The NIS2 Directive widens Europe's cybersecurity net to eighteen sectors, brings personal accountability to management bodies, and puts a 24-hour clock on incident reporting. We help essential and important entities, and the suppliers in their chains, build the security programme the directive actually demands.
NIS2 is transposed differently in every member state, and scope is where most organisations get it wrong, in both directions. We start with an honest applicability assessment and build only what the directive genuinely requires of you.
A definitive answer on whether you are an essential entity, an important entity, or in scope through a customer's supply chain, followed by a gap analysis against the directive's security measures and your member state's transposition.
Risk management, supply chain security, incident handling, business continuity and governance measures built into one coherent programme, typically anchored on ISO 27001 so a single system serves the certificate and the regulation.
The 24-hour early warning and 72-hour notification only work if they are rehearsed. We build the reporting playbooks, run the tabletop exercises, and prepare management for the accountability the directive places on them personally.
NIS2 compliance is ultimately an evidence problem: could you demonstrate, under scrutiny, that your security measures are appropriate and operating? That is precisely the question our Senior Lead Auditors spend their working lives asking on behalf of certification bodies, so we build programmes that answer it before a regulator asks. And because NIS2 sits naturally on an ISO 27001 spine, one well-built system can serve the directive, the certificate and your customers' due diligence at once.
Essential, important, or supply-chain scope, determined against your member state's transposition, not a generic checklist.
One management system serving NIS2, certification and procurement due diligence together.
Briefings and governance structures for boards who are now personally on the hook.
Senior Lead Implementer and Senior Lead Auditor credentials on every engagement. No juniors, no hand-offs.
Sector, size and service analysis against the directive and your member state's transposition, so you know definitively whether and how NIS2 applies before a penny is spent on controls.
Your current measures benchmarked against the directive's security requirements: risk analysis, incident handling, continuity, supply chain, secure development, cryptography, access control and training, with an honest reading of the distance to compliance.
Measures deployed inside your existing ways of working, anchored on ISO 27001 where that serves you, with supply chain obligations flowed down to the suppliers who now carry them.
Incident reporting rehearsed against the 24-hour and 72-hour clocks, management briefed on their accountability, and an evidence pack maintained so scrutiny holds no fear.
Ongoing internal audit, management review and regulatory monitoring as member state guidance matures, so compliance is a state you maintain rather than a project you finished once.
Not directly, as NIS2 is an EU directive, but it reaches UK businesses through EU establishments and through supply chains: if you provide services to in-scope EU entities, their obligations flow down to you contractually. The UK is meanwhile advancing its own strengthened regime, so the direction of travel is the same on both sides of the Channel.
Both carry the same security obligations; they differ in supervision and penalties. Essential entities face proactive supervision and higher maximum fines; important entities are supervised reactively. Which you are depends on sector and size, and we settle it at scoping.
Not automatically, but it is the best foundation available: a certified ISMS covers most of the directive's measures and, crucially, provides the evidence trail regulators expect. We map the delta, typically incident reporting mechanics and supply chain specifics, and close it.
Up to €10 million or 2% of worldwide turnover for essential entities, €7 million or 1.4% for important entities, and member states can hold management personally liable. The sharper risk for most firms, though, is commercial: in-scope customers are already pushing NIS2 requirements into contracts.
A 30-minute scoping call with a senior lead auditor will settle it, and give you an honest plan either way.