NIS2 Readiness, Measured Against Your Codebase
A fixed-scope assessment: where your software and delivery process actually stand against NIS2, and a remediation plan your engineers can run. Two to four weeks.
NIS2 is transposed law with enforcement underway, and most readiness work sold today ends at a control register — a spreadsheet of obligations with nobody attached to the part where the software changes. This assessment is the engineering half, packaged: we measure your codebase, pipelines and delivery process against what NIS2 actually requires, and hand you a plan sequenced by deadline that your team can execute.
It is deliberately fixed in scope and short. Two to four weeks depending on how many services and pipelines are involved, a defined set of inputs, a defined set of outputs, and no meter left running at the end. If you want help executing the remediation afterwards, that is a separate decision — nothing in the assessment is written to make it necessary.
How the two to four weeks run
Phase 1 — Scope and access
Read access to repositories and CI, an architecture walkthrough from someone who knows the system, and whatever your consultant or counsel has already produced — we build on their obligation analysis rather than re-deriving it.
Phase 2 — Gap analysis
Findings measured against the codebase, not against themes: named repositories, pipelines and services, each with an owner and an effort estimate. Supply chain, release provenance, incident detection and reporting windows, access control, evidence generation.
Phase 3 — Remediation plan and handover
A plan sequenced by regulatory deadline and genuine risk: what must be true by the date, what is urgent regardless, and what can wait. Delivered in writing with a working session for your engineering leads.
Consultant output vs engineering output
Both halves matter. This is the half nobody was selling.
What a compliance consultant gives you
- Which obligations apply to your entity
- A control framework and a register
- A percentage-readiness score
- A recommendation to "engage engineering"
What this assessment gives you
- Gaps located in named repos, pipelines and services
- An owner and an effort estimate per finding
- Evidence generated by the pipeline, not a person
- A 30/60/90 your engineers can actually run
Already have the left column? Good — bring it. We build on your consultant's work rather than re-deriving it, and the assessment gets faster. Read more about how we approach security and compliance engineering.
Common questions
Is this a certification or an audit?
Neither, and we say so plainly. We are the engineering side: we find the gaps in the software and the delivery process and give you the plan to close them. If you need certification or a legal opinion on applicability, you need an auditor or counsel — we work alongside both regularly, and their output makes our assessment faster.
What does it cost?
A fixed fee agreed before we start, based on how many services and pipelines are in scope — not time and materials, and no meter running. Bring an architecture overview to the first call and you will leave with the number.
We already have a consultant’s gap analysis. Is this redundant?
No — it is the other half. A consultant’s analysis tells you which obligations apply and how far you are in policy terms. Ours tells you where the software fails them and what it costs to fix. We take their register as an input and give your engineers something they can put in a sprint.
What do you need from our team?
Read access to the repositories and CI, one architecture walkthrough, and questions answered in batches — your engineers do not babysit us. If parts of the estate are sensitive, we scope around them explicitly rather than pretending we saw everything.
And if the assessment finds a mountain?
Then you will know the mountain’s actual shape, which beats suspecting it. The plan separates configuration-level fixes from genuine engineering quarters — those two piles are rarely the size people fear. If you want us to execute the remediation, we can staff it; if your own team runs it, the plan is written for them.