CyberSec42
NIS2 Readiness

NIS2, prepared down to the demonstrable proof.

CyberSec42

NIS2 readiness means putting your security posture in a state where every obligation in the directive meets a concrete piece of evidence. We determine whether you are in scope, analyse the gaps against the NIS2 requirements, implement the technical and organisational measures and accompany you with an examinable evidence package up to the accredited body. Proof instead of checkmarks.

Why now

The effort lies in the proof, not in the intention.

NIS2 requires demonstrable risk management, short reporting lines and accountability at management level. The individual measure is rarely the problem. What becomes difficult is the robust proof that all requirements together are met and effective, and that a significant incident can be detected and reported within the required windows. That is exactly where we focus the readiness.

At the end you hold in your hands:
  • a documented determination of whether you are in scope and which obligations apply,
  • a gap analysis with gaps prioritised by risk and effort,
  • implemented measures with a piece of evidence per requirement,
  • an established reporting process for the 24 and 72 hour windows,
  • an evidence package that stands up to examination.
What is included

What NIS2 readiness contains.

Scope

Scope and obligations

We clarify whether and as which category of entity you fall under NIS2, including requirements that customers pass down through the supply chain.

Gap analysis

Current against target

Your current state is compared against the required measures, and the gaps are prioritised by risk and effort.

Measures

Technical and organisational

From access control and multi-factor through backup and business continuity to vulnerability and supply chain management, implemented or hardened.

Reporting

Detection and escalation

A process that detects significant incidents in good time and makes the 24 hour early notification and the 72 hour report realistically achievable.

Evidence

Proof per requirement

Every obligation is mapped to a concrete piece of evidence, so your state is examinable at any time and not merely asserted.

Governance

Roles and management

Responsibilities, reporting lines and the involvement of management, as NIS2 holds them accountable.

How it works

From the gap to examinable evidence.

Step 1

Scoping and gap analysis

We determine whether you are in scope and assess your state against the relevant NIS2 obligations, with a prioritised list of gaps.

Step 2

Measures and evidence

We implement or harden the controls, set up the reporting lines and map every requirement to a piece of evidence.

Step 3

Support up to examination

We prepare the evidence package, accompany the path to the accredited body and keep the evidence current afterwards.

Why CyberSec42

Evidence that stands up to examination.

The honest boundary. CyberSec42 is not an accredited certification body and does not provide legal advice. We prepare, implement, collect evidence and accompany you up to the accredited body. The attestation is issued by the accredited body, and the binding legal interpretation of NIS2 is the responsibility of your legal counsel. This is guidance, not legal advice.

Frequently asked

NIS2 readiness, briefly explained.

What does NIS2 readiness mean?

NIS2 readiness means putting your security posture in a state where every obligation in the directive meets a concrete piece of evidence. It covers determining whether you are in scope, a gap analysis, the implementation of measures, a working reporting process and an examinable evidence package.

Does CyberSec42 certify against NIS2?

No. CyberSec42 prepares you for the NIS2 requirements, implements measures, collects evidence and accompanies you up to the accredited body. CyberSec42 is not itself an accredited certification body and does not provide legal advice.

How long does a NIS2 readiness take?

That depends on size, sector and maturity. Scoping and gap analysis give a clear picture early on, after which the duration follows from the number and depth of the gaps to be closed. In a first conversation we scope it for your case.

What does the gap analysis deliver, concretely?

It compares your current state with the required NIS2 measures and produces a prioritised list of gaps by risk and effort. That makes clear what to do and in what order, before measures and evidence follow.

Does the readiness also help with supply chain requirements?

Yes. Many companies inherit the requirements through their customers' clauses without being directly in scope themselves. The examinable evidence package can equally be used to provide such proof to customers and procurement teams.

Know where you stand with NIS2.

In a first conversation we assess whether you are in scope and show what is still missing before you are examinable. After that you have a clear plan with evidence.

Request a readiness conversation

CyberSec42 is an independent technical security partner, not an accredited certification body and not a provider of legal advice.