NIS2 Ready
From applicability to a defensible compliance position, with the governance duties covered.
- Duration
- 8–12 weeks
- Price
- €18,000 to €35,000
- excl. VAT, indicative
AI & Cybersecurity
Deploy AI you can defend, and defend with AI.
Legal

Services
Prove it once. Use the proof everywhere.
Compliance becomes expensive at the moment it fragments. A NIS2 programme run by one team, an ISO 27001 project run by another, a SOC 2 audit answered by a third, and a GDPR register nobody has opened since it was written. The same control gets implemented three times, evidenced three ways, and maintained by nobody.
We work the other way round. One unified control framework, mapped across NIS2, DORA, ISO 27001, SOC 2, GDPR and the AI Act. A control is designed once, implemented once, and its evidence is produced once — then reused by every audit that asks for it. In practice the overlap is around seventy per cent.
The other half of this practice is the calendar. Certificates need maintaining, registers need updating, and regulations change. That work is better done continuously at a known monthly cost than rediscovered eight weeks before a surveillance audit.
Where you stand — against a standard, a regulation, a risk model or an authorisation scheme — before anyone commits to a programme.
A structured review of your security organisation, controls and practices against ISO 27001 or NIST CSF, scored by domain and ranked by exposure.
A short, decisive answer to the question that blocks everything else: which regulations apply to which of your entities, in which member states, and from when.
Where you stand against a named standard — ISO 27001, 27701, 22301 or 42001 — clause by clause, before you commit to certification.
A risk analysis built on your real business scenarios: what an attacker would want, the paths available, and the treatment decisions that follow.
The evidence pack and gap review for a system that needs a formal authorisation to operate — public-sector, health or critical-infrastructure schemes included.
NIS2, DORA and the CRA, translated from legal text into a plan with dates and owners.
Assessment against the ten measures of Article 21 and the governance duties of Article 20, followed by a programme that closes the gaps in the order a regulator would expect.
The full DORA scope for financial entities and their ICT providers: ICT risk management, incident classification and reporting, the register of information, and preparation for threat-led penetration testing.
For manufacturers and software vendors placing products on the EU market: security by design, vulnerability handling, SBOM, and the technical documentation the CRA requires you to keep.
The security annexes, assurance plans and audit rights that make your contracts defensible, whether you are the client asking or the supplier answering.
ISO 27001, 27701, 22301 and 42001, SOC 2, SWIFT CSP and the sector schemes, taken through to the certificate or the attestation.
From scoping to the certification audit: statement of applicability, risk treatment, documented information, internal audit and management review, with the certification body chosen early.
The annual cycle that keeps the certificate: internal audit programme, management review, corrective actions and surveillance audit preparation, run without consuming your team.
A business continuity management system built to the standard and taken through certification: analysis, strategies, plans, exercises, audit.
Extensions built on an existing ISO 27001 system: cloud controls, personal data in the cloud, a privacy information management system, or business continuity.
Trust services criteria selected for what your customers actually ask about, controls designed to be evidenced automatically, and an auditor engaged at the right moment.
The annual Customer Security Programme attestation: control assessment against the current CSCF, remediation, and the independent assessment SWIFT requires.
Sector and national qualifications prepared with qualified partners, so the scheme-specific requirements are handled by people who hold the qualification themselves.
The legal reading of your security and data obligations — contracts, sector rules, cross-border transfers — with counsel we work with, turned into a register you can maintain.
GDPR and the local laws that apply wherever your data actually sits.
Records of processing that reflect reality, lawful bases that hold, retention actually enforced, and a data subject request process that meets the one-month clock.
A designated DPO with the independence the regulation requires, handling the register, the impact assessments, the requests and the relationship with the supervisory authority.
Impact assessments for the processing that needs one, and design reviews early enough that the answer can still change the architecture.
Transfer mechanisms, impact assessments and local registration duties across the jurisdictions we cover: Tunisia, Morocco, Senegal, Ivory Coast, Brazil (LGPD), Argentina and Colombia.
The AI Act and ISO 42001, applied to the systems you are already deploying.
For each AI system: are you a provider or a deployer, is it prohibited, high risk, limited risk or minimal, and which obligations start on which date.
The full obligation set for high-risk systems: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and conformity assessment.
A management system for AI that carries much of the AI Act evidence with it, built on your existing ISO 27001 system rather than alongside it.
A short, usable policy that says which tools are approved, what may be pasted into them, who reviews the output, and what happens to shadow AI already in use.
Policies, continuity plans, data classification, a virtual CISO or DPO, and the committee that keeps the risk register honest.
An information security policy set your teams can actually follow, mapped to the frameworks you answer to, with the approval and review cycle already defined.
Business impact analysis, continuity strategy and a recovery plan that has been tested, not just written, with the cyber scenario treated as a first-class case.
A classification scheme your staff can apply without a lawyer, the labels wired into Microsoft Purview or its equivalent, and the handling rules that follow from each level.
A senior specialist at a fixed number of days a month who carries the security function, the data-protection function, or both, and answers for them to your board and your regulator.
The security committee run for you: agenda, risk register kept current, decisions recorded, actions chased, and the quarterly report your board reads.
One set of controls mapped across NIS2, DORA, ISO 27001, SOC 2, GDPR and the AI Act, so evidence is produced once and answers every audit that asks for it.
Selection and implementation of a compliance platform — Vanta, Drata, Secureframe or a European alternative — configured around your control framework rather than the vendor's default.
Compliance run as a subscription: the calendar, the evidence, the internal audits, the supplier reviews and the regulatory watch, handled continuously instead of in an annual panic.
What you hold, what it is worth, who you depend on, and what would hurt if it fell.
Supplier risk handled as a process rather than a spreadsheet: tiering, due diligence, contractual security clauses and the evidence NIS2 and DORA expect you to hold.
The evidence an insurer or an acquirer will ask for, gathered and challenged before they ask, so the premium or the valuation reflects your real posture.
From applicability to a defensible compliance position, with the governance duties covered.
The four DORA pillars covered, including the register of information ready for submission.
A certification project with a date, a fixed price and a certification body engaged early.
Type I, then the observation window for Type II, with evidence collected automatically.
What you are buying, in security terms, in time for it to affect the price.
Your compliance obligations run continuously: evidence collected as it is produced, internal audits on schedule, regulatory changes watched, and the audit answered without a scramble.
A designated data protection officer with the independence the GDPR requires, handling the register, impact assessments, data subject requests and the supervisory authority.
One point of contact for regulatory questions across Europe, French-speaking Africa and South America, answered with local partners who practise in that jurisdiction.
A senior security leader on your management team for a defined number of days each month: strategy, board reporting, supplier reviews, incident decisions and the compliance calendar.
Two to four days settles which regulations apply to which entity, from when, and what has to be registered. Everything else is easier to plan afterwards.