NIS2
NIS2 is enforceable and carries personal management liability. We produce the technical evidence behind Articles 20–23, generated from your live attack surface rather than from a questionnaire.
What you receive
- Article 20–23 readiness assessment
- Management-body governance evidence
- 24/72-hour incident reporting workflow
- Supply-chain security requirements
When you need this
Three situations that call for it. If none of them is yours, it probably is not the right spend.
You have just been told you are in scope
The size-cap rule pulls in medium and large organisations across the Annex I and Annex II sectors, including many that have never been regulated for security before. The first piece of work is scope — which legal entities, which services, and which systems sit behind them.
A customer is auditing you as a supplier
Article 21(2)(d) makes in-scope entities responsible for security in their direct supplier relationships, so the obligation travels down contracts to firms NIS2 never names. Answering it needs technical evidence about your own estate, not a countersigned policy.
Your board must approve what it cannot read
Article 20 makes approval of the risk-management measures an act of the management body, with oversight duties and training attached to it. That only works if the measures are described in terms a non-technical body can attest to and later defend.
How it runs
Where you actually are
A working session to establish what is already in place and what your regulator, your auditor or your board is going to ask for. Usually the gap is narrower than feared and differently shaped.
What the obligation really requires
We separate what the text mandates from what a consultancy has told you it mandates. Several of the controls sold against these regimes are not required by them.
A scoped programme
The specific modules and engagements that close the gap, sequenced by what your deadline is and what depends on what — not by what is easiest to sell you.
Evidence, not a gap report
The output is the artefact your assessor accepts: test results, control evidence and a record of what changed. A document describing your gaps is not evidence that you closed them.
No lock-in
Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.
Who turns up
The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.
Scope
What this does not cover
Whether you are in scope in a particular Member State is a legal question shaped by transposition, and one for your own counsel.
Registration and incident notification to your national authority are your filings; we prepare the technical content behind them.
Physical resilience duties under the CER Directive are separate obligations and are not covered by a NIS2 engagement.
- NIS2 Directive (EU) 2022/2555
- Sets ten minimum risk-management measures under Article 21 and staged reporting at 24 hours, 72 hours and one month.
- Commission Implementing Regulation (EU) 2024/2690
- Fixes the technical requirements for Article 21 and the significant-incident thresholds for digital infrastructure and ICT providers.
- CER Directive (EU) 2022/2557
- Covers physical resilience of critical entities; an entity can be designated under both directives with separate duties.
If the scope is wrong
Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.
Questions
The ones we are actually asked.
Does an assessment protect us from a fine?
No. Member States must provide for maximum fines of at least €10 million or 2% of worldwide annual turnover for essential entities, and the authority judges the measures that were actually in place. Evidence helps that argument; it does not end it.
We hold ISO 27001. Does that cover NIS2?
It reaches much of Article 21, but not all of it. NIS2 adds staged incident reporting, management-body approval and training, and supplier obligations — and a certificate scoped to one business unit does not speak for every entity in scope.
Who decides whether an incident is significant?
You do, in the first instance, against the Article 23 test — severe operational disruption or financial loss for you, or considerable damage to others. The 24-hour early warning runs from becoming aware, not from finishing the assessment.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.