Compliance with NIS2 Directive

The NIS2 Directive is the EU-wide legislation on cybersecurity. The aim of this Directive is to boost the overall level of cybersecurity in the EU and to ensure that a high level of common cybersecurity measures are adopted.

The challenge

Evolving EU cybersecurity landscape

The EU’s Network and Information Security (NIS) Directive, first introduced in 2016, has undergone a significant update with the introduction of the NIS2 Directive, which came into force in January 2023. It modernised the existing legal framework to keep up with increased digitisation and an evolving cybersecurity threat landscape.

Increased compliance obligations for critical sectors

A wide range of sectors are now within scope, including ICT Service Management, Financial Market Infrastructures, Cloud Computing, Healthcare, and Medical Devices. These organisations must comply with stringent security and notification requirements.

Formalisation of management requirements

Entities identified by Member States as "essential" or "important" must formalise their cybersecurity governance, processes, and reporting to align with the NIS2 requirements placing new demands on leadership, operational teams, and technology infrastructures.

The service

BH Consulting provide these services to organisations required to comply with the NIS2 Directive:
  • NIS2 readiness assessment: a gap analysis with a focus on the ‘Foundational Actions’ for each of the 16 Risk Management Measures (RMM) required to meet the legislative obligations of the Directive. Our methodology involves use of a Risk Management Measures based questionnaire specially developed to follow the requirements specified in the NIS2 Directive and tracking the NCSC IRL latest recommendations. This enables us to generate a bespoke report outlining areas to address and suggested remediation steps, mapped to the requirements of the directive while considering the latest updates from the National Cyber Security Centre on NIS2.

  • NIS2 compliance program: we will help to align your current cybersecurity management with NIS2. This includes making recommendations around modifications and improvements to security controls and helping to put in place policies and procedures to meet the requirements of NIS2. NCSC’s Risk Management Measures Guidance and its Foundational Actions is the key framework we use for this work. We also consider ‘Supporting Actions’ which are further controls that may be required, depending on the specific risks faced by the organisation.

Benefits

Provides a management framework to allow your organisation demonstrate compliance with NIS2

Provides a formal cybersecurity strategy aligned to the requirements of your organisation which pays due regard to the requirements of the directive

Implements a risk based approach to the management of cybersecurity

Supports building processes to enhance cyber resilience and vendor risk management

Testimonials

Why get in touch with BH Consulting

BH Consulting is a trusted, independent cybersecurity and data protection consultancy with over 20 years of experience. Whether you need expert guidance on compliance, risk management, or security strategy, our team delivers practical, vendor-neutral advice tailored to your needs.

Let’s start a conversation about securing your business.

Areas of interest*