Compliance: GDPR & NIS2

NIS2 is landing on EU businesses now. From light-touch 'are we compliant?' advisory through to a full readiness review. A service worth paying a premium to get right.

When you need this

Sound familiar?

  • The NIS2 letter has arrived, and nobody is sure whether it even applies to you.
  • GDPR compliance is a folder from 2018 that nobody has opened since.
  • A big client sent a security questionnaire you could not answer honestly.
  • Management heard about personal liability and suddenly has questions.

Why it matters

With NIS2, 'we think we're fine' is no longer a defence. And executives are personally on the hook. Knowing where you stand is far cheaper than finding out the hard way.

How it works

The service, explained.

Know where you stand against GDPR and NIS2

We assess your current posture and rank the gaps by risk and by the effort to close them. NIS2 is landing on EU businesses now, and it carries personal accountability for leadership, so guessing is no longer a safe option.

Light advisory or a full readiness review

Some clients want a quick read on whether they are broadly compliant, others need a documented readiness review that holds up if a regulator asks. We scope to whichever you need and leave you with evidence you can point to.

What you get

What's included

  • Where you stand against GDPR and NIS2 today
  • Gaps ranked by risk and effort to close
  • Light advisory or a full readiness review
  • Documentation that holds up if you're ever asked

The process

The flow, end to end.

Step 1
Scope
Which rules actually apply to you: GDPR always, NIS2 depending on sector and size.
Step 2
Assess
Your current state against the requirements, gap by gap.
Step 3
Rank
Gaps ordered by risk, and by the effort to close them.
Step 4
Evidence
Documentation that stands up when someone official asks.

Pricing

from €1,900 one-time

Net, plus 19% VAT.

See full pricing

FAQ

Common questions.

Does NIS2 even apply to us?

That is the first question the work answers, and for many mid-sized companies it is genuinely unclear: sector, size, and supply-chain position all matter. If it does not apply, you get that in writing and can stop worrying.

Are you lawyers?

No, and the work reflects that honestly: we cover the technical and organizational side, the controls, the evidence, the reality of your systems. Where a question is purely legal, we say so and point to where a lawyer belongs.

What is the difference between the light and the full version?

The light advisory answers where you roughly stand, in a short engagement. The full readiness review documents every requirement, your evidence for it, and the plan for the gaps. That is the version you want if an authority or a large client asks.

Our IT provider says everything is fine. Is it?

Maybe, but a self-assessment by the party that built the systems is exactly what reviews exist to check. An independent look either confirms it, which is valuable, or finds what politeness was covering.

Book a free infrastructure assessment.

A no-commitment look at your setup. What's healthy, what's at risk, and what to fix first. Real answers, no pressure.