NIS2 audit and compliance
Strengthen your cyber security

Supporting organisations towards a secure, digital future: the NIS2 compliance offering

Committing to NIS2

The European NIS2 directive requires many organisations to significantly strengthen their cybersecurity and digital risk governance.
At NETSYSTEM, we support you step by step in your NIS2 audit and compliance, with a tailor-made approach combining cybersecurity, IT risk management, governance and audit.

Your personalised NIS2 quote

Why comply with NIS2?

What is NIS2?

NIS2 (for Network and Information Security 2) is the new European directive on cyber security, which replaces and strengthens the NIS 1 directive of 2016.

Its objective:

To raise the level of cybersecurity in the European Union, by imposing stricter rules on critical organisations.

Who is affected by NIS2?

The NIS2 directive concerns entities operating in 18 specific sectors of activity, themselves broken down into highly critical and critical sub-sectors. The directive also introduces other criteria, notably that of size, so the first entities concerned are essential and important (more than 50 employees, with a turnover in excess of 10 million euros).

Do you have any doubts about whether or not this applies to you?

Contact us, we’ll help you sort it out.

What do I need to do to comply with NIS2?

The entities concerned must:

  • Appoint a cybersecurity manager
  • Implement clear cybersecurity governance (roles, responsibilities, reporting)
  • Map critical assets
  • Perform cyber risk management
  • Have business continuity plans (BCP/BRP)
  • Journal, monitor and detect incidents
  • Report major incidents within 24 hours
  • Raise awareness and train teams
  • Evaluate risks related to service providers and subcontractors

Note that in the event of non-compliance, the entities concerned may be exposed to financial penalties.

What are the key stages in NIS2 compliance?

Here’s what needs to be implemented to aim for compliance (the timescales are given as an indication and can obviously vary depending on the organisation’s cyber maturity):

  • Compliance diagnosis / NIS2 audit
    → 1 to 2 months
  • Definition of an action plan and prioritisation of risks
    → 1 to 2 months
  • Implementation of security measures (governance, systems security, continuity, incident management, supplier security…)
    → 6 to 18 months depending on complexity
  • Document formalisation (policies, procedures, PSSI, charter, BCP, etc.)
    → In parallel, but takes time
  • Training, awareness-raising, and testing
    → Ongoing, but at least 1 to 2 months of initial deployment
  • Verification/Final audit
    → To ensure that everything is in place before a potential audit
How long does it take to become NIS2 compliant?

This depends on the organisation’s initial level of maturity. On average, it takes between 6 and 24 months to achieve full compliance.

For example:

  • A company that is already ISO 27001 or very mature in cybersecurity can be compliant in 6 to 9 months.
  • A company with little structure or little cyber investment will need 12 to 24 months to set up processes, tools, audits, etc.

Our support offer for NIS2 compliance.

A pragmatic, tailor-made ROI approach.

Our digital transformation and cybersecurity consultancy will help you achieve NIS2 compliance, fully integrating security issues into your processes. We offer tailor-made support covering :

Initial diagnosis & maturity assessment

  • Understand your current situation, identify gaps, define applicable obligations.
01

Customised roadmap

  • Prioritise actions, define milestones, structure your action plan.
02

Operational implementation

  • Drafting policies, structuring governance, tools, BCP/ERP, supplier management, risk management, systems security...
03

Checking and maintaining compliance

  • Final audit, recommendations, implementation of monitoring and continuous improvement indicators.
04

Netsystem helped EMERA GROUP comply with NIS2

Emera is a major player in the field of accommodation and services for seniors (nursing homes, EHPAD, senior services residences, etc.) in Europe. At a time of digital transformation in the healthcare and medico-social sector, Emera handles sensitive data (personal, medical, etc.) and relies on critical infrastructures to guarantee continuity of service and the security of its residents.

Faced with the entry into force of the NIS2 directive (Network and Information Systems Directive 2) and the rapid development of cyber threats, Emera wanted to strengthen its regulatory compliance and set up a robust cyber security organisation.

Netsystem is PASSI qualified

The PASSI qualification is issued by the Agence Nationale de Sécurité des Systèmes d’Information (ANSSI).

It is aimed at trusted service providers who carry out organisational and physical security audits, as well as audits of technical scopes, on their own behalf or on behalf of their customers.

It is a real guarantee of quality and expertise for organisations looking for a cybersecurity consultancy to carry out an audit of their structure.

Why choose Netsystem?

  • Cybersecurity & compliance specialist (ISO 27001, PASSI, NIS2, DORA, RGPD, IA Act…)
  • A global vision : cyber, governance, performance and strategy
  • +35 expert consultants, rooted in the field
  • Proven methodology, tailored to SMEs and large organisations alike
  • Options for long-term support (outsourced CISO, testing, auditing…)

At Netsystem, we help our customers to do much more than simply comply with the directive.
The NIS2 directive requires a real transformation of the organisation in terms of cybersecurity: governance, risk management, control of suppliers, continuity plans, etc. It's not just a checklist to fill in, it's a structuring approach that needs to be integrated into the company's overall strategy.

That's where our role comes into its own: we work with our customers to build roadmaps tailored to their level of maturity, with concrete, progressive solutions.
The objective is clear: to make them autonomous, resilient and capable of meeting the cyber challenges of today and tomorrow.

Whether you're starting from scratch or are already well advanced, we can adapt. And above all, we move forward together.

To find out more about cyber security

No posts found!