Everyone answers the questionnaire.
You Can Answer It With Evidence
NIS2 Executive Assurance Assessment
An independent report on where you actually stand against the NIS2 Directive, and on whether your leadership's own responsibility is demonstrable rather than assumed. One document that answers both the customer and the regulator.
Duration
Two days of my time
Your time
About four hours
FEE
Fixed, agreed in writing
Delivery
Remote, one practitioner

"Technical implementation can be delegated.
Executive responsibility cannot."
JONATHAN MAIN
GOVERNANCE ARCHITECT
25+ years across 19 industries and
35 countries.
ISO 9001, 14001, 27001, 42001, 45001
& 50001 Lead Auditor (BSI)
CIA ▪ CISA ▪ CRISC ▪ CDPSE
NIS2 Directive Trained Professional
"We were confident in our technical implementation. What we didn't have was independent confirmation that leadership could demonstrate its own side of it. That's what this gave us, something we could put in front of our leadership with confidence, not just our security team."
VP & CTO · Global leader in smart grid technology for utilities
Why this is happening now
The regulator may not have called yet.
Your Customers Already Have
In-scope companies are obliged to manage security across their supplier relationships. Which means they are obliged to ask you. Every organisation I have done NIS2 work for has since received those requests, formally and informally.
⏹ ⏹ Being able to answer stops being a compliance cost and becomes contract retention.
29,500
You decide you're in scope
German companies the regulator has identified as in scope. Nobody sends you a letter. You determine your own status, and you register yourself.
24h
Not 72
The 72-hour figure is GDPR muscle memory. The first reporting clock is shorter, and it starts when the incident happens, not when you become aware.
Article 20
Approve. Oversee. Personally.
The management body must approve the measures, oversee them and undertake training, not just be briefed on them. That duty cannot be delegated.
Figures relate to the German transposition of Directive (EU) 2022/2555, in force since December 2025 with no transition period. Status can change; nothing here is legal advice.
What you get
Two things you'd expect.
And The One Nobody Checked
01
NIS2 gap analysis
Every applicable article of the Directive, specific to your sector and sub-sector, tested against what you have actually implemented.
02
ISMS alignment
Your existing practices, certified or not, checked against the requirements to confirm what is already covered. No credit for work already done gets lost.
03
Executive assurance
Independent confirmation that leadership's own responsibility is demonstrable, not assumed: approval, oversight, training, decision rights, escalation authority, evidenced involvement. The layer for which the assessment exists.
When I verified a group's NIS2 implementation, most of what I found sat at leadership level rather than in the technical build. A quarter of it was Article 20 alone.
How it runs
Two days of my time.
Four Hours Of Yours
Whatever stage you have reached is the starting point. Nothing needs to be finished first.
If the assessment overruns, the fee does not change. It is agreed in writing before anything starts.
Consult
30 MIN
No obligation. If it fits, a fixed fee follows in writing within one working day.
Scoping
2–3 HRS
Interviews and evidence. You share what exists today.
Assessment
NONE
About a day and a half of my time. Nothing required from you.
Debrief
60 MIN
Two reports issued, and the debrief delivered by the person who did the work.
What you are left holding
Written for leadership.
Not For Auditors
DELIVERABLE 01
Leadership briefing note
A non-technical summary of your position, the material risks and the priorities. This is the document that goes into the leadership record and answers a customer request.
DELIVERABLE 02
Detailed technical findings
The full gap analysis, findings, evidence notes and a prioritised remediation roadmap with effort estimates. The working document for the people who will act on it.
DELIVERABLE 03
Leadership debrief
Sixty minutes with the person who did the work. Findings are written as decisions that never reached leadership properly, not as management failures. The first version gets acted on. The second gets filed.
Being precise about it
Some of what this is, and
What It Isn't
▪ Not a certification. No accredited certification scheme for NIS2 compliance exists.
▪ Not implementation work. Nothing is designed or embedded, before or after.
▪ Not legal advice.
▪ Not delivered by a team. One senior practitioner throughout.
▪ Not a scope determination. You determine applicability. The assessment verifies it.
▪ Not penetration testing.
▪ Not a retainer. It terminates on delivery.
▪ Not conditional on being finished. Whatever stage you are at is the starting point.
NIS2 and ISO 27001 overlap substantially, so if you hold the standard or are working towards it, that work is credited rather than repeated. Component 02 confirms what your existing ISMS already satisfies. This is not an ISO 27001 audit and produces no ISO 27001 report.
