attackless
← All services
ATTACKLESS / SERVICE 02

NIS2

Understand whether your organisation is in scope and turn applicable obligations into a working plan.

THE ENGAGEMENT

Five phases, one compliance roadmap

We don't sell a generic checklist. Each engagement moves through the same sequence of phases, in order, so the plan you end up with reflects your actual obligations under the directive — not a template.

01
Start here

Scope assessment

We determine whether NIS2 applies to your organisation at all — sector, size class and any statutory exceptions are checked before anything else, so you're not paying to comply with a law that doesn't reach you.

02
Phase two

Control gap analysis

Where the directive does apply, we map your current technical and organisational measures against its requirements and document exactly where the gaps are.

03
Phase three

Management responsibilities

NIS2 puts accountability on management bodies directly. We document what that means in practice — oversight, approval and training obligations included.

04
Phase four

Incident-reporting workflow

A working process for the directive's early-warning and reporting deadlines — who is notified, when, and with what information — built around your existing incident response.

05
Phase five

Evidence roadmap

A prioritised, dated plan for closing the gaps and documenting compliance — so what you can show a regulator or auditor is decided in advance, not assembled after the fact.

!
Applicability isn't automatic

Sector, size and statutory exceptions determine applicability. The scope assessment in phase one exists precisely because "are we even in scope" is a real question with a real answer — we won't assume the directive applies to you before checking.