Step 01
Start and scope
Align business areas, processes, systems, suppliers, and existing documentation into an operational scope.
Make NIS2 manageable, structured, and audit-ready. We turn cybersecurity, incident reporting, supplier risk, resilience, and management accountability into a practical implementation plan.
✓ ISO 27001:2022 base mapped
✓ supplier risk prioritised
→ incident process wiring
○ management review pending
// nis2 readiness
We use ISO/IEC 27001:2022 as the management-system backbone, then add the NIS2-specific layer for governance, reporting readiness, suppliers, resilience, and evidence.
Step 01
Align business areas, processes, systems, suppliers, and existing documentation into an operational scope.
Step 02
Review policies, controls, evidence, incident reporting, supplier security, resilience, and accountability.
Step 03
Turn findings into owners, dependencies, timelines, priorities, and evidence requirements.
Step 04
Support process design, documentation, evidence structure, operational routines, and training.
// operating model
NIS2 becomes an operating model: reviewable processes, clear ownership, and evidence that can be shown when asked.
We assess your security and operational processes against ISO/IEC 27001:2022, then add NIS2-specific expectations.
Cyber risk management, supplier security, service provider controls, and resilience are prioritised by exposure.
Management reporting, Lead Implementer training, and decision routines make responsibility explicit.
What you get
A focused readiness review usually starts in the low five-figure range. Core implementation often lands in the mid five figures; larger multi-site programmes can be higher.
A readiness review and roadmap usually takes 2 to 5 weeks. Core implementation often takes 8 to 12 weeks; complex environments may need 4 to 6 months.
Not automatically. ISO 27001 is a strong ISMS foundation. NIS2 adds governance, reporting, supplier security, resilience, and evidence expectations.
Privacy settings
Necessary only
We use necessary storage for security and consent management. Analytics and marketing stay off unless you allow them.
Optional processing runs only after your consent under GDPR Art. 6(1)(a). You can change this choice at any time. Privacy policy