Skip to content

Home Expertise / Risk & governance

GRC / GRC-04

NIS 2 readiness and security improvement plan

Support to assess potential NIS 2 applicability and develop relevant technical, organisational and evidence-based security measures.

WHEN IT HELPS

A focused response
to a defined need.

Executives, legal teams or CISO; a potentially in-scope entity or supplier receiving customer security requirements.

AT A GLANCE

Family
Risk & governance

Engagement
Advisory

Reference
GRC-04

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Scope applicability with legal counsel
  • gap analysis
  • governance, incidents, continuity, suppliers and treatment planning

Deliverables

  • Scope and assumptions note
  • requirements-to-evidence matrix
  • roadmap and tracking pack

Acceptance evidence

Each selected requirement has an applicable source, an owner, expected evidence and an action.

DELIVERY

How the work is structured.

Approach

Scope context; engage business owners and decision-makers; assess risks or gaps; decide controls; organise follow-up and evidence.

Prerequisites & responsibilities

Customer: sponsor, available business owners, risk decisions and legal advice where needed. Provider: methodology, facilitation, analysis and decision file.

Scope factors

Entities, processes, stakeholders, regulatory scope, document maturity and workshops. Project, periodic support or fractional CISO depending on need.

Questions to clarify

Which countries and activities? What size and group structure? Which sectoral or contractual obligations also apply?

IMPORTANT BOUNDARIES

The applicable national framework and the entity’s position are assessed at the time of engagement. Readiness support does not issue a NIS 2 certification or a legal guarantee of compliance.

The work supports decisions and evidence for the agreed framework. Legal advice, independent certification and the decisions of regulators or assessors remain separate responsibilities.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

An IT provider receives NIS 2 questions from several customers. Project: assess its own status and contractual commitments. Target outcome: a reusable evidence baseline and consistent answers without assuming applicability prematurely.

Scenario 02

A European group operates in several countries. Project: map activities and national frameworks. Target outcome: a shared programme with local additions; one French guidance page is not treated as a Europe-wide conclusion.

Technology and reference context

ANSSI publications and applicable EU and national rules; record the framework version in the file.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.