Compliance and regulation

NIS2

Adaptation to the NIS2 Directive for essential and important entities.

What it involves

What we do

NIS2 widens the sectors in scope and tightens the measures, incident reporting and management accountability. We determine whether your organisation is in scope, which measures apply and how to demonstrate them.

What's included

  • Applicability analysis and entity classification
  • Gap assessment against the Article 21 measures
  • Adaptation plan and management-level governance
  • Incident notification procedure (24h/72h/1 month)
  • Supply chain security
  • Mandatory training for management bodies

Who it's for

  • Essential and important entities across the 18 NIS2 sectors
  • Critical suppliers to those entities
  • Groups with subsidiaries in several Member States

Deliverables

  • Applicability report
  • NIS2 gap assessment
  • Adaptation plan
  • Notification procedure

Reference frameworks and standards

NIS2ISO 27001ENSNIST CSF

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does NIS2 fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.