Governance, Risk & Compliance
NIS2 Readiness & Implementation
From 'are we in scope?' to a registered, evidenced, defensible compliance position.
The situation
What the client receives
Schedule of deliverables
- Scope and entity classification (essential / important) with written justification
- National registration support (DNSC in Romania; equivalent authority elsewhere)
- Gap assessment against the Art. 21 measures and Art. 23 reporting duties
- Prioritised remediation roadmap with owners, cost and dates
- 24h / 72h / 1-month incident notification procedure and templates
- Management-body accountability briefing and training record
- Inspection-ready evidence pack
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- Directive (EU) 2022/2555
- RO: GEO 155/2024, Law 124/2025
- DNSC Orders 1 & 2/2025
- Commission Implementing Regulation (EU) 2024/2690
- ISO/IEC 27001
Related services
Discuss this engagement
Tell us about your entity, its sector and where you stand on registration and we will set out the scope, the method and the reporting format.