NIS2.
Know Where You Stand
Free workshop pack ▪ All sectors in scope
A half-day workshop you run yourself, with your own teams. It's the same material I use with paying clients.
01
The workshop presentation. The Directive, article by article, across every sector it covers.
02
The Statement of Applicability and Implementation Register. You fill it in as you go.
03
An ISO 27001 gap section (if applicable). What your ISMS already covers, and what it doesn't.
Both documents, right here.
No form, no email, no follow-up sequence.
01
Presentation ▪ PDF
02
Working document ▪ XLSX
Yours, no strings. I've deliberately left the determinations blank. If you ever want an independent opinion on your position, that opinion is only worth something if the judgements in it are yours, not mine.

"Technical implementation can be delegated.
Executive responsibility cannot."
JONATHAN MAIN
GOVERNANCE ARCHITECT
25+ years across 19 industries and 35 countries.
ISO 9001, 14001, 27001, 42001, 45001 & 50001 Lead Auditor (BSI)
CIA ▪ CISA ▪ CRISC ▪ CDPSE ▪ NIS2 Directive Trained Professional
What's in it
Two working documents.
Not One PDF Guide
DOCUMENT 01
The NIS2 Readiness Workshop presentation
The Directive, article by article, across all eighteen sectors it names. Scope, what actually applies to you, and where your existing management systems already do the work. Every section ends with discussion questions for the room.
DOCUMENT 02
The Statement of Applicability & Implementation Register
You fill it in as you go. By the end of the session it's no longer a worksheet, it's your action plan. It also doubles as your evidence file when a customer or an authority asks.
01
Understanding the Directive
What NIS2 requires, in plain language. Essential and important entities, and what the distinction changes.
02
Scope: do you fall under NIS2?
The sector, size and designation criteria, walked through properly, so you can document the answer rather than assume it.
03
Defining your own scope
Drawing the boundary: which systems, services and entities the implementation needs to cover.
04
Article-by-article requirements
Governance, incident handling, continuity, supply chain, cryptography, access control, reporting. What each one means for your operations, whatever they are, and what to do about it.
05
ISO 27001 gap analysis (if applicable)
Where your existing ISMS already satisfies NIS2, and where the gaps are. No credit for work already done gets lost.
Why the pack is built this way
Most of NIS2 is a technical build.
The Rest Sits With The Management Body
ISO 27001, ISMS, controls, detection, response. Necessary work, and in most organisations it is already well underway.
The second layer gets less attention: approving the measures, overseeing them, training that can be evidenced. The Directive places that on the management body itself, and it stays there however capable the people you delegate to are.
The pack covers both layers. Only one of them can be handed to someone else.
DELEGATION
STOPS HERE
.png)
.png)
Leadership layer
APPROVE · OVERSEE
TRAIN · EVIDENCE
Specialist layer
ISO 27001 · ISMS · CONTROLS
DETECTION · RESPONSE
CAN BE DELEGATED
What happens next
Three ways forward.
Pick The One That Fits
For every sector the Directive names: energy, water, transport, health, digital infrastructure, banking, space, manufacturing, chemicals, food, waste, postal, and digital services and research. Whether or not you've started.
Do it yourself
Run the workshop, complete the Statement of Applicability, implement what it tells you. The pack is yours, no obligation.
No time to run it yourself
Doing this properly takes weeks of senior time most teams don't have. Talk it through directly, scoped to your organisation, no hand-off to juniors. One caveat: if I do the implementation, the independent review has to come from someone else. It is one or the other, never both.
