NIS2 · Directive (EU) 2022/2555

Meet the NIS2 risk management measures

We confirm whether you are an essential or important entity, assess you against the ten Article 21 measures and test that you can meet the Article 23 reporting deadlines.

Book a NIS2 assessmentSee a sample report
LegislationDirective (EU) 2022/2555
Enforced byNational competent authorities in each member state
Structure10 Article 21 measures
Suited toMedium and large entities in 18 critical sectors
01 · The framework

Article 21 measures

Entities must take appropriate and proportionate technical, operational and organisational measures. Management bodies must approve them and can be held liable.

aRisk analysis and information system security policies
bIncident handling
cBusiness continuity, backup, disaster recovery and crisis management
dSupply chain security
eSecurity in acquisition, development and maintenance, including vulnerability handling
fAssessing the effectiveness of security measures
gBasic cyber hygiene and training
hCryptography and encryption
iHR security, access control and asset management
jMulti-factor authentication and secured communications
02 · Reporting

Article 23 reporting

Significant incidents follow staged deadlines. We test your process against each one.

24 hoursEarly warningNotify the CSIRT or authority that a significant incident has occurred.
72 hoursIncident notificationAn initial assessment of severity, impact and indicators of compromise.
1 monthFinal reportA detailed description, root cause, mitigation applied and cross-border impact.
03 · How we assess

Evidence first, interviews second

Every rating is backed by evidence from your environment, so the result reflects what is running, not what the policy says. A baseline typically takes two weeks.

  1. 01ScopeAgree the target, the systems in scope and who we need to speak to.
  2. 02CollectInterviews, document review and live data from Pulse and Trace.
  3. 03ScoreRate every requirement against your target, with evidence for each rating.
  4. 04ReportA prioritised roadmap and a short board briefing.
04 · What you receive

A result you can act on

Findings map across frameworks, so work done for NIS2 counts towards the others you hold.

✓Scored gap analysisStatus for every requirement against your target, backed by evidence.
✓Prioritised roadmapP1 to P3 work packages with owners, dates and exit criteria.
✓Board briefingA short summary of where you stand and the decisions needed.
✓Evidence kept currentResults live in Attest and update as your environment changes.
Often assessed together
NCSC Cyber Assessment Framework ISO/IEC 27001:2022 GDPR and UK GDPR

Know where you stand against NIS2 in two weeks

A baseline assessment with a prioritised roadmap and a board-ready summary.

Book a NIS2 assessment