EU cybersecurity

Turn EU cyber obligations into an accountable program.

The NIS2 Directive expands and strengthens cybersecurity risk management and reporting obligations for covered entities in the EU. Applicability depends on sector, size, national implementation, and other facts. We help establish the right scope and operational response.

Our implementation focus

Make the requirements operational.

  1. 01

    Assess applicability with legal and sector input

  2. 02

    Map governance and cybersecurity risk measures

  3. 03

    Strengthen incident handling and escalation

  4. 04

    Address supply chain and supplier security

  5. 05

    Build evidence and management oversight

Independent assessment

National implementing rules vary. Regulatory interpretation should be reviewed with qualified legal counsel.

Questions we hear

Get the distinctions right.

Is NIS2 the same as NIST CSF 2.0?

No. NIS2 is an EU directive implemented through national law. NIST CSF 2.0 is a voluntary cybersecurity risk framework. The framework can help organize work, but it does not determine legal applicability or compliance.

Does ISO/IEC 27001 certification prove NIS2 compliance?

No. An ISMS can support risk management and evidence, but NIS2 obligations depend on the entity, sector, and national implementing law. Evaluate the remaining duties explicitly.

Should every supplier claim to be NIS2 compliant?

No. First establish whether the supplier is directly in scope, affected through customer contracts, or both. Describe the specific controls and evidence available instead of making a blanket claim.

Work with Normstone

Build a defensible path to readiness.

Tell us the outcome you need and the markets involved. We’ll help define the work.

Start a conversation