Services
NIS2 conformity — the organisational layer
Where IEC 62443 orders the technology and the CRA the product, NIS2 orders the organisation. The directive demands more than a document: lived risk-management measures, working reporting processes and evidence towards the authorities. The gap analysis is the first concrete step towards it — it shows, in a structured way, where your company stands today.
Are you in scope?
NIS2 distinguishes between "essential" and "important" entities and ties scope to sector and company size. It generally covers medium and large organisations (from roughly 50 staff or ten million euro annual turnover) in regulated sectors — including energy and parts of manufacturing. Smaller suppliers are drawn in through the supply chain, because their customers demand evidence. The first part of any analysis is therefore the clean clarification of your status. NIS2 is an EU directive, transposed by each member state into national law (for example the Netherlands' Cyberbeveiligingswet), so the precise authority and deadlines depend on where you operate.
Management accountability
NIS2 moves responsibility upward. Management bodies must approve the measures, oversee their implementation and undergo training. Across the EU this personal accountability is a defining feature of the directive. A documented gap analysis demonstrates that management takes its duty of care seriously.
The ten measures under Article 21
The substance is the ten baseline measures: risk analysis and security policies; handling of security incidents; business continuity and data backup; supply-chain security; security in acquisition, development and maintenance; assessment of effectiveness; cyber hygiene and training; cryptography and encryption; personnel security and access control; and multi-factor authentication and secured communication. We examine each of these categories individually.
ISO/IEC 27001 as evidence
An information security management system (ISMS) to ISO/IEC 27001 covers a large part of these measures and counts as recognised evidence. As an ISO/IEC 27001 Lead Auditor, we build your ISMS so that it serves both ends: certification readiness and NIS2 evidence in one. That includes setting up the system, internal audits and preparing for third-party certification.
Particularities in industry
Many analyses fail because they treat operational technology like an office network. Because we come from OT practice, we assess not only the governance but the control systems behind it — and connect the organisational layer to your IEC 62443 and CRA work rather than building it separately.
Our process
A current-state review through interviews and document study, a gap analysis with risk rating, a prioritised action plan with effort estimates and — on request — implementation support as a vCISO. The result is an actionable document you can put before management and the authorities.
Essential and important entities — the difference
NIS2 recognises two categories. Essential entities — such as larger energy operators — face the strictest, partly proactive supervision and the highest fines. Important entities are generally examined on a reactive basis, for instance after an incident. The classification therefore governs not only the obligations but the intensity of supervision and the risk if something goes wrong. Determining it cleanly is the first step of any analysis.
Reporting and registration obligations
Beyond risk management, NIS2 requires two formal duties. First, registration with the competent authority within the prescribed deadlines. Second, the reporting of significant incidents in several stages: an early warning at very short notice, a fuller notification within 72 hours, and a final report within one month. These processes must be prepared before anything happens — in an incident there is no time to invent them.
The supply chain comes with it
An often underestimated point: NIS2 requires you to account for the security of your suppliers and service providers too. Conversely, smaller suppliers are drawn into scope because their larger customers demand evidence. Conformity is increasingly a precondition for staying a business partner — not only a matter for the authorities.
Is ISO 27001 enough?
ISO/IEC 27001 covers many NIS2 measures and is strong evidence, but it does not replace every obligation — such as the reporting and registration duties. We show you where the standard carries and where additional steps are needed.
From obligation to benefit
NIS2 is often seen as pure burden. In fact the directive forces something worth doing anyway: knowing which risks your company carries and being prepared when something goes wrong. Considered risk management protects not only against fines but against real outages and their financial damage. We help you implement the obligation so that it serves your operations, not only the authorities.
What you receive
The result is an actionable package: a status assessment, a prioritised list of measures with effort and risk, and a roadmap you can put before management and the authorities. On request we support the implementation — and connect it with your IEC 62443 and, for manufacturers, CRA work.
Further reading: IEC 62443 – Assessment & Security Architecture · vCISO & Ongoing Advisory · Energy & Industrial Technology
Clarify your NIS2 status
A free intro call, no commitment, a reply within 24 hours.