ITH logo 1 e1741681818351

Are you an ISP? You are subject to NIS2 as a critical entity.

Internet service providers are listed in the NIS2 Directive as critical entities. Implementing NIS2 is not an option for operators—it is a legal obligation.ITH provides practical technical support and guides your company through the entire compliance process.

The ITH Security Operations Center (SOC) is a fully managed security operations center that provides continuous monitoring of infrastructure, threat detection, and real-time response to security incidents—all without the need to invest in building your own team.

ith-nis2-dla-isp-img

NIS2 Price List for ISPs

(promotional offer valid through the end of July)

Flexible Plan

Freedom and growth without financial risk

Implementation: 10,000 PLN 25,000 PLN
6,500 PLN / month
3,500 PLN/month
+

Support from a dedicated SOC engineer may be available

350 PLN/h
  • full implementation of the system
  • Comprehensive, dedicated service
  • training for management and employees
  • Reporting in accordance with the NIS2 Directive (optional)
  • an open-ended contract following a free trial period
  • Guaranteed system stability and updates
  • 24/7/365 SOC monitoring

Strategic Plan

(with a 60-month contract)

For market leaders who rely on
to maximize their ROI

Implementation: 5,000 PLN 25,000 PLN
5,000 PLN per month
2,500 PLN/month
+

Support from a dedicated SOC engineer may be available

350 PLN/h
  • 0 zł for the first 3 months!
  • full implementation of the system
  • A dedicated Account Manager for 5 years
  • training for management and employees
  • Reporting in accordance with the NIS2 Directive (optional)
  • A fixed price guarantee for 60 months (inflation protection)
  • savings of as much as 33,000 zł over the entire term of the contract
  • 24/7/365 SOC monitoring

Without implementing NIS2, you risk:

  • Fines of up to €10 million or 2% of global annual turnover. The higher amount applies.
  • Personal liability of management, including a prohibition on the CEO and CTO from holding executive positions.
  • Mandatory audits by supervisory authorities—UODO, CSIRT, and UOKIK—at any time during operations.
  • Loss of public procurement and B2B contracts. Institutional clients require their suppliers to be compliant.
  • An increased likelihood of incidents occurring without appropriate risk management procedures.
  • A permanent loss of reputation and the trust of business partners following the first serious security incident.

Once NIS2 is implemented, you’ll benefit from:

  • Full compliance with EU regulations and the KSC Act. Preparedness for an audit at any time during business operations.
  • A competitive edge in tenders and public procurement. NIS2 is becoming a requirement for supplier qualification.
  • Effective protection of network infrastructure and information systems against digital threats.
  • Business continuity management with documented BCP/DRP plans that are tested regularly.
  • Compliance monitoring by ITH experts. Your team focuses on services; we focus on security.
  • The management and employees have been trained in accordance with the requirements of regulatory authorities applicable throughout the European Union.

NIS2 applies to you if you provide at least one of these services

NIS2 covers a wide range of digital service providers and telecommunications operators. Check which of the categories listed below apply to your business.

ith-1-w-circle-icon

Public Communication Networks

Do you build and operate cable, radio, or fiber-optic infrastructure? The mere fact that you own a public communications network qualifies you as a key...

Read more
ith-2-w-circle-icon

Internet access

Do you provide broadband Internet access services to residential or business customers? This is the basis for ISP classification under NIS2. The law leaves no...

Read more
ith-3-w-circle-icon

DNS Services

Do you manage a DNS system for your own customers? The DNS infrastructure is listed in the NIS2 Directive as a critical component. Its failure...

Read more
ith-4-w-circle-icon

Hosting and the Cloud

Do you offer virtual servers, dedicated servers, or managed cloud environments? Even if hosting is just one segment of your business, it is classified separately...

Read more
ith-5-w-circle-icon

CDN and Internet Exchange (IXP)

Do you manage a content distribution network or an internet exchange point? NIS2 treats these services as critical infrastructure. Their unavailability has a cascading effect...

Read more
ith-6-w-circle-icon

VoIP and Voice Transmission

Do you provide IP-based voice services to business customers, call centers, or as part of a subscriber package? Over-IP voice services are subject to the...

Read more

ISPs are the digital backbone of a properly functioning economy

An ISP infrastructure failure is not just a problem for a single company; it is a real threat to public safety, the functioning of the economy, and the proper functioning of public administration. Therefore, under the directive, operators of essential services have been given the highest priority in terms of cybersecurity. Member States are required to enforce the NIS2 requirements on critical entities with particular rigor. The lack of a systematic approach to cyber risk management puts not only the operator at risk, but also your customers and the country’s entire digital infrastructure.

What, specifically, must an ISP implement?

Formal security policies, risk analysis of network infrastructure and IT systems, and a cyber risk register available to the supervisory authority. Risk management must be an ongoing process, not a one-time event.

Incident response procedures with required deadlines: initial incident reporting to the CSIRT within 24 hours, detailed report within 72 hours. Without a 24/7 SOC, meeting these deadlines is operationally impossible.

A business continuity plan covering scenarios involving ISP infrastructure failures, with a disaster recovery plan that is tested regularly. Crisis management must be documented and practiced, not just put on paper.

Network security architecture, including segmentation, firewalls, traffic monitoring, DDoS protection, and intrusion detection and prevention systems (IDS/IPS). The security of the information systems used to manage the infrastructure must be documented.

The policy for controlling access to network and infrastructure management systems is implemented using MFA, the principle of least privilege, and full logging. All administrative access must be audited for a minimum of 12 months.

Verification and documentation of security standards for business partners and subcontractors: hardware and software vendors, and colocation providers. DNS service providers and external partners require a formal risk assessment.

Regular cybersecurity training for employees and training for management on the responsibilities under NIS2. Employee awareness is essential for an effective system and is a formal requirement of the directive.

Policies for encrypting data in transit and at rest within the ISP's infrastructure. Information security management covers customer data, log data, network device configurations, and billing data.

Regular security scanning of IT systems, patch management for network devices, and documentation of vulnerabilities. Potential threats must be identified before they become actual threats to the network.

Everything NIS2 Requires, All in One Place

ith-1-w-circle-icon

Security Audit

Comprehensive audit of an ISP’s network infrastructure in accordance with NIS2 and KSC. Report with priorities for the management board—compliance assessment ready for review by regulatory authorities.

Learn more
ith-2-w-circle-icon

Network Vulnerability Scanning

Regular CVE scans of network devices, management systems, and ISP infrastructure. Documentation of the results for the supervisory authority in accordance with the NIS2 standard.

Learn more
ith-3-w-circle-icon

Managed Firewall for ISPs

Perimeter protection and network segmentation for the operator, managed by ITH engineers. Network security that includes all documentation required by NIS2 as standard.

Learn more
ith-4-w-circle-icon

Anti-DDoS Protection

ISP infrastructure is a prime target for DDoS attacks. NIS2 requires measures to ensure business continuity—DDoS protection is the technical foundation of compliance.

Learn more
ith-5-w-circle-icon

SOC 24/7 – Monitoring and Response

A security center that monitors the ISP's infrastructure 24/7. Automated incident management procedures with reporting to the CSIRT.

Learn more
ith-6-w-circle-icon

Backup and Disaster Recovery

Automatic, tested backups. A recovery plan compliant with and the requirements of the NIS2 Directive. Encryption and redundancy included as standard.

Learn more

They trusted us

ITH
ITH
ITH
ITH
ITH

Let's talk about your company's needs

Check out what else we have for you!

Write to us

Support
Maintenance

ITH NOC
Management Center
Infrastructure ITH
Open all week, 24 hours a day

Solutions
for you

ITH sales team
Open Monday through Friday from 9:00 a.m. to 8:00 p.m.

    Expand This offer does not constitute an offer within the meaning of the Civil Code. This offer is intended solely for business customers. All prices listed are net prices. * Pursuant to Article 23 of the Act of August 23, 1997, on the Protection of Personal Data (Journal of Laws of 2016, No. 922 of June 28, 2016, consolidated text), I hereby consent to the processing of my personal data provided in the form above (i.e., Tax Identification Number (NIP), phone number, email address) by ITH Sp. z o.o., with its registered office in Warsaw, ul. Nowogrodzka 31, 00-511 Warsaw, registered in the Register of Entrepreneurs of the National Court Register under KRS number 0000469801, Tax ID (NIP): 7010389026, REGON: 146777630, for the purpose of presenting and fulfilling a commercial offer. I have been informed of my right to access the data I have provided, to modify it, and to object to its further processing. The controller of personal data is ITH Sp. z o.o., with its registered office in Warsaw, at ul. Nowogrodzka 31, 00-511 Warsaw, registered in the Register of Entrepreneurs of the National Court Register under KRS number 0000469801, NIP: 7010389026, REGON: 146777630.
    _DSC6603

    FAQ

    Yes—the NIS2 Directive (EU 2022/2555) explicitly classifies providers of public electronic communications networks and services as critical entities in the digital infrastructure sector. If you provide internet access, voice services, or data transmission to external customers and employ 50 or more employees or have a turnover of 10 million euros or more—you are a critical entity without exception. Smaller ISPs may be designated as such by a decision of the national regulatory authority if they provide critical services. Contact us—we’ll conduct a free assessment.

    Key entities (which include ISPs) are subject to a stricter supervisory regime than important entities. The differences are significant: higher financial penalty thresholds (€10 million vs. €7 million), active and proactive oversight by authorities (not merely reactive after an incident), and an obligation to register and report regularly. For key entities, supervisory authorities may conduct unannounced inspections, require external audits, and issue orders to immediately cease operations. For important entities, supervision is reactive—it occurs primarily after an incident.

    Business continuity management at an ISP is a formal, documented system that ensures the operator is able to maintain or quickly restore services following a failure or attack. NIS2 specifically requires: a business continuity plan (BCP) describing procedures for maintaining services under various failure scenarios, a disaster recovery plan (DRP) with measurable RTO and RPO objectives, regular testing of both plans (at least once a year), and documentation of the test results. ITH develops and tests both plans as part of the NIS2 implementation for ISPs.

    NIS2 imposes a three-stage obligation on ISPs, as key entities, to report serious incidents: (1) an early warning within 24 hours of detection—basic information about the nature of the incident, (2) a full incident report within 72 hours—a detailed assessment, scope, and potential impacts, (3) a final report within 30 days—a description of the corrective actions taken and lessons learned. CSIRT Polska is the primary body responsible for receiving reports. Our 24/7 SOC automates this entire process—from detection and classification to submitting the required report on behalf of your ISP.

    Management liability is one of the most significant elements of NIS2 and is very much a reality. The directive requires Member States’ authorities to implement mechanisms for the personal liability of individuals holding management positions. In Poland, this means that penalties of up to 300% of monthly salary may be imposed, and in extreme cases, a ban on holding management positions. This liability is of a supervisory nature—the board of directors is responsible for implementing and maintaining the security system, even if it does not participate in day-to-day technical operations. Therefore, training for management is a mandatory component of our implementation.

    Yes—ITH is leading the NIS2 implementation as an external team of experts, minimizing the involvement of the internal IT department. We take on the entire administrative, documentation, and legal burden. This includes: auditing, developing policies and procedures, training, technical implementation of security controls, and continuous 24/7 SOC monitoring. For ISPs without a dedicated security team, this is the most effective and fastest implementation model.