered sector, services delivered into the EU that make you subject to the directive, and EU customers who must now hold their suppliers to security requirements. The third route catches the most US companies, and it arrives as a contract clause rather than a regulator's letter.
It is a strong base, not a substitute. Most of the technical controls map across, but NIS 2 adds requirements your US frameworks do not cover: registration with an EU national authority, incident reporting within 24 and 72 hours to that authority, supply chain accountability and mandatory training for the management body. A gap analysis maps what you have onto what the directive asks.
It depends where you start. Scoping and registration take a few days. A gap analysis typically takes two to three weeks, and implementing the measures two to six months depending on how many controls are missing. Compliance is not a project that ends: monitoring, reporting and periodic audits continue.
The management body of the entity in scope. NIS 2 places accountability at board level: management approves the security measures, oversees implementation, must undergo training and can be held liable for non-compliance. For essential entities the authority may also temporarily suspend individuals from management duties.
Yes. Our teams operate across Romania, the UK and the US, so the people handling your EU obligations sit in the same time zone as the authority you report to, while account conversations happen on your schedule.
A thirty-minute conversation. Tell us your EU footprint, entity sizes and what you already have in place; we tell you which entities are in scope, what the directive requires and how long it would take. If nothing you run is in scope, we say that too — cheaper for everyone than a project nobody needed.

Your EU customers will ask before the regulator does. Have the answer ready.

A thirty-minute conversation and a free initial assessment show you which of your entities are in scope, where you stand against the NIS 2 requirements and what reaching compliance would involve.

We reply within 15 minutes. We do not send unsolicited offers.

The information on this page is general and indicative. It does not constitute legal advice and does not replace the legislation in force in any member state or official guidance from a competent authority.