Fifty questions across the ten measures of Article 21(2). The report says which three to take first and what each involves — before you have spoken to anybody, and at no cost.
Sector and size decide whether you are an essential or an important entity, and the obligations differ. That question is answered before any work is scoped.
Risk analysis, incident handling, continuity, supply chain, development, effectiveness, cyber hygiene, cryptography, access control and authentication.
Regulators ask what you did and when. The programme produces the record as it goes rather than reconstructing it under pressure.
The self-assessment, in ten minutes and at no cost. Most conversations start from its report.
Essential or important, and under which national implementation.
Controls, documentation and incident drills against the ten measures.
An audit-ready pack, kept current rather than assembled under pressure.
Policies, records and drill results against each of the ten measures, ordered the way the directive lists them — and maintained after the fact rather than filed away.
The self-assessment is free, takes ten minutes, and its report is yours whether or not you go further with us.