Insight
NIS2 gap analysis: the process, the content and the ten measures under Article 21
The gap analysis is the first concrete step towards NIS2 conformity. It answers the question at the start of every project: where do we stand today — measured against what the law requires?
What is a NIS2 gap analysis?
A structured current-state review that compares your present security posture with the requirements of the national NIS2 transposition and derives prioritised fields of action. The result is an ordered list: what exists, what is missing, what risk each gap carries, and with what effort it can be closed.
Why it comes first
Without a gap analysis, every investment in security is a shot in the dark. The analysis makes sure you do the most important things first — and can justify them to management and the authorities.
The process in four steps
Preparation and scoping; a current-state review through interviews, document study and — for OT — a plant walk-through; comparison against the requirements and risk rating; a prioritised action plan with effort estimates.
The ten measures under Article 21
Risk analysis and security policies; incident handling; business continuity and data backup; supply-chain security; security in acquisition, development and maintenance; assessment of effectiveness; cyber hygiene and training; cryptography; personnel security and access control; multi-factor authentication.
Particularities in OT environments
In operational technology the priorities differ: interventions must spare operations, legacy systems cannot simply be updated, availability comes first. A purely IT view misses exactly that.
A gap analysis makes conformity plannable. Clarify your NIS2 status.
Further reading: NIS2 & ISO/IEC 27001 · ISO/IEC 27001
Clarify your NIS2 status
A free intro call, no commitment, a reply within 24 hours.