Gabrielius Vinciūnas

Paulius Užkurėlis

The best place to start is the official NIS2 Directive published by the EU. National regulators also provide guidance on how the directive is applied locally, which can help clarify practical expectations, e.g., Cyber Security Act (liet. Kibernetinio saugumo įstatymas), published by Parliament of the Republic of Lithuania.
ISO 27001 is a strong starting point, but it does not automatically mean NIS2 compliance. NIS2 goes further, especially around governance, incident reporting, and management responsibilities, so additional work is usually required.
The timeline depends on organisational size, existing security maturity, and regulatory scope. It can take from 6 months to 2 years. Most organisations work towards NIS2 compliance in stages, starting with a gap analysis and then addressing priorities step by step.