NIS2
Compliance

Practical help to meet the EU NIS2 Directive — risk-management measures, incident reporting, supply-chain security, and governance obligations for essential and important entities.

Overview

Meet your NIS2 obligations.

NIS2 significantly expands EU cybersecurity obligations and personal accountability for management. If your organisation is an essential or important entity, you must implement appropriate risk-management measures and meet strict incident-reporting timelines.

We assess your obligations, close the gaps against the directive, and put the governance, risk-management, supply-chain, and incident-reporting processes in place — pragmatically, mapped to frameworks you may already use such as ISO 27001.


Scope

What we deliver.

The risk, reporting, and governance measures NIS2 requires.

Framework: EU NIS2 Directive Article 21 measures Incident reporting ISO 27001 mapping

FAQ

NIS2 FAQ

The questions we're asked most about scope, cost, and timing.

How much does NIS2 compliance cost?
NIS2 readiness support is typically €2,000–3,500 per month over a 2–4 month engagement, depending on size, sector, and maturity. Use our estimator for a tailored figure.
Does NIS2 apply to my organisation?
NIS2 applies to medium and large organisations across many sectors deemed essential or important — energy, transport, banking, health, digital infrastructure, ICT management, and more. We confirm classification during scoping.
What are the main NIS2 requirements?
Appropriate risk-management measures (Article 21), incident reporting within strict timelines, supply-chain security, business continuity, and direct management accountability.
How long does NIS2 readiness take?
Typically 2–4 months, depending on maturity and whether you already have a framework such as ISO 27001.
Can NIS2 build on ISO 27001?
Yes — if you already have ISO 27001, much of the work is reusable. We map NIS2 onto your existing ISMS to avoid duplication.
When does NIS2 take effect for us?
NIS2 is being transposed into national law across the EU; obligations apply once your member state’s implementation is in force. We help you track and meet the timeline.
Are we an "essential" or "important" entity?
It depends on your sector and size; the distinction affects supervision and penalties. We confirm your classification during scoping.
What are the incident-reporting deadlines?
NIS2 requires an early warning within 24 hours and a fuller notification within 72 hours; we build the processes to meet these.
Does management have personal liability?
Yes — NIS2 places direct accountability on management for cybersecurity governance, which our programme addresses explicitly.
Can NIS2 reuse our ISO 27001?
Yes — we map NIS2 onto an existing ISMS so you are not duplicating effort.

Related services

Explore more.

Ready to meet NIS2?

A 30-minute scoping call costs nothing. Non-compliance penalties cost considerably more.

Book a meeting Send an email