EU NIS2 · Network & Information Security

NIS2 has teeth. Be ready before it bites.

The NIS2 Directive widens Europe's cybersecurity net to eighteen sectors, brings personal accountability to management bodies, and puts a 24-hour clock on incident reporting. We help essential and important entities, and the suppliers in their chains, build the security programme the directive actually demands.

We hold ourselves to the standards we audit: Cybercontrols is certified to
ISO/IEC 27001:2022Certified · SANCERT ISO/IEC 42001:2023Certified · SANCERT Cyber EssentialsCertified Government Commercial AgencyApproved Supplier · G-Cloud 15
What we deliver

From "are we in scope?" to demonstrable compliance.

NIS2 is transposed differently in every member state, and scope is where most organisations get it wrong, in both directions. We start with an honest applicability assessment and build only what the directive genuinely requires of you.

01

Scope & Gap Assessment

A definitive answer on whether you are an essential entity, an important entity, or in scope through a customer's supply chain, followed by a gap analysis against the directive's security measures and your member state's transposition.

02

Implementation

Risk management, supply chain security, incident handling, business continuity and governance measures built into one coherent programme, typically anchored on ISO 27001 so a single system serves the certificate and the regulation.

03

Incident & Reporting Readiness

The 24-hour early warning and 72-hour notification only work if they are rehearsed. We build the reporting playbooks, run the tabletop exercises, and prepare management for the accountability the directive places on them personally.

Why Cybercontrols

Regulation is best handled by people who audit for a living.

NIS2 compliance is ultimately an evidence problem: could you demonstrate, under scrutiny, that your security measures are appropriate and operating? That is precisely the question our Senior Lead Auditors spend their working lives asking on behalf of certification bodies, so we build programmes that answer it before a regulator asks. And because NIS2 sits naturally on an ISO 27001 spine, one well-built system can serve the directive, the certificate and your customers' due diligence at once.

Scope, settled

Essential, important, or supply-chain scope, determined against your member state's transposition, not a generic checklist.

ISO 27001 anchored

One management system serving NIS2, certification and procurement due diligence together.

Management accountability

Briefings and governance structures for boards who are now personally on the hook.

Senior-led, always

Senior Lead Implementer and Senior Lead Auditor credentials on every engagement. No juniors, no hand-offs.

How it works

From applicability to demonstrable compliance, without surprises.

Step 1

Applicability & scoping

Sector, size and service analysis against the directive and your member state's transposition, so you know definitively whether and how NIS2 applies before a penny is spent on controls.

Step 2

Gap analysis

Your current measures benchmarked against the directive's security requirements: risk analysis, incident handling, continuity, supply chain, secure development, cryptography, access control and training, with an honest reading of the distance to compliance.

Step 3

Build & embed

Measures deployed inside your existing ways of working, anchored on ISO 27001 where that serves you, with supply chain obligations flowed down to the suppliers who now carry them.

Step 4

Rehearse & evidence

Incident reporting rehearsed against the 24-hour and 72-hour clocks, management briefed on their accountability, and an evidence pack maintained so scrutiny holds no fear.

Step 5

Operate & improve

Ongoing internal audit, management review and regulatory monitoring as member state guidance matures, so compliance is a state you maintain rather than a project you finished once.

Questions we hear most

NIS2, answered plainly.

Does NIS2 apply to UK companies?

Not directly, as NIS2 is an EU directive, but it reaches UK businesses through EU establishments and through supply chains: if you provide services to in-scope EU entities, their obligations flow down to you contractually. The UK is meanwhile advancing its own strengthened regime, so the direction of travel is the same on both sides of the Channel.

What is the difference between essential and important entities?

Both carry the same security obligations; they differ in supervision and penalties. Essential entities face proactive supervision and higher maximum fines; important entities are supervised reactively. Which you are depends on sector and size, and we settle it at scoping.

Does ISO 27001 certification satisfy NIS2?

Not automatically, but it is the best foundation available: a certified ISMS covers most of the directive's measures and, crucially, provides the evidence trail regulators expect. We map the delta, typically incident reporting mechanics and supply chain specifics, and close it.

What are the penalties?

Up to €10 million or 2% of worldwide turnover for essential entities, €7 million or 1.4% for important entities, and member states can hold management personally liable. The sharper risk for most firms, though, is commercial: in-scope customers are already pushing NIS2 requirements into contracts.

In scope, out of scope, or not sure?

A 30-minute scoping call with a senior lead auditor will settle it, and give you an honest plan either way.