NIS2 Is Already Enforced. Are You In Scope?
We help mid-sized companies across the EU determine their NIS2 exposure, close Article 21 risk-management gaps, and build a documented, audit-ready compliance program — before an incident, an auditor, or a regulator asks.
Does NIS2 apply to you?
Directive (EU) 2022/2555 pulls in far more mid-sized companies than most teams expect, including suppliers to in-scope organizations. A few quick questions, one clear answer.
Which best describes your business?
- Sector—
- EU jurisdiction—
- Size-cap—
- Auto-inclusion—
What NIS2 non-compliance actually costs.
Directive (EU) 2022/2555 backs its requirements with real fines, fixed deadlines, and personal liability for leadership, not just a checkbox.
of global annual turnover for essential entities, whichever is higher.
- 24h Early warning to your national CSIRT
- 72h Formal incident notification
- 1mo Final report with root cause and mitigation
Management bodies must approve and oversee cyber risk measures directly. Getting it wrong can mean personal accountability, including temporary bans from managerial roles.
Most companies don’t fail NIS2 because they’re insecure. They fail because they never realised they were in scope.
NIS2 expanded who’s regulated far beyond critical infrastructure — and enforcement doesn’t wait for you to notice.
Most companies already run real security work. The gap is turning that work into a documented, reportable program that satisfies NIS2’s specific obligations. That’s where we help—by making your organisation NIS2-ready before an incident, an auditor, or a regulator asks.
A Structured Approach to NIS2 Readiness.
We begin by assessing your current security posture against NIS2’s Article 21 risk-management requirements, identifying control gaps, and prioritizing remediation. From implementing technical safeguards and documenting policies to preparing incident-reporting evidence, we help you build an environment that is organized, defensible, and ready for regulatory scrutiny.
Everything You Need for NIS2 Readiness.
Every engagement produces real, usable deliverables mapped to NIS2’s Article 21 risk-management measures — not a slide deck, a working compliance program.
NIS2 Gap Assessment Report
Your current posture mapped against all 10 Article 21 measures, with a prioritized remediation path.
Risk Management Policy Package
Documented, board-approved policies covering every required risk-management area.
Incident Response & Reporting Playbook
A tested workflow built around the 24-hour, 72-hour, and 1-month reporting clock.
Supply Chain Security Assessment
Vendor and third-party risk mapped and vetted against Article 21’s supply-chain requirement.
Business Continuity & Disaster Recovery
Backup architecture, recovery objectives, and crisis-management procedures.
Technical Controls Implementation
MFA, access control, encryption policy, and vulnerability management, deployed not just documented.
Staff Security Awareness Training
Cyber hygiene training that satisfies Article 21’s basic training requirement.
Governance & Board Reporting Pack
Management-body sign-off documentation, addressing NIS2’s personal-liability requirement directly.
Continuous Monitoring & Annual Review
Ongoing oversight so your compliance posture stays current as NIS2 guidance evolves.
Security work that shows up in the numbers.
Every engagement is measured, not just delivered.
The Right NIS2 Partner Makes All the Difference.
| Criteria |
// Recommended
BPDoxS
|
// In-house In-house team | // Vendor Typical vendor |
|---|---|---|---|
| NIS2 Expertise | Dedicated NIS2 readiness methodology, built around Article 21 |
General security knowledge, rarely NIS2-specific |
Generic compliance checklist, not mapped to NIS2 |
| Incident Reporting Readiness | Tested 24h / 72h / 1-month reporting workflow |
No formal process until an incident forces one |
Documented on paper, rarely tested |
| Supply Chain Security | Vendor risk mapped against Article 21's requirement |
Ad-hoc vendor reviews, no formal mapping |
Often out of scope entirely |
| Regulatory Tracking | Continuous monitoring as NIS2 guidance evolves |
Depends on internal team bandwidth |
Annual review at best |
| Governance Documentation | Board-ready sign-off pack, addresses personal liability |
Internal reporting, rarely board-formatted |
Generic templates, not liability-specific |
| Cost Efficiency | Predictable engagement pricing, no hidden fees |
High staffing and ongoing overhead |
Recurring licenses plus additional service costs |
Independently recognized.
Rated by clients on Clutch · GoodFirms · Sortlist · DesignRush · RightFirms
Questions Worth Asking.
Everything you need to know before becoming NIS2-ready with confidence.
No — NIS2 doesn't have a certification scheme the way ISO 27001 or SOC 2 do. It's regulatory compliance, assessed by your national competent authority, not an accredited certifying body. We prepare you to meet Article 21's requirements and stand up to that regulatory scrutiny — we don't issue a certificate because NIS2 doesn't work that way.
Most companies assume they're too small. If your sector falls under Annex I or II and you have 50+ employees or over €10M in turnover, you're almost certainly in scope — meeting either figure alone is enough. Use the scope checker above for an instant read, or talk to us directly if you're not sure.
Fines up to €10M or 2% of global turnover for essential entities (€7M / 1.4% for important entities), a 24-hour/72-hour/1-month reporting clock you're expected to hit from day one, and personal liability for management if oversight failures caused the gap. This is why readiness has to happen before an incident, not after.
Typically 8–14 weeks from kickoff to audit-ready, depending on your current security maturity. After the initial gap assessment, you get a realistic roadmap with clear milestones — not a vague timeline.
Yes. Whether you're running your own stack, a managed provider, or a hybrid setup, we integrate with what you already have instead of forcing a complete redesign. NIS2 readiness is built around your existing infrastructure, not against it.
Both carry the same Article 21 risk-management obligations — the difference is enforcement and penalty tier. Essential entities (Annex I sectors like energy, banking, digital infrastructure) face proactive supervision and fines up to €10M/2%. Important entities (Annex II, like most digital providers and manufacturing) are supervised reactively — after an incident or complaint — with fines up to €7M/1.4%.
Know if NIS2 applies. Know exactly what to do next.
Every engagement starts with understanding your sector, your exposure, and your gaps against Article 21 — before we recommend a single control.
