NIS2, Decoded — and Turned Into a Plan

NIS2, Decoded — and Turned Into a Plan

NIS2, Decoded — and Turned Into a Plan

Find out whether NIS2 applies to you, where you stand against the ten required measures, and what to fix first. A documented readiness assessment your management can stand behind.

Find out whether NIS2 applies to you, where you stand against the ten required measures, and what to fix first. A documented readiness assessment your management can stand behind.

Aligned with NIS2 Art. 21 & BSI Guidance

Aligned with NIS2 Art. 21 & BSI Guidance

A steel supply chain receding into darkness with one link glowing blue

NIS2 Readiness

Problem

The Law Landed. The Clarity Didn’t.

The Law Landed. The Clarity Didn’t.

NIS2 is national law, and the obligations sit with management personally — they cannot be delegated to IT or an external provider. Yet most companies still can’t answer the first question: does it even apply to us?

The ones who know they’re in scope face a second problem. Their customers are already asking for proof, and what’s being sold as “NIS2 compliance” is often a certificate that does not exist. There is no NIS2 certification.deployers, not just the companies building models — and the AI literacy duty in Article 4 applies regardless of how low-risk your use case is. Meanwhile vendors are reassuring customers that their product is compliant, which says nothing at all about your own obligations.

Solution

Scope, Gap, Plan

Scope, Gap, Plan

We start with the question everyone skips: are you in scope, and why? You get a documented determination — sector annex, size thresholds, and the supply-chain route that pulls companies in through their customers.prototype protection, data protection — genuinely apply.

From there we assess you against the ten risk-management measures in Article 21 and the incident-reporting duties, then hand you a prioritised roadmap with owners and effort estimates. Everything lands in a GRC workspace, so your evidence stays current instead of aging in a spreadsheet.ISO/IEC 42001.

Agenda

How It Works

How It Works

01

Scope Determination

  • Sector annex check: essential entity, important entity, or out of scope.

  • Size and turnover thresholds — including the exceptions that override them.

  • Supply-chain pull-in: the obligations your customers pass down to you.

  • A written determination with the reasoning, not just a yes or no.

01

Scope Determination

  • Sector annex check: essential entity, important entity, or out of scope.

  • Size and turnover thresholds — including the exceptions that override them.

  • Supply-chain pull-in: the obligations your customers pass down to you.

  • A written determination with the reasoning, not just a yes or no.

02

Gap Assessment

  • All ten risk-management measures under Art. 21, scored against your reality.

  • Incident reporting readiness: the 24-hour, 72-hour and one-month deadlines.

  • Interview-based — no agents installed, no disruption to operations.

  • Evidence gaps flagged separately from control gaps.

02

Gap Assessment

  • All ten risk-management measures under Art. 21, scored against your reality.

  • Incident reporting readiness: the 24-hour, 72-hour and one-month deadlines.

  • Interview-based — no agents installed, no disruption to operations.

  • Evidence gaps flagged separately from control gaps.

03

Remediation Roadmap

  • Prioritised by risk and effort, not by chapter order.

  • Named owners and realistic timelines for each item.

  • Quick wins separated from structural work.

  • Overlap with your GDPR records identified and reused.

03

Remediation Roadmap

  • Prioritised by risk and effort, not by chapter order.

  • Named owners and realistic timelines for each item.

  • Quick wins separated from structural work.

  • Overlap with your GDPR records identified and reused.

04

Management Briefing

  • NIS2 requires management to be trained. We deliver that briefing.

  • Liability, approval duties and reporting obligations, in plain language.

  • Documented attendance — because that documentation is part of the evidence.

  • Documented training records as part of the evidence set.

04

Management Briefing

  • NIS2 requires management to be trained. We deliver that briefing.

  • Liability, approval duties and reporting obligations, in plain language.

  • Documented attendance — because that documentation is part of the evidence.

  • Documented training records as part of the evidence set.

4

Management Briefing

  • NIS2 requires management to be trained. We deliver that briefing.

  • Liability, approval duties and reporting obligations, in plain language.

  • Documented attendance — because that documentation is part of the evidence.

  • Documented training records as part of the evidence set.

Execution

Built for Companies Without a CISO

Built for Companies Without a CISO

This runs as three to four working sessions over roughly three weeks. We work from interviews and documents you already have — nothing is installed on your network.

You receive:

  • Scope determination with documented reasoning.

  • Gap report against Art. 21 and the reporting duties.

  • Remediation roadmap with owners, effort and priority.

  • Management briefing covering liability and duties.

Target Audience

Ideal For:

Ideal For:

  • Newly in-scope entities: companies that crossed a threshold or sit in a covered sector for the first time.

  • Suppliers pulled in from above: you’re not directly regulated, but your customer is — and now you are too.

  • Management boards: who carry the personal liability and want evidence of due care.

  • Companies holding a questionnaire: a customer asked, and you need a defensible answer.

ROI & Business Impact

Why Invest in This?

Personal Liability

NIS2 puts management personally on the hook — and the duty cannot be delegated away. A documented readiness assessment is your evidence of due care.

Faster Sales Cycles

Answer customer security questionnaires in days instead of weeks. The evidence is already collected and mapped.

No Wasted Spend

Fix the five things that actually matter before buying the platform you don’t need.

Pricing

Scoped Around Your Team.

Every engagement is scoped to your team, your industry, and your risk profile. Tell us what you need and we’ll put together a concrete offer.

NIS2 Readiness

Scope determination, gap assessment and remediation roadmap

  • Format: three to four working sessions, remote or on site.

  • Duration: roughly three weeks end to end.

  • Scope: scope determination, Art. 21 gap assessment, reporting readiness.

  • Deliverables: gap report, prioritised roadmap, management briefing.

  • Optional: ongoing evidence management via Managed GRC.

NIS2 Readiness

Scope determination, gap assessment and remediation roadmap

  • Format: three to four working sessions, remote or on site.

  • Duration: roughly three weeks end to end.

  • Scope: scope determination, Art. 21 gap assessment, reporting readiness.

  • Deliverables: gap report, prioritised roadmap, management briefing.

  • Optional: ongoing evidence management via Managed GRC.

NIS2 Readiness

Scope determination, gap assessment and remediation roadmap

  • Format: three to four working sessions, remote or on site.

  • Duration: roughly three weeks end to end.

  • Scope: scope determination, Art. 21 gap assessment, reporting readiness.

  • Deliverables: gap report, prioritised roadmap, management briefing.

  • Optional: ongoing evidence management via Managed GRC.

FAQ

Common Questions

Are we even in scope?
Is this a NIS2 certification?
We already have ISO 27001. Do we still need this?
Our customer sent us a NIS2 questionnaire. Can you help with just that?

That's not all

Continue the Journey

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.