top of page

NIS2.
Know Where You Stand

Free workshop pack ▪ All sectors in scope

A half-day workshop you run yourself, with your own teams. It's the same material I use with paying clients.

01

The workshop presentation. The Directive, article by article, across every sector it covers.

02

The Statement of Applicability and Implementation Register. You fill it in as you go.

03

An ISO 27001 gap section (if applicable). What your ISMS already covers, and what it doesn't.

Both documents, right here.

No form, no email, no follow-up sequence.

01

Presentation  ▪  PDF

02

Working document  ▪  XLSX

Yours, no strings. I've deliberately left the determinations blank. If you ever want an independent opinion on your position, that opinion is only worth something if the judgements in it are yours, not mine.

"Technical implementation can be delegated.

Executive responsibility cannot."

JONATHAN MAIN
GOVERNANCE ARCHITECT

25+ years across 19 industries and 35 countries.

ISO 9001, 14001, 27001, 42001, 45001 & 50001 Lead Auditor (BSI)
CIA ▪ CISA ▪ CRISC ▪ CDPSE ▪ NIS2 Directive Trained Professional

What's in it

Two working documents.
Not One PDF Guide

DOCUMENT 01

The NIS2 Readiness Workshop presentation

The Directive, article by article, across all eighteen sectors it names. Scope, what actually applies to you, and where your existing management systems already do the work. Every section ends with discussion questions for the room.

DOCUMENT 02

The Statement of Applicability & Implementation Register

You fill it in as you go. By the end of the session it's no longer a worksheet, it's your action plan. It also doubles as your evidence file when a customer or an authority asks.

01

Understanding the Directive

What NIS2 requires, in plain language. Essential and important entities, and what the distinction changes.

02

Scope: do you fall under NIS2?

The sector, size and designation criteria, walked through properly, so you can document the answer rather than assume it.

03

Defining your own scope

Drawing the boundary: which systems, services and entities the implementation needs to cover.

04

Article-by-article requirements

Governance, incident handling, continuity, supply chain, cryptography, access control, reporting. What each one means for your operations, whatever they are, and what to do about it.

05

ISO 27001 gap analysis (if applicable)

Where your existing ISMS already satisfies NIS2, and where the gaps are. No credit for work already done gets lost.

Why the pack is built this way

Most of NIS2 is a technical build.
The Rest Sits With The Management Body

ISO 27001, ISMS, controls, detection, response. Necessary work, and in most organisations it is already well underway.

The second layer gets less attention: approving the measures, overseeing them, training that can be evidenced. The Directive places that on the management body itself, and it stays there however capable the people you delegate to are.

The pack covers both layers. Only one of them can be handed to someone else.

DELEGATION

STOPS HERE

Untitled design (8).png
Untitled design (7).png

Leadership layer

APPROVE · OVERSEE

TRAIN · EVIDENCE

Specialist layer

ISO 27001 · ISMS · CONTROLS

DETECTION · RESPONSE

CAN BE DELEGATED

What happens next

Three ways forward.
Pick The One That Fits

For every sector the Directive names: energy, water, transport, health, digital infrastructure, banking, space, manufacturing, chemicals, food, waste, postal, and digital services and research. Whether or not you've started.

Do it yourself

Run the workshop, complete the Statement of Applicability, implement what it tells you. The pack is yours, no obligation.

You want an independent read

Two days, fixed fee, fully remote. Independent confirmation of the layer only the management body can fulfil, plus a technical gap analysis. Two reports, one engagement.

No time to run it yourself

Doing this properly takes weeks of senior time most teams don't have. Talk it through directly, scoped to your organisation, no hand-off to juniors. One caveat: if I do the implementation, the independent review has to come from someone else. It is one or the other, never both.

Take the pack.
Decide Afterwards

No obligation either way

If you'd rather talk first, the initial consult is thirty minutes, confidential, and carries no commitment.

"Integrated systems is the only sustainable form of governance."

Jonathan Main

bottom of page