GOVERNANCE & COMPLIANCE

NIS2
Compliance

Entity classification, gap analysis, and implementation planning for NIS2 obligations — across governance, risk management, supply chain security, and incident reporting.

Practical NIS2 readiness without the consultancy bloat

NIS2 widens the scope of EU cybersecurity regulation to 18 sectors and introduces stricter obligations: documented risk management measures, supply chain security, incident reporting within tight timelines, and personal accountability for management bodies. ShadowCore’s NIS2 service helps organizations confirm whether they qualify as an Essential or Important Entity, identify the controls that need to change, and reach a defensible compliance position.

The engagement starts with scope and entity classification, followed by a structured gap analysis against the directive’s ten risk-management areas. Each gap is paired with a remediation action, an owner, and the evidence the supervisory authority is likely to ask for. Where an ISO 27001 ISMS is already in place, work focuses on the delta between existing controls and NIS2-specific obligations.

NIS2 typically runs alongside other frameworks. See GRC & Compliance for multi-framework coordination, ISO 27001 for a control baseline that satisfies most NIS2 expectations, and Incident Response for the operational capability required by the directive’s reporting obligations.

Engagement snapshot

What a NIS2 engagement includes

Entity classification

Determine whether your organization qualifies as an Essential or Important Entity under NIS2 based on sector, size, and economic role.

  • Essential
  • Important
  • 18 sectors

Gap analysis

Assessment of current controls against NIS2 obligations for risk management, incident handling, business continuity, and supply chain security.

Reporting readiness

Workflows for the 24-hour early warning, 72-hour incident notification, and final report — including evidence trails and decision logs.

  • 24h warning
  • 72h report

Roadmap & accountability

Prioritized implementation plan with owners, evidence requirements, timelines, and management-body briefings for personal-liability obligations.

Capabilities

NIS2 Compliance Services

A practical compliance program built for evidence, accountability, and audit readiness.

NIS2 Gap Analysis

Comprehensive assessment of your current posture against NIS2 requirements with a prioritized remediation roadmap.

Scope & Entity Classification

Determine whether your organization qualifies as an Essential or Important Entity under the directive.

Risk Management Measures

Map current controls against NIS2 obligations for incident handling, business continuity, and supply chain security.

Management Accountability

Prepare leadership for governance duties, approval workflows, evidence trails, and supervisory expectations.

Incident Reporting Readiness

Build the processes required for 24-hour early warnings, 72-hour notifications, and final incident reporting.

Remediation Roadmap

Prioritized implementation plan with owners, evidence requirements, timelines, and audit-ready deliverables.

Interactive Tool

NIS2 Entity Check

Determine if your organization falls under NIS2 as an Essential or Important Entity.

Comparison

NIS1 vs NIS2

Key changes and escalated requirements under the NIS2 directive.

Aspect NIS1 NIS2
Scope OES + DSP (limited sectors) Essential + Important Entities (18 sectors)
Fines Member state defined EUR 10M or 2% worldwide turnover (Essential)
Management Liability No personal liability Personal liability for management bodies
Incident Reporting Undue delay 24h early warning, 72h full report
Supply Chain Not addressed Mandatory supply chain risk management
Enforcement Reactive Proactive audits + on-site inspections
Who it is for

When NIS2 applies — and where to start

  • Entities newly in scope of NIS2 across the 18 sectors that need to confirm their classification and obligations.
  • Organizations already certified to ISO 27001 that need to extend their program to meet NIS2-specific requirements.
  • Companies with EU operations or supply-chain exposure to Essential or Important Entities required to demonstrate security maturity.
  • Management bodies preparing for personal accountability obligations introduced under the directive.
Typical outcomes

What the engagement leaves you with

  • A documented entity classification, scope statement, and obligation map under NIS2.
  • A gap analysis against risk management, incident handling, business continuity, and supply chain requirements.
  • Incident reporting workflows aligned to the 24-hour early warning, 72-hour notification, and final report timelines.
  • A prioritized remediation roadmap with owners, evidence, and management-body briefings ready for supervisory review.

Start your NIS2 roadmap

Free initial consultation. We'll assess your current posture and map a remediation plan.

Contact Us