Privacy · EU member states
EU NIS2 Directive
Essential and important entities in the EU, and the US vendors that serve them, carry management-level cyber duties.
Who it applies to
The businesses that carry NIS2, and the pages written for them.
Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.
Which packages satisfy it
Cyber and Data Protection Assessment
Any business of 10 to 500 people that has never had a real assessment, or has not had one in a year
SOC 2 Readiness: Type 1 and Type 2
SaaS, AI and technology companies of 5 to 300 people, and professional firms whose clients require it
CMMC Level 2 Gap Readiness Package
Defense manufacturers, engineering and design firms, and IT and service suppliers of 10 to 300 people handling CUI
What it asks for
In plain English, what NIS2 expects you to have in place.
- A data mapWhat personal data you collect, why, where it goes and how long you keep it.
- A lawful basis and a noticeA reason for each use and a privacy notice that says so in plain language.
- Rights handlingA process to answer access, correction, deletion and opt-out requests within the required time.
- Security appropriate to the riskTechnical and organizational measures that match the sensitivity of the data.
- Processor and vendor termsContracts that bind the companies processing data on your behalf.
- Breach notificationA tested process to assess a breach and notify the authority and the people affected on the clock the law sets.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.
Questions we get about NIS2
Do you certify NIS2 compliance?
Where do we start with NIS2?
We also need other frameworks. Do we do NIS2 separately?
Also in privacy: GDPR · State privacy · every framework by industry
Next step
Thirty minutes, an engineer, a written scope for NIS2.
Book the demo and see how one control set carries NIS2 and everything else you owe. Or leave your details and an engineer replies within one business day.