What NIS 2 involves
The NIS 2 Directive does not ask for a set of documents, but for a security programme that works and can be demonstrated. The main obligations of essential and important entities are the following.
Classification and registration
Establishing the status of essential or important entity and registering with the National Cyber Security Directorate (DNSC).
Technical and organisational measures
Multi-factor authentication, endpoint protection, backups, encryption, access control and the other controls required by law.
Periodic audit
A security audit carried out by a DNSC-accredited auditor, concluded with a formal report.
Incident reporting
Notifying DNSC in stages: early warning within 24 hours, notification within 72 hours and a final report within 30 days of detection.
Supply chain
Assessing supplier risks and including security clauses in contracts.
Management accountability
Management approves the measures and is accountable for their application, and security training becomes mandatory.
Consultancy: building compliance
We work alongside the organisation from the initial assessment to maintaining compliance over time.
Gap analysis and initial assessment
We assess the current situation against NIS 2 requirements and deliver a compliance plan with priorities and deadlines.
Implementing the measures
We implement the missing technical and organisational controls, with technologies from our partner portfolio.
Policies, procedures and documentation
We draft the security policies, incident response procedures and documentation required by law, adapted to the organisation.
Maintaining compliance
We monitor, report and update the measures as legislation and the organisation evolve.
Independent audit
The audit is an activity distinct from consultancy. We carry it out as a DNSC-accredited auditor, separately from implementation projects, to preserve the objectivity and the separation of roles required by the regulatory framework.
Cybersecurity audit
We assess actual compliance, technical and organisational, against NIS 2 requirements, as an accredited third party.
Formal compliance report
We deliver the audit report, with the documented level of compliance and the supporting evidence.
Recommendations and remediation plan
We prioritise non-conformities and indicate the remediation steps, which your team or a supplier of your choice can implement.
Where do you stand with NIS 2?
We offer an initial assessment, free of charge, so that you clearly understand the current situation and the next steps.