NIS2 Ready
From applicability to a defensible compliance position, with the governance duties covered.
- Duration
- 8–12 weeks
- Price
- €18,000 to €35,000
- excl. VAT, indicative
Four practices, held by one team.
Services
Six frameworks asking overlapping questions. One evidence base that answers all of them.
Compliance becomes expensive at the moment it fragments. A NIS2 programme run by one team, an ISO 27001 project run by another, a SOC 2 audit answered by a third, and a GDPR register nobody has opened since it was written. The same control gets implemented three times, evidenced three ways, and maintained by nobody.
We work the other way round. One unified control framework, mapped across NIS2, DORA, ISO 27001, SOC 2, GDPR and the AI Act. A control is designed once, implemented once, and its evidence is produced once — then reused by every audit that asks for it. In practice the overlap is around seventy per cent.
The other half of this practice is the calendar. Certificates need maintaining, registers need updating, and regulations change. That work is better done continuously at a known monthly cost than rediscovered eight weeks before a surveillance audit.
NIS2, DORA and the CRA, translated from legal text into a plan with dates and owners.
A short, decisive answer to the question that blocks everything else: which regulations apply to which of your entities, in which member states, and from when.
Assessment against the ten measures of Article 21 and the governance duties of Article 20, followed by a programme that closes the gaps in the order a regulator would expect.
The full DORA scope for financial entities and their ICT providers: ICT risk management, incident classification and reporting, the register of information, and preparation for threat-led penetration testing.
For manufacturers and software vendors placing products on the EU market: security by design, vulnerability handling, SBOM, and the technical documentation the CRA requires you to keep.
The security annexes, assurance plans and audit rights that make your contracts defensible, whether you are the client asking or the supplier answering.
ISO 27001 and SOC 2 run as projects with a date, not as open-ended programmes.
From scoping to the certification audit: statement of applicability, risk treatment, documented information, internal audit and management review, with the certification body chosen early.
The annual cycle that keeps the certificate: internal audit programme, management review, corrective actions and surveillance audit preparation, run without consuming your team.
Trust services criteria selected for what your customers actually ask about, controls designed to be evidenced automatically, and an auditor engaged at the right moment.
Extensions built on an existing ISO 27001 system: cloud controls, personal data in the cloud, a privacy information management system, or business continuity.
Sector and national qualifications prepared with qualified partners, so the scheme-specific requirements are handled by people who hold the qualification themselves.
GDPR and the local laws that apply wherever your data actually sits.
Records of processing that reflect reality, lawful bases that hold, retention actually enforced, and a data subject request process that meets the one-month clock.
A designated DPO with the independence the regulation requires, handling the register, the impact assessments, the requests and the relationship with the supervisory authority.
Impact assessments for the processing that needs one, and design reviews early enough that the answer can still change the architecture.
Transfer mechanisms, impact assessments and local registration duties across the jurisdictions we cover: Tunisia, Morocco, Senegal, Ivory Coast, Brazil (LGPD), Argentina and Colombia.
The AI Act and ISO 42001, applied to the systems you are already deploying.
For each AI system: are you a provider or a deployer, is it prohibited, high risk, limited risk or minimal, and which obligations start on which date.
The full obligation set for high-risk systems: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and conformity assessment.
A management system for AI that carries much of the AI Act evidence with it, built on your existing ISO 27001 system rather than alongside it.
A short, usable policy that says which tools are approved, what may be pasted into them, who reviews the output, and what happens to shadow AI already in use.
One control framework, one evidence base, every audit served from it.
One set of controls mapped across NIS2, DORA, ISO 27001, SOC 2, GDPR and the AI Act, so evidence is produced once and answers every audit that asks for it.
Selection and implementation of a compliance platform — Vanta, Drata, Secureframe or a European alternative — configured around your control framework rather than the vendor's default.
A focused session for directors on what NIS2 and DORA make them personally accountable for, what to ask, and what a good answer sounds like.
Compliance run as a subscription: the calendar, the evidence, the internal audits, the supplier reviews and the regulatory watch, handled continuously instead of in an annual panic.
From applicability to a defensible compliance position, with the governance duties covered.
The four DORA pillars covered, including the register of information ready for submission.
A certification project with a date, a fixed price and a certification body engaged early.
Type I, then the observation window for Type II, with evidence collected automatically.
Every AI system inventoried, classified and dated, with the obligations that follow.
Your compliance obligations run continuously: evidence collected as it is produced, internal audits on schedule, regulatory changes watched, and the audit answered without a scramble.
A designated data protection officer with the independence the GDPR requires, handling the register, impact assessments, data subject requests and the supervisory authority.
One point of contact for regulatory questions across Europe, French-speaking Africa and South America, answered with local partners who practise in that jurisdiction.
Two to four days settles which regulations apply to which entity, from when, and what has to be registered. Everything else is easier to plan afterwards.