You end up compliant, not advised. NIS2 compliance walks you to a met requirement — the scoping, the gaps and the evidence — rather than handing you a report about them.

Take the free self-assessment
Audit-ready in 4–5 months
  • A free self-assessment that tells you where you stand today
  • The ten measures of Article 21(2), closed one by one
  • An audit-ready evidence pack, kept current

We start from where you actually are

Ten minutes before any conversation

Fifty questions across the ten measures of Article 21(2). The report says which three to take first and what each involves — before you have spoken to anybody, and at no cost.

Whether it applies to you at all

Sector and size decide whether you are an essential or an important entity, and the obligations differ. That question is answered before any work is scoped.

The ten measures, closed

Risk analysis, incident handling, continuity, supply chain, development, effectiveness, cyber hygiene, cryptography, access control and authentication.

Evidence, not intentions

Regulators ask what you did and when. The programme produces the record as it goes rather than reconstructing it under pressure.

The ten measures of Article 21(2)

Risk analysis and security policies
A policy approved by management, and an assessment behind it with owners and dates.
Incident handling
Roles, reporting, records, and readiness for the 24-hour early warning and 72-hour notification.
Business continuity
Backups including an offline copy, a tested restore, recovery targets and a crisis plan.
Supply chain security
Who reaches your systems, assessed before selection and bound by contract afterwards.
Acquisition, development and maintenance
Controlled change, vulnerability handling on the clock, and a way for outsiders to report one.
Assessing effectiveness
Measures, internal review and independent testing — with every finding owned and dated.
Cyber hygiene and training
Annual training including management, phishing simulation, and the basics kept in place.
Cryptography
A policy for where encryption applies, and keys managed with expiry and an owner.
Access control and asset management
A current inventory, least privilege, same-day removal for leavers, privileged accounts apart.
Authentication and secure communications
Multi-factor across remote and administrative access, and a channel that survives an incident.

How it works

01

See where you stand

The self-assessment, in ten minutes and at no cost. Most conversations start from its report.

02

Establish applicability

Essential or important, and under which national implementation.

03

Close the gaps

Controls, documentation and incident drills against the ten measures.

04

Package the evidence

An audit-ready pack, kept current rather than assembled under pressure.

What you get

An evidence pack an auditor accepts

Policies, records and drill results against each of the ten measures, ordered the way the directive lists them — and maintained after the fact rather than filed away.

Check where you stand against NIS2

The self-assessment is free, takes ten minutes, and its report is yours whether or not you go further with us.