NIS2 Directive

NIS2 services, matched to where you are today.

Organisations do not all need the same NIS2 support. Some need to establish whether they are in scope and where to begin. Others need independent assurance that their compliance position is credible. Some need a structured programme that can move from regulatory interpretation to governance, implementation and sustained compliance.

Choose your starting point

Three NIS2 engagement options.

Each engagement is designed to produce board-ready findings, prioritised actions and evidence that can support management oversight.

5-day diagnostic

NIS2 Diagnostic

Understand whether NIS2 applies to you, how much work is involved, and how to structure your response from the start.

  • Entity scoping and applicability
  • Readiness review against NIS2 security requirements
  • Estimate of programme size, complexity and effort
  • Recommended mobilisation roadmap
Output: A concise diagnostic summary with scope view, priority actions and mobilisation roadmap.
Start with a diagnostic
Independent assurance

NIS2 Compliance Verification

Test whether your NIS2 position is credible, well-evidenced and ready for leadership, audit or supervisory review.

  • Review of governance, controls and accountability
  • Assessment of evidence quality and traceability
  • Independent challenge of compliance status
  • Prioritised remediation actions
Output: An independent readiness view with evidence findings, challenge points and prioritised remediation actions.
Verify your readiness
Full programme

NIS2 Programme Design

Build the governance, ownership model and delivery structure for a practical, sustained NIS2 programme.

  • Programme governance and workstream design
  • Control ownership and accountability model
  • Evidence framework and reporting cadence
  • Implementation roadmap and prioritisation
Output: A programme design covering governance, ownership, evidence and delivery workstreams.
Discuss programme design
Thought leadership

NIS2 frameworks.

The engagement options above are delivered using two proprietary frameworks. Executive briefings for each are available to download below.

NIS2 briefings

Executive perspectives on NIS2.

Practical analysis of the governance, programme and assurance decisions involved in implementing and sustaining NIS2.

July 20265-minute read

Governing the NIS2 Gaps That Remain at Programme Close

A NIS2 programme may reach its planned end date with some findings still open. Supplier negotiations can take longer than expected, technical remediation may depend on wider investment, and new gaps can emerge while delivery is under way. Extending the programme until every issue disappears may be impractical because the obligations, systems and risk environment continue to change.

Read briefing
June 20266-minute read

A NIS2 Programme Should Leave an Operating Model Behind

When a NIS2 programme closes, the steering committee stands down and the programme team disperses. The regulatory obligations continue: controls require ongoing verification and evidence, risk assessments require refreshing, the incident notification capability requires testing, and the management body needs reporting to exercise oversight. Each of these needs to be designed, owned and handed over before the programme closes.

Read briefing
March 20266-minute read

The Governance Foundations of a NIS2 Programme

NIS2 places substantive, ongoing obligations on the management body. Building a compliance position that meets them requires a governed programme, with a mandate, a defined scope and formal close conditions. Organisations that treat NIS2 as a list of controls to check off will find the position they have built is difficult to demonstrate and harder to sustain.

Read briefing
March 20264-minute read

ISO 27001 Certification and NIS2 Supervisory Scrutiny

ISO 27001 certification demonstrates that a management system was in place and conformed to the standard at the point of audit. NIS2 supervisory scrutiny asks a different set of questions: whether specific obligations under the directive are met at the time of inspection, including management body accountability, incident notification readiness and supply chain security in the form the directive requires.

Read briefing
February 20265-minute read

The Scope Decision Behind a Credible NIS2 Programme

A programme scoped too broadly cannot be delivered in time. One scoped too narrowly produces gaps that surface during supervisory inspection rather than during the programme. Both result from the same mistake: treating regulatory scope as programme scope rather than as its starting point.

Read briefing
January 20265-minute read

NIS2 Is Not One Rulebook Across Europe

NIS2 is a European directive, not a regulation. Unlike a regulation, it does not apply identically across all EU Member States. Each Member State must enact its own implementing legislation, and the details matter: scope, supervision, evidence expectations and enforcement can differ materially between jurisdictions.

Read briefing
December 20255-minute read

Starting a NIS2 Programme Without Knowing Your Position

Most organisations that are in scope for NIS2 cannot yet answer three questions with confidence: which entities are in scope and under which national law, whether the governance conditions for a programme exist, and what scale of work lies ahead. Commissioning a programme without those answers produces a programme that either over-corrects or addresses the wrong things.

Read briefing
October 20255-minute read

NIS2 Makes Cybersecurity a Leadership Duty

NIS2 does not only impose obligations on the security function. Article 20 places specific requirements on the management body: to approve the cybersecurity risk management measures the organisation adopts, to oversee their implementation, and to follow cybersecurity training. These obligations sit with senior leaders directly and cannot be discharged by the CISO or delegated to a technical team.

Read briefing
Common questions

NIS2 FAQ.

NIS2 applies to public and private entities in one of 18 sectors listed in Annex I or Annex II of the Directive, provided the entity meets the medium enterprise size threshold: at least 50 employees or €10 million annual turnover. Certain categories fall within scope regardless of size. Where the organisation operates across multiple EU Member States, scope must be assessed against each country's national transposition legislation separately, as Member States have implemented the Directive in different ways.

The sector and size criteria are a starting point. National competent authorities retain the power to designate additional entities beyond the standard thresholds. If your organisation operates in energy, transport, banking, financial infrastructure, healthcare, water, digital infrastructure, or a number of other sectors, a scope analysis is the right first step.

For essential entities, infringements of the Article 21 security obligations or Article 23 incident notification requirements can attract fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, the maximum is €7 million or 1.4% of worldwide annual turnover. The calculation basis is worldwide turnover.

Beyond fines, NIS2 introduces personal accountability provisions. Natural persons with managerial responsibility can be held personally liable. For essential entities, competent authorities can request a court to temporarily prohibit a chief executive officer or legal representative from exercising their functions where prior enforcement measures have proved ineffective. Management body approval and oversight are legal requirements.

Article 21 sets out ten categories of security measure: risk analysis and security policies, incident handling, business continuity and disaster recovery, supply chain security, secure system acquisition and development, effectiveness testing, cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication. These are ongoing obligations.

Article 23 adds strict incident notification timelines: a 24-hour early warning to the national CSIRT or competent authority, a fuller notification within 72 hours, and a final report within one month. Article 20 places specific obligations on the management body to approve the security measures and oversee their implementation. Separate enforcement provisions make individuals with managerial responsibility personally liable for infringements.

Internal teams cannot easily challenge their own work or produce an independent view of the compliance position. NIS2 carries personal liability for management body members: a management body that has relied entirely on internal self-assessment is in a weaker position if a supervisory authority asks difficult questions. External involvement also brings direct programme experience, including how to sequence workstreams, where programmes of this type typically lose coherence, and what a supervisory authority expects to find.

The diagnostic is a deliberately bounded starting point. Five working days, spread over two to three weeks, produces a clear picture of scope, readiness, and what a programme needs to look like before any further investment is made. It is a low-commitment way to establish whether, and how, external support adds value.

Yes. The three engagements are designed for different starting positions. The NIS2 Compliance Verification is for organisations that have done substantive work and need an independent view of whether the position is credible, well-evidenced, and ready for leadership, audit, or supervisory review. It works with what already exists, identifies where the gaps are, and produces a prioritised remediation view.

Where the work underway is a programme that needs better structure, governance, or delivery design, the Programme Design engagement can provide that without displacing what has already been built. The starting point is a conversation about where things currently stand.

Yes. The work covers the full range of NIS2 sectors, from energy, transport, and healthcare to digital infrastructure, financial services, and public administration. Sector matters because the applicable national transposition, the relevant competent authority, and the supervisory expectations vary between sectors as well as between jurisdictions.

Multinational engagements are a regular part of the work. Where an organisation operates across multiple EU Member States, the programme needs to account for genuine legal variation between national implementations. Each entity's position is mapped against the applicable national law.

The starting point is a 20-minute advisory call to understand the organisation's current position and which engagement makes sense. There is no obligation following that call.

If a diagnostic is the right next step, the pre-work is modest: a document request covering corporate structure, service descriptions, headcount and turnover figures, existing legal analysis, and current governance and policy documents. The diagnostic itself requires targeted sessions with the legal lead, CISO, and relevant functional and operational leads. Most participants are involved for one to three hours each across the five days.

A full programme runs for twelve to twenty-four months depending on the organisation's starting position, structure, and jurisdictional spread. The diagnostic, which comes first, takes five working days spread across two to three weeks.

The programme does not require operational leads to step away from their day roles. It requires a named executive sponsor with genuine decision authority, a programme manager with dedicated time, and part-time participation from functional leads who will own their workstreams after the programme closes. The most demanding phase for the internal team is the gap assessment and initial design work. The later delivery workstreams are largely run by the internal team, with external support focused on governance, challenge, and course correction.

20-minute advisory call

Not sure where your organisation stands on NIS2?