Skip to content
ITCVidal

Clarify duties, keep evidence

NIS2: cyber security you can evidence

With Directive (EU) 2022/2555 (NIS2) and its national implementation, the number of companies that have to maintain a demonstrable level of cyber security grows considerably. It is no longer only classic operators of critical facilities that are affected, but also suppliers, service providers and mid-sized companies across a range of sectors.

What is genuinely new is the responsibility of the management level: directors and board members must approve the risk management measures, oversee their implementation and be trained for the task. The work can be delegated; the responsibility cannot.

This includes

  • Scoping analysis: do you fall under the rules as an essential or important entity – and with which sites and legal entities?
  • Building risk management in line with Art. 21 NIS2 (policies, incident and crisis management, backup and recovery, access control, cryptography)
  • Supply chain security: putting requirements for service providers into contracts and verifying them
  • Reporting and registration processes that meet the deadlines set out in the Directive (early warning, notification, final report)
  • Evidence documentation for supervisory authorities, clients and auditors
  • Training and briefing for the management level
  • Dovetailing with existing structures from the GDPR, an ISMS or ISO 27001 instead of building a second parallel world
  • A prioritised action plan stating effort, ownership and deadline

How we work

The first question is whether and to what extent you are affected at all – that assessment is the basis for every further investment. We then compare your current state against the requirements and translate the gaps into an action list sorted by risk and effort. What you get is a sound basis for decisions rather than a collection of prohibitions.

Because data protection and information security largely concern the same processes and the same evidence, we handle both together. Anyone maintaining a record of processing activities has already completed part of the NIS2 documentation – and vice versa.

Let us talk about your project.

A data protection question, NIS2 scoping, a planned use of AI, a hosting migration or an application that does not exist yet – tell us what you need. You will get a personal reply, not a ticket number.