NIS2 & Cybersecurity Act

    NIS2 asks for evidence, not a plan

    NIS2 asks the same thing across Europe: proof that your security measures actually work, not just a policy that says they should.

    We deliver that technical proof. A manual pentest, retest included, and an audit-ready report your regulator or your largest client can use directly. Whichever country you operate in and whichever framework applies.

    NIS2 Directive Overview
    ScopeEU-WIDE
    18
    Sectors
    €10M
    Max Fine
    Applies to essential and important entities across critical infrastructure sectors

    Key NIS2 Requirements

    Risk Management

    Implement clear and structured measures to identify, assess, and manage cyber risks across your organisation.

    Incident Reporting

    Report significant security incidents to the relevant authorities within the required 24 to 72-hour timeframe.

    Supply Chain Security

    Identify and manage cybersecurity risks introduced by suppliers, service providers, and partners.

    Continuous Monitoring

    Continuously monitor systems and environments to detect threats and suspicious activity in a timely manner.

    Access Control

    Enforce strong authentication and manage user accounts, roles, and access rights properly.

    Documentation

    Maintain clear policies, procedures, and evidence to demonstrate compliance and support audits.

    What We Cover

    We do not run a full NIS2 programme. Your ISMS, your incident reporting procedure and your supplier policy stay with your own team or your compliance partner. We deliver the technical and human evidence that file needs.

    Manual pentest with audit-ready report and retest
    Continuous testing through RedSOC PTaaS
    Red team exercise on detection and response
    Phishing, vishing, smishing and mystery guest
    Security awareness, board sessions included
    Risk assessment, policy advice and maturity scan
    Evidence
    What goes into your NIS2 file

    One signed report from an independent tester: scope, method, findings and retest. That is what your auditor wants to see under Article 21.

    100%
    Manually tested
    €0
    For the retest

    Frequently Asked Questions

    NIS2 applies to essential and important entities across 18 sectors operating in the EU. Essential entities include operators in energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. Important entities include postal services, waste management, manufacturing of critical products, food, chemicals, and digital services. Size thresholds also apply: medium-sized companies (50 or more employees or over €10M turnover) in covered sectors generally fall in scope. We do not formally determine whether you are in scope; that judgement sits with your regulator or your legal advisor. What we do is translate it into a testing scope: which systems, which frequency, which evidence.

    NIS2 Article 34 sets a two-tier fine structure. Essential entities face fines up to €10 million or 2% of global annual turnover, whichever is higher. Important entities face fines up to €7 million or 1.4% of global annual turnover, whichever is higher. In addition to financial penalties, supervisory authorities can order binding instructions, temporary management bans, and require organizations to notify affected parties.

    NIS2 Article 23 requires a three-stage process. Within 24 hours of awareness: an early warning to your national CSIRT or competent authority confirming the incident and whether a cyberattack is suspected. Within 72 hours: a formal incident notification with severity assessment, affected systems, and estimated impact. Within one month: a final report including root cause, measures taken, and any cross-border implications. We do not build that reporting chain for you; it stays with your own organisation. What we do is test whether it works: a red team exercise shows whether an attack is actually detected and escalated within the window NIS2 expects.

    Yes. NIS2 Article 20 holds management bodies directly accountable for cybersecurity compliance. Board members must approve the organization's cybersecurity risk management measures and actively oversee their implementation. In cases of serious violations, national authorities can temporarily prohibit specific individuals from exercising management functions. Article 20 also requires training for board members. Our security awareness session for management and the board is built for that requirement.

    In Belgium, the Centre for Cybersecurity Belgium (CCB) is the national competent authority for most sectors under NIS2. In the Netherlands, the NCSC (Nationaal Cyber Security Centrum) coordinates national oversight, but sector-specific supervisors also have authority: for example, DNB for financial institutions and the RDI for digital infrastructure. Whichever supervisor applies, under Article 21 they ask for the same thing: documented evidence that your measures were tested by an independent party. Our report is built for that question.

    A full NIS2 trajectory runs over months and touches your policies, your processes and your supply chain. The technical test is a defined part of it that can start independently. Lead time depends on scope: the number of applications, networks and environments you have tested. We set that scope during intake, together with the planning. If you are tight on time for an audit or a client request, a rapid response pentest exists.

    NIS2 article 21 requires proportional, documented testing of the effectiveness of security measures, but does not specify a fixed frequency or method. Continuous testing platforms are one valid approach, periodic pentesting is another, and many organisations combine both. What matters to a NIS2 auditor is documented evidence of effectiveness with named accountability, not the technology you used. A signed pentest report from an independent tester is widely accepted; an automated dashboard alone usually is not.

    No. We are not a compliance firm and we do not take over your NIS2 programme. Our role is the evidence: manual pentests with an audit-ready report and retest, continuous testing through RedSOC, red team exercises, social engineering, and security awareness training including the session for management and the board. Our consultancy services add risk assessment, policy advice and a maturity measurement. Your ISMS, your incident reporting procedure and your supplier policy stay with your own team or your compliance partner. We work alongside them without friction.

    Turn NIS2 pressure into audit-ready proof

    A manual pentest with a report and free retest you can put straight into your NIS2 file.