Compliance · NIS2 and beyond
NIS2, without the theatre.
We assess against the obligations that actually apply to you, test the controls rather than take their word for it, and hand back a roadmap ordered by risk.
Recon · Why it matters
A folder of policies does not survive an incident.
Compliance work goes wrong when it produces documents nobody uses. Done properly, the work that closes an audit finding is usually the same work that closes a real gap, and the evidence you show an auditor is the output of testing rather than a written assurance that testing happened.
Coverage · What we test
What is in scope.
01
Scope and applicability
Whether NIS2 applies to you, as an essential or important entity, and what that means in practice.
02
Gap analysis
Current state against the required measures: risk management, incident handling, supply chain, and business continuity.
03
Technical validation
We test the controls. A documented control that fails under testing is still a gap, and we report it as one.
04
Governance and reporting
Management accountability, reporting timelines, and the evidence you need ready before you need it.
Execution · How we work
How the engagement runs.
Step 01
Establish what applies
Sector, size and role in the supply chain decide your obligations. We settle that first so nothing is over-engineered.
Step 02
Assess honestly
You get the real position, including where you are already fine. Inflated findings help nobody.
Step 03
Prioritise by risk
The roadmap is ordered by exposure, not by the order the articles happen to appear in.
Step 04
Validate with testing
Where a control is technical, we test it. Evidence beats attestation.
Debrief · What you get
What lands on your desk.
Every engagement ends with something your engineers can act on and your auditors can accept.
- Applicability statement setting out which obligations apply to your entity and why
- Gap register mapped to the specific requirement, with the evidence behind each judgement
- Remediation roadmap ordered by risk, with effort and owner against each item
- Technical evidence from testing the controls, ready to show an auditor
Questions · Straight answers
Common questions.
Are you a certification body?
No. We run the assessment, the technical validation and the remediation work. Formal certification is issued by an accredited body, and we work alongside GRC partners where that is the goal.
How does this relate to ISO 27001?
The control sets overlap heavily. Work done for one usually counts toward the other, and we map findings across both so you are not paying twice.
Need this scoped? Let's talk.
Tell us what you need tested and when. A senior tester reads every request and replies within an hour with scope, timing and price.
Reply within an hour · NDA on request · Scoped by a senior tester, not sales