NIS2 Applicability & Gap Assessment
First establish whether NIS2 binds you at all. Then close the gap.
In plain terms
NIS2 is an EU law forcing organisations in named sectors — energy, transport, manufacturing, digital infrastructure, waste, food, and more — to run real cybersecurity practices, with fines and named management accountability attached. Most companies still do not know whether it applies to them, and applicability is the part that changes the budget by an order of magnitude. We settle that question first, in writing, then assess against the actual duties.
What you get
- A documented applicability determination — essential entity, important entity, or out of scope, with the reasoning
- Assessment against the Article 21 risk-management measures
- Incident reporting readiness against the 24-hour, 72-hour and one-month clocks
- A remediation plan mapped to your national transposition
Who it is for
Any EU-operating organisation in or supplying a NIS2 sector, and anyone who has been told by a customer that they are now in scope.
Tool
Check your scope first
Applicability drives everything else in this engagement. Settle it here in five questions.
Illustrative starting point based on the answers you gave. It is not a legal determination of scope. Confirm applicability with qualified counsel before acting on it.