Cybersecurity governance

NIS2 Readiness & Cyber Resilience

Management-focused readiness assessments that connect NIS2 obligations with risk governance, incident response, supply-chain assurance and ISO 27001 controls.

Directive (EU) 2022/2555ISO/IEC 27001:2022ENISA guidance

Scope of support

What the engagement can cover.

Scope is tailored to the certification basis, current lifecycle state and evidence already available.

  1. 01

    Entity and scope assessment

  2. 02

    Article 21 measure mapping

  3. 03

    Incident reporting workflow

  4. 04

    Supply-chain security review

  5. 05

    Management accountability briefing

  6. 06

    ISO 27001 crosswalk and evidence plan

Typical outputs

Applicability memoGap registerRemediation roadmapEvidence crosswalk

Training & working sessions

From standard text
to project decisions.

Modules combine standards context with the documents, reviews and evidence choices teams make during delivery.

Phase 01

Applicability

Entity type, sector, jurisdiction and national transposition context.

Phase 02

Risk measures

Governance, technical controls and supply-chain obligations.

Phase 03

Incident reporting

Escalation, evidence and reporting timeline design.

Phase 04

Assurance

Management review, test plan and traceable remediation evidence.

Instructor assignments and any claimed program history are provided only after internal approval and verification.

Engagement scoping

Information that makes the first review useful.

No compliance outcome is promised from a website form. Scope begins with the program facts and evidence that can actually be reviewed.

01

Applicable basis

Standard revision, authority or customer basis, assurance level and agreed means of compliance.

02

Lifecycle state

Current milestone, approved plans, baselines, open findings and target review date.

03

Requested boundary

Training, gap analysis, document review, evidence recovery or audit-readiness support.

FAQ

Questions before the first workshop.

Is NIS2 the same in every EU country?+

No. NIS2 is an EU directive implemented through national law. Scope, supervision and procedures must be checked against the applicable member-state rules.

Does ISO 27001 automatically prove NIS2 compliance?+

No. ISO 27001 can supply strong management-system evidence, but legal scope, reporting, accountability and sector obligations require a dedicated assessment.

Start with a technical conversation

Make your NIS2 evidence easier to defend.

Tell us the standard, lifecycle stage and evidence challenge. We will help frame a focused next step.

info@heraklet.com ↗

We use your details only to respond to this request.