top of page

Everyone answers the questionnaire.
You Can Answer It With Evidence

NIS2 Executive Assurance Assessment

An independent report on where you actually stand against the NIS2 Directive, and on whether your leadership's own responsibility is demonstrable rather than assumed. One document that answers both the customer and the regulator.

Duration

Two days of my time

Your time

About four hours

FEE

Fixed, agreed in writing

Delivery

Remote, one practitioner

"Technical implementation can be delegated.

Executive responsibility cannot."

JONATHAN MAIN
GOVERNANCE ARCHITECT

25+ years across 19 industries and

35 countries.

ISO 9001, 14001, 27001, 42001, 45001

& 50001 Lead Auditor (BSI)
CIA ▪ CISA ▪ CRISC ▪ CDPSE

NIS2 Directive Trained Professional

"We were confident in our technical implementation. What we didn't have was independent confirmation that leadership could demonstrate its own side of it. That's what this gave us, something we could put in front of our leadership with confidence, not just our security team."

VP & CTO · Global leader in smart grid technology for utilities

Why this is happening now

The regulator may not have called yet.
Your Customers Already Have

In-scope companies are obliged to manage security across their supplier relationships. Which means they are obliged to ask you. Every organisation I have done NIS2 work for has since received those requests, formally and informally.

⏹     ⏹      Being able to answer stops being a compliance cost and becomes contract retention.

29,500

You decide you're in scope

German companies the regulator has identified as in scope. Nobody sends you a letter. You determine your own status, and you register yourself.

24h

Not 72

The 72-hour figure is GDPR muscle memory. The first reporting clock is shorter, and it starts when the incident happens, not when you become aware.

Article 20

Approve. Oversee. Personally.

The management body must approve the measures, oversee them and undertake training, not just be briefed on them. That duty cannot be delegated.

Figures relate to the German transposition of Directive (EU) 2022/2555, in force since December 2025 with no transition period. Status can change; nothing here is legal advice.

What you get

Two things you'd expect.
And The One Nobody Checked

01

NIS2 gap analysis

Every applicable article of the Directive, specific to your sector and sub-sector, tested against what you have actually implemented.

02

ISMS alignment

Your existing practices, certified or not, checked against the requirements to confirm what is already covered. No credit for work already done gets lost.

03

Executive assurance

Independent confirmation that leadership's own responsibility is demonstrable, not assumed: approval, oversight, training, decision rights, escalation authority, evidenced involvement. The layer for which the assessment exists.

When I verified a group's NIS2 implementation, most of what I found sat at leadership level rather than in the technical build. A quarter of it was Article 20 alone.

How it runs

Two days of my time.
Four Hours Of Yours

Whatever stage you have reached is the starting point. Nothing needs to be finished first.

If the assessment overruns, the fee does not change. It is agreed in writing before anything starts.

Consult

30 MIN

No obligation. If it fits, a fixed fee follows in writing within one working day.

Scoping

2–3 HRS

Interviews and evidence. You share what exists today.

Assessment

NONE

About a day and a half of my time. Nothing required from you.

Debrief

60 MIN

Two reports issued, and the debrief delivered by the person who did the work.

What you are left holding

Written for leadership.
Not For Auditors

DELIVERABLE 01

Leadership briefing note

A non-technical summary of your position, the material risks and the priorities. This is the document that goes into the leadership record and answers a customer request.

DELIVERABLE 02

Detailed technical findings

The full gap analysis, findings, evidence notes and a prioritised remediation roadmap with effort estimates. The working document for the people who will act on it.

DELIVERABLE 03

Leadership debrief

Sixty minutes with the person who did the work. Findings are written as decisions that never reached leadership properly, not as management failures. The first version gets acted on. The second gets filed.

Being precise about it

Some of what this is, and 
What It Isn't

▪  Not a certification. No accredited certification scheme for NIS2 compliance exists.
 

▪  Not implementation work. Nothing is designed or embedded, before or after.
 

▪  Not legal advice.
 

▪  Not delivered by a team. One senior practitioner throughout.
 

▪  Not a scope determination. You determine applicability. The assessment verifies it.
 

▪  Not penetration testing.

 

▪  Not a retainer. It terminates on delivery.
 

▪  Not conditional on being finished. Whatever stage you are at is the starting point.

NIS2 and ISO 27001 overlap substantially, so if you hold the standard or are working towards it, that work is credited rather than repeated. Component 02 confirms what your existing ISMS already satisfies. This is not an ISO 27001 audit and produces no ISO 27001 report.

Why an outside opinion is the point

I have no prior relationship with your systems.
That Is The Product

I did not build what I am assessing, and I will not be selling you the remediation afterwards. The criteria are the Directive itself, never a framework of mine. Your determinations stay yours; my opinion on them is what you are buying.

"Your specialists say you're covered. The consultant who built it says you're covered. Both are marking their own homework."

Jonathan Main, Governance Architect

If you are not ready for an outside opinion

Run the workshop yourself instead

The article-by-article breakdown I use, and the register for recording your position against each one. Free, no email required, and no follow-up. The determinations are deliberately left blank.

If your authority asked tomorrow,
What Would You Send Them?

Start here

Thirty minutes, confidential, no commitment. If the assessment isn't the right thing for you, I'll say so.

"A customer asked us to evidence our position. We could have sent what everyone sends: our own word for it. We sent an independent report instead."

SALES director, energy sector

bottom of page