NIS2 / Cyber-Resilience Readiness Review

An independent reading of your NIS2 scope and readiness, in writing, built specifically for EU mid-market businesses that don’t have a dedicated compliance function to figure this out internally.

NIS2 has a materially wider scope than DORA — it reaches essential and important entities across many more sectors than financial services alone. If your business falls into scope, you’re expected to demonstrate specific control mapping and incident response capability, and most mid-market businesses newly caught by this haven’t had the internal resource to work out precisely what that means for them.

That is what this engagement is.

€15,000. Three to four weeks. Delivered in writing, with a presentation to whoever needs to hear it.

Fixed fee. No implementation work. No commissions. No product recommendations influenced by suppliers.

Why clients commission this review

  • NIS2 scope determination has never been formally done, and the board isn’t confident whether the business is genuinely in or out.
  • The business is confirmed in scope, and needs a genuine control mapping exercise against the specific NIS2 requirements, not a generic security best-practice comparison.
  • Incident response capability exists informally but has never been documented or tested against NIS2’s specific reporting timelines.
  • A supply chain partner or customer has asked for evidence of NIS2 compliance as part of their own due diligence.

Who this is for

Boards at EU mid-market essential or important entities who want an independent scope determination and control mapping.

Businesses without a dedicated compliance function needing a clear, practical read of what NIS2 actually requires of them specifically.

Who this is not for

Large financial services entities primarily concerned with DORA — that regime has its own, more specific set of requirements; see our DORA-focused reviews instead.

Businesses wanting security controls or incident response tooling implemented. We identify and recommend; we do not implement.

What you receive

The Review tells you three things in writing: whether and how you’re in scope, where your control environment stands against NIS2’s requirements specifically, and what to close first. Five artefacts, delivered together, in plain language.

A scope determination. A specific, documented answer on whether and how the business falls under NIS2, and as which entity type.

A control mapping against NIS2’s specific requirements. Not generic best practice — the actual articles and requirements, checked against what’s genuinely in place.

An incident response gap analysis. Whether current incident response capability could actually meet NIS2’s specific reporting timelines under pressure.

A prioritised roadmap. What to close first, second, third, sequenced by regulatory risk.

A board presentation. A one-hour session with your board or risk committee, findings presented, challenged, and discussed in the room.

How the Review runs

Three to four weeks, in four phases: scoping and inventory, interviews and evidence gathering, synthesis and writing, then presentation and revisions around your board cycle.

Everything is written before it is said. Nothing is presented to your board that you have not read first.

What this is not

Legal advice on scope determination. The Review gives you a well-evidenced, practitioner-level read; final legal certainty on edge-case scope questions is a matter for regulatory counsel.

A remediation engagement. We identify and recommend; we do not implement.

Proof

References available on request.

What happens next

Start a Conversation

Thirty minutes. We confirm fit, scope, and timing. No proposal is sent unless you ask for one.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Book a NIS2 / Cyber-Resilience Readiness Review scoping call