Compliance · P1

EU Cybersecurity & NIS2 Readiness

NIS2 widened EU cybersecurity law to eighteen sectors and made management personally accountable, but whether it reaches a specific company depends on entity type, sector, size, jurisdiction and how each Member State transposed it. Industry alone never decides applicability, and the national implementations differ.

This assessment provides a readiness indicator based on the information provided. It does not constitute legal advice, a regulatory determination, or a guarantee of compliance. Regulatory applicability depends on facts, jurisdiction, and legal interpretation that should be confirmed with qualified counsel.

Who it is for

The companies this problem finds first.

Companies operating in the EU in energy, transport, banking, health, digital infrastructure, ICT service management, manufacturing, food, waste, postal, space, public administration and related sectors

Suppliers to essential or important entities receiving supply-chain security clauses

Non-EU companies offering services in the EU

When it comes up

The moments that turn this from a someday into a now.

  • National authority registration deadline
  • Customer supply-chain security clause
  • Significant incident with 24-hour early-warning duty
  • New EU market entry
  • Management-liability question from the board
What we assess

9 areas, one control library.

Every area maps to controls already in the platform's single control library, so evidence collected here counts toward every other framework the business has adopted.

Entity classification: essential, important, out of scope, per Member State

Governance and management-body accountability

Risk management measures (Article 21)

Incident notification (24h early warning, 72h notification, final report)

Supply-chain security

Business continuity and crisis management

Cryptography, access control, MFA and secure communications

Vulnerability handling and disclosure

Registration and cooperation with authorities

What you get

Deliverables you can hand to a buyer, a board or a regulator.

  • Applicability assessment per Member State: entity type, sector, size, jurisdiction, essential or important status, local implementation, for counsel review
  • Article 21 measure-by-measure readiness with evidence
  • Incident notification readiness test
  • Supply-chain clause register
  • Management training and accountability record
  • Remediation roadmap
Frameworks behind it

The sources every control cites.

Requirement statements are plain-English summaries for planning; the source instrument controls. Which of these reach your business is a question the assessment records with its reasoning, not one this page answers.

  • Network and Information Security Directive 2 (Directive (EU) 2022/2555)
  • ISO/IEC 27001
  • NIST Cybersecurity Framework 2.0
  • ISO 22301 (Business Continuity)
  • Digital Operational Resilience Act (Regulation (EU) 2022/2554)
Value by role

What each executive gets out of it.

CEO

A defensible answer to whether NIS2 reaches you, in each country, before a regulator or customer decides for you.

CFO

Programme scope set by the actual classification instead of the broadest reading.

CTO / engineering

Article 21 measures turned into the specific controls and evidence that are missing.

General counsel

Member State by Member State applicability reasoning with sources and conditions recorded.

CISO / security lead

Incident-notification timelines rehearsed against the plan before the first significant incident.

How it fits

Integrated capabilities, not a separate programme.

Engagement tiers

Compliance · Regulated Industry · Resilience. Tiers describe depth and cadence; there is no per-regulation price.

Usually bought by

CEO, General counsel, CISO / security lead, COO, Board

Part of these packages

EU Expansion

FAQ

The objections, answered directly.

Applicability is decided by entity type, sector, size and the national transposition, not the industry label. Suppliers to in-scope entities are pulled in by contract regardless.

Several have, and where transposition is late the Directive still shapes what customers and authorities expect. The assessment tracks each national implementation separately.

Start with a conversation.

Thirty minutes to scope the engagement. No obligation.

Speak with an advisor