Company details
Menu
WFH Labs / NIS2 technical preparation

Turn NIS2 requirements into work your IT team can carry out.

NIS2 is an EU cybersecurity directive implemented through national law. Once the requirements relevant to your organisation are established, we help assess the technical arrangements and the changes needed to support them.

Where we can help

  • System and service ownership, including important suppliers and dependencies.
  • Access arrangements, maintenance and vulnerability handling.
  • Backup and recovery arrangements, and the evidence of testing.
  • Technical records needed to support incident handling and management review.

What you receive

  • A review of access, backups, maintenance and technical incident procedures against the requirements you provide.
  • A gap list with priorities, responsible people and suggested technical changes.
  • A list of records to collect or maintain, such as access reviews and restore-test results.

Help implementing these changes can be included in the agreed scope.

What is NIS2, and does it affect us?

NIS2 is an EU directive on cybersecurity. It covers risk management, incident reporting, suppliers and management responsibility. Countries implement it through national law, so the applicable duties depend on where your organisation operates, its sector, size and role. Some entities are covered regardless of size.

A customer asking you for security evidence does not automatically mean your own business falls directly within NIS2. It may be a supply-chain requirement. Establish the legal scope, then identify the systems and technical work involved.

European Commission: NIS2 overview ↗

What does technical implementation involve?

We connect an agreed requirement to a system, a person responsible and a check of the result. For example, a recovery requirement may need a restore test, a documented result and a plan to fix anything that failed.

The work can include reviewing access, backup arrangements, system updates, supplier dependencies and technical incident procedures. Changes and responsibilities are agreed with your team and existing providers. Keep records as the work happens so your answers can be supported later.

Example: a policy says former staff lose access promptly. We check the actual account-removal process across relevant systems, identify missed accounts and agree how future removals will be checked.

Questions about this work

Can you support teams across Europe?

Yes. We can work remotely with your team and providers across Europe. Establish the relevant national requirements with your legal or compliance adviser, then agree the technical scope, access and working arrangements with us.

Does ISO 27001 automatically cover NIS2?

No. ISO 27001 work may provide useful safeguards and records, but NIS2 scope and national obligations still need a separate assessment.

Will you implement the changes?

Implementation can be included. The proposal identifies which changes WFH will make, which your team or suppliers will make, and how they will be checked.

How the work begins

Share your agreed scope, requirements and available system information. We identify the people who need to contribute and confirm the work, responsibilities and expected result before starting.

Key terms

Read the NIS2 directive on EUR-Lex ↗

Next step / Start with your situation

You do not need to know the technical term.

Tell us what is happening, what it affects and when you need help. We’ll discuss whether we can help and what a useful first piece of work would be.