At full delivery capacity until the end of 2026.
NIS2 is reaching you through your customers
You may not be regulated by NIS2 NIS2 An EU directive that makes regulated companies responsible for the security of their suppliers - which is why their questionnaires and contract clauses reach you. directly. But regulated customers must manage supplier risk, so the security appendix, questionnaire, or audit clause lands on your desk. We turn it into a realistic security roadmap.
We interpret the cybersecurity meaning and feasibility of customer requirements. Legal enforceability and final contract wording belong with qualified counsel.
Where This Fits
Who this is for
This is you
Your company
- SME supplier: software, IT services, MSP or SaaS, engineering, maintenance, data processing
- Serving customers in NIS2-regulated sectors
- Not directly regulated yourself, or not sure
What is pushing you
- A customer sent a NIS2 security questionnaire or contract appendix
- You have been named a critical or significant supplier
- Procurement asks for MFA, incident reporting, backup proof, audit rights, or subcontractor controls
How we do it
-
Instead of promising the customer you are NIS2 compliant, we prove the controls the contract actually requires.
-
Instead of answering the questionnaire from memory, we answer from evidence, with gaps stated honestly.
-
Instead of signing security clauses unread, we flag unrealistic obligations before you sign.
The Problem
The requests you receive
Suppliers rarely get a clean technical checklist. They get legal wording, procurement questions, and clauses like these:
- “Supplier must comply with applicable cybersecurity requirements.”
- “Supplier must notify cybersecurity incidents without undue delay.”
- “Supplier must allow audit of implemented security measures.”
- “Supplier must ensure equivalent obligations for subcontractors.”
- “Supplier must maintain business continuity of the provided service.”
The hard part is not reading the text. It is knowing what must be implemented, what evidence to show, what goes on a roadmap, and what to negotiate before signing.
The Roadmap
Five phases
Read the customer request
Contract clauses, security annexes, questionnaires, audit and SLA obligations. The starting point is the document your customer sent, not a generic checklist.
Extract the real obligations
What is explicitly required, what is implied, what evidence is expected, and what is too broad to accept. The output is an obligation matrix.
Map obligations to controls and evidence
Access control and MFA, incident handling, patch management, backups and recovery, logging, subcontractors, continuity. We assess what exists and what evidence is missing.
Build the roadmap and response pack
What to fix before signing, what to accept with a remediation plan, and what to negotiate. Plus an evidence pack the customer can actually review.
Retainer operation
Customers come back with follow-up questions, revised clauses, and audit requests. The retainer keeps evidence current, controls reviewed, and the roadmap moving.
Free Resource
Start with the checklist
Self-assess with the same readiness checklist we use in supplier engagements: 32 checks across ownership, contracts, access, incidents, backup, and evidence. Print it, and tick an item only if you could show a document or record that proves it.
Get the readiness checklistMore gaps than ticks? That is exactly what the retainer is for.
Start Here
How to start
The same four steps for every engagement here. You can stop after step two and owe nothing.
- 1
Run the Discovery Calculator
FreeAbout four minutes, no sign-up. It runs in your browser and nothing is sent anywhere unless you choose to send it.
- 2
Send me the result
FreeI reply with a recommendation for your situation - including when the honest answer is that you do not need me yet.
- 3
Starter Assessment (€1,900) or Starter Month (€2,900)
Fixed price, one-offThe paid entry, and the only one. It ends with a roadmap of the major milestones and a recommended retainer tier.
- 4
Continue on a retainer
From €950 a monthIf the roadmap makes sense to both of us, implementation runs inside the retained engagement. Part of what you paid for the starter door is credited against it.
How this becomes a retainer
Supplier readiness is rarely one document: customers come back with new questionnaires, audit requests, and revised clauses. The starter door produces the roadmap; the retained engagement is where it gets built. One senior practitioner, a fixed monthly hour cap, and a tier set after the starter door rather than guessed before it.
What is not included
No legal advice, and no declaration that an indirectly affected supplier is “NIS2 compliant”. The goal is to satisfy reasonable customer requirements, prove what exists, and show a credible roadmap for the rest.
NIS2 reaches most suppliers through contracts, not through the directive itself. The customer's security appendix is the real requirement.
Regulated by NIS2 directly? The Retained Security Partner path covers governance and the full control set.