NIS2 Directive · EU Compliance · Critical Infrastructure

NIS2 Compliance Consulting for Organisations

NIS2 is not a documentation exercise. It asks for named accountability, measures that actually get implemented, and evidence that survives scrutiny. That is the path supported here — from the gap analysis through to the report that reaches your board.


First, a boundary: whether NIS2 applies to your organisation is a legal question — one for your legal advisers, not for this page. The work here starts after that: with what actually needs doing.

  1. NIS2 Gap Analysis

    A structured comparison of where you stand against NIS2 and the relevant standards. Every gap is assessed: how much it matters, what closing it costs, and what happens if it stays open.

    Substantial gains in maturity within months are achievable (e.g. from 1.45 to 3.09 in eight months). How fast depends on the starting point, available resources and the involvement of the organisation.

  2. Accountability and Governance

    NIS2 places explicit duties on management. That calls for named roles, clear escalation paths and decisions recorded so they can be traced — not a policy nobody has read.

    • Defining roles and responsibilities for information security
    • Translating requirements into processes and IT services, with owners and dates
  3. Defining the Measures

    The gaps become a plan that can be worked through: prioritised by risk, with owners, dates and a recognisable target state. Risk decides what comes first — not the order of the articles in the directive.

  4. Documentation: Policies and Standards

    Writing and developing security policies, building the surrounding framework, lifting existing documents to what NIS2 expects. A policy is not an end in itself: it has to describe what people actually do, or it falls over in the first audit.

    • Security policies and guidelines
    • The wider framework and the process descriptions that go with it
    • Service Provider Security Policy and a standardised checklist for assessing provider contracts
  5. Implementation

    The point where most compliance programmes stall. This is where the project-management side earns its place: steering the work, coordinating the business areas and service providers involved, and keeping at it until things are done.

    • Coordination of rollout and onboarding of security tooling through external service providers
    • Risk and quality management
    • Stakeholder and service-provider management
    • Supply chain security: reviewing provider contracts against defined security requirements
  6. Follow-up on Agreed Measures

    A remediation plan nobody follows up is a list of good intentions. Every agreed measure is tracked until it is genuinely implemented — with regular review, escalation when things slip, and a status that is actually true.

  7. Evidence and Audit Preparation

    What is not evidenced did not happen, as far as an audit is concerned. So the documentation grows alongside the work: records, minutes and proof — prepared and findable, not scattered across four shared drives.

    This includes preparation for external audits and coordination while they run.

  8. Management Reporting

    Leadership carries the liability and therefore needs to know where the organisation stands. Regular reporting makes progress, open risk and pending decisions visible — in a form that works in a board meeting, not only inside the IT department.

  9. NIS2 Awareness and Training

    NIS2 requires cyber-security training, explicitly including the management body. The security awareness training is therefore part of the programme rather than an appendix — with content matched to your actual risks, and attendance records that stand up as evidence.

    More on security awareness training for staff

Scope of the service

Compliance consulting is offered exclusively for organisations operating in the EU and UK markets. Particular experience includes healthcare, the public sector and critical infrastructure.

NIS2 overlaps heavily with ISO 27001 and BSI IT-Grundschutz. Work already done there is not wasted — see Cyber Security.

Rebel PM International does not provide legal advice and does not act as a certification body. Whether NIS2 applies to you is a question for your lawyers. What follows from it, and how it gets implemented, is the work here.