NIS2
Readiness
NIS2 put cybersecurity obligations on essential and important entities across the EU, made management personally accountable, and attached a 24-hour reporting clock. We run readiness so your risk-management measures and reporting process satisfy Article 21 and Article 23 before a supervisory authority asks.
Who this is for
Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.
Essential and important entities in the sectors NIS2 covers, across any member state
Companies who supply those entities and are being pushed obligations through the supply chain
Organisations whose management body needs to demonstrate it approved and oversees the measures
Teams who need the 24-hour and 72-hour reporting process to exist before an incident
What the engagement does
Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.
- Confirm whether you are in scope, as essential or important, and in which member states
- Assess your position against the Article 21(2) measures, all ten of them
- Establish management body approval, oversight and training - the accountability NIS2 made personal
- Build the incident reporting process against the 24-hour, 72-hour and one-month obligations
- Address supply chain security, which NIS2 treats as a first-class obligation rather than a clause
- Prepare the evidence a supervisory authority would ask to inspect
What you walk away with
A documented position against every Article 21 measure, a management body that has demonstrably approved and overseen it, and a reporting process that can meet a 24-hour clock. Because NIS2 penalties can attach to management personally, the governance evidence matters as much as the technical controls.
How it runs
Four phases. You always know which one you are in and what is outstanding.
Scoping call
We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.
Assessment
We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.
Remediate and evidence
We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.
Hand off to your assessor
You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.
What the assessment covers
The control areas we walk for NIS2. Each breaks down into individual controls carrying status, owner and evidence in Talon.
NIS2 is supervised by national competent authorities, not certified. Supervision can include inspections and audits. Readiness prepares you for that, and for the questions your customers in scope will pass down to you.
It runs in Talon, not in a spreadsheet
Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.
- Control-by-control status, kept current by the people doing the work
- Evidence filed against the control it satisfies, with expiry dates tracked
- The auditor request list, so nothing is chased over email
- A readiness view that shows what an assessor would see
Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.
Our partnersAsked on almost every NIS2 call
NIS2 covers defined sectors above size thresholds, with member state variation in how it was transposed. Being out of direct scope does not mean being unaffected - entities in scope are required to manage supply chain risk, which lands on their suppliers.
An early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month. The early warning is short, but it has to happen - which means somebody must be able to decide "this is significant" quickly.
NIS2 requires management bodies to approve the measures and oversee implementation, and provides for accountability where they fail to. Documented approval and training is not a formality here.
It covers much of Article 21 but not all of it, and it does not address the reporting obligations or the governance accountability. An existing ISMS is a strong starting position, not a complete answer.
Rarely run alone
Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.
NIS2 readiness, on your timeline
A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.