# NIS2 compliance

> You end up compliant, not advised.

NIS2 compliance walks you to a met requirement — the scoping, the gaps and the evidence — rather than handing you a report about them.

**Key points**

- A free self-assessment that tells you where you stand today
- The ten measures of Article 21(2), closed one by one
- An audit-ready evidence pack, kept current

## We start from where you actually are

### Ten minutes before any conversation

Fifty questions across the ten measures of Article 21(2). The report says which three to take first and what each involves — before you have spoken to anybody, and at no cost.

### Whether it applies to you at all

Sector and size decide whether you are an essential or an important entity, and the obligations differ. That question is answered before any work is scoped.

### The ten measures, closed

Risk analysis, incident handling, continuity, supply chain, development, effectiveness, cyber hygiene, cryptography, access control and authentication.

### Evidence, not intentions

Regulators ask what you did and when. The programme produces the record as it goes rather than reconstructing it under pressure.

## The ten measures of Article 21(2)

- **Risk analysis and security policies** — A policy approved by management, and an assessment behind it with owners and dates.
- **Incident handling** — Roles, reporting, records, and readiness for the 24-hour early warning and 72-hour notification.
- **Business continuity** — Backups including an offline copy, a tested restore, recovery targets and a crisis plan.
- **Supply chain security** — Who reaches your systems, assessed before selection and bound by contract afterwards.
- **Acquisition, development and maintenance** — Controlled change, vulnerability handling on the clock, and a way for outsiders to report one.
- **Assessing effectiveness** — Measures, internal review and independent testing — with every finding owned and dated.
- **Cyber hygiene and training** — Annual training including management, phishing simulation, and the basics kept in place.
- **Cryptography** — A policy for where encryption applies, and keys managed with expiry and an owner.
- **Access control and asset management** — A current inventory, least privilege, same-day removal for leavers, privileged accounts apart.
- **Authentication and secure communications** — Multi-factor across remote and administrative access, and a channel that survives an incident.

## How it runs

1. **See where you stand** — The self-assessment, in ten minutes and at no cost. Most conversations start from its report.
2. **Establish applicability** — Essential or important, and under which national implementation.
3. **Close the gaps** — Controls, documentation and incident drills against the ten measures.
4. **Package the evidence** — An audit-ready pack, kept current rather than assembled under pressure.

## What you get

**An evidence pack an auditor accepts** — Policies, records and drill results against each of the ten measures, ordered the way the directive lists them — and maintained after the fact rather than filed away.

---

Canonical: https://centio.bg/uslugi/nis2-compliance