The challenge
The NIS2 directive sets stricter requirements for risk management, incident reporting and supply chain security for businesses in energy, transport, healthcare, digital infrastructure, manufacturing, public administration and other critical sectors. Many companies don't know whether the directive applies to them, what measures are required or how to document their compliance. The deadlines are set and the consequences of non-compliance are significant — including personal liability for management.
What we do
We start by assessing whether NIS2 applies to your business and to what extent. Then we carry out a risk assessment, identify gaps and build the security measures, procedures and documentation required. We establish the multi-stage incident reporting process the directive requires: early warning to CSIRT within 24 hours, formal notification within 72 hours, intermediate status reports, and a complete final report within 1 month documenting what happened, why, and how to prevent it going forward. We help you classify incidents by severity to guide escalation and resource allocation. If an incident also involves personal data, GDPR reporting kicks in too — we make sure you cover both. We help you manage supply chain security and build procedures for information sharing with service recipients about threats and remedial measures.
What you get
Applicability assessment
We clarify whether and how the NIS2 directive applies to your business — so you don't spend resources on the wrong things.
Risk assessment and measures
We identify your security risks and build the technical and organisational measures the directive requires.
Incident readiness with multi-stage reporting
We develop procedures for the full incident reporting chain — early warning within 24 hours, notification within 72 hours and a final report within 1 month. This includes investigation of what caused the incident and identification of signs of intrusion, so you can act quickly, correctly and in compliance with CSIRT requirements.
What's included
Do you know if NIS2 applies to you?
We'll do a free review and tell you whether the directive affects your business — and what you need to do.
Contact usFrequently asked questions
Are we covered by NIS2?
The directive applies to businesses in sectors including energy, transport, health, digital infrastructure, manufacturing and public administration. We carry out an applicability assessment and clarify what applies to you.
How quickly do we need to act?
The directive is being implemented into national legislation now. The sooner you start, the smoother the transition.
What do we get?
Risk assessment, security policies, complete incident reporting procedures, supplier assessment and documentation ready for supervisory authorities. Everything tailored to your business.
Can you handle supply chain security?
Yes. We assess your suppliers and build procedures so you meet the directive's supply chain security requirements.
What happens if we don't comply?
Non-compliance can lead to fines and personal liability for management. We help you prioritise the right measures in time.
We're also covered by GDPR — can you coordinate?
Yes. We build a coordinated process covering both NIS2 and GDPR, so you don't need to manage parallel tracks.
Need help with NIS2?
Tell us about your business and we'll do an assessment. Free of charge, no obligation.