SteadySec Your retained security partner

At full delivery capacity until the end of 2026.

NIS2 is reaching you through your customers

You may not be regulated by NIS2 directly. But regulated customers must manage supplier risk, so the security appendix, questionnaire, or audit clause lands on your desk. We turn it into a realistic security roadmap.

We interpret the cybersecurity meaning and feasibility of customer requirements. Legal enforceability and final contract wording belong with qualified counsel.

Where This Fits

Who this is for

This is you

Your company

  • SME supplier: software, IT services, MSP or SaaS, engineering, maintenance, data processing
  • Serving customers in NIS2-regulated sectors
  • Not directly regulated yourself, or not sure

What is pushing you

  • A customer sent a NIS2 security questionnaire or contract appendix
  • You have been named a critical or significant supplier
  • Procurement asks for MFA, incident reporting, backup proof, audit rights, or subcontractor controls

How we do it

  • Instead of promising the customer you are NIS2 compliant, we prove the controls the contract actually requires.

  • Instead of answering the questionnaire from memory, we answer from evidence, with gaps stated honestly.

  • Instead of signing security clauses unread, we flag unrealistic obligations before you sign.

The Problem

The requests you receive

Suppliers rarely get a clean technical checklist. They get legal wording, procurement questions, and clauses like these:

  • “Supplier must comply with applicable cybersecurity requirements.”
  • “Supplier must notify cybersecurity incidents without undue delay.”
  • “Supplier must allow audit of implemented security measures.”
  • “Supplier must ensure equivalent obligations for subcontractors.”
  • “Supplier must maintain business continuity of the provided service.”

The hard part is not reading the text. It is knowing what must be implemented, what evidence to show, what goes on a roadmap, and what to negotiate before signing.

The Roadmap

Five phases

1

Read the customer request

Contract clauses, security annexes, questionnaires, audit and SLA obligations. The starting point is the document your customer sent, not a generic checklist.

2

Extract the real obligations

What is explicitly required, what is implied, what evidence is expected, and what is too broad to accept. The output is an obligation matrix.

3

Map obligations to controls and evidence

Access control and MFA, incident handling, patch management, backups and recovery, logging, subcontractors, continuity. We assess what exists and what evidence is missing.

4

Build the roadmap and response pack

What to fix before signing, what to accept with a remediation plan, and what to negotiate. Plus an evidence pack the customer can actually review.

5

Retainer operation

Customers come back with follow-up questions, revised clauses, and audit requests. The retainer keeps evidence current, controls reviewed, and the roadmap moving.

Free Resource

Start with the checklist

Self-assess with the same readiness checklist we use in supplier engagements: 32 checks across ownership, contracts, access, incidents, backup, and evidence. Print it, and tick an item only if you could show a document or record that proves it.

Get the readiness checklist

More gaps than ticks? That is exactly what the retainer is for.

Start Here

How to start

The same four steps for every engagement here. You can stop after step two and owe nothing.

  1. 1

    Run the Discovery Calculator

    Free

    About four minutes, no sign-up. It runs in your browser and nothing is sent anywhere unless you choose to send it.

  2. 2

    Send me the result

    Free

    I reply with a recommendation for your situation - including when the honest answer is that you do not need me yet.

  3. 3

    Starter Assessment (€1,900) or Starter Month (€2,900)

    Fixed price, one-off

    The paid entry, and the only one. It ends with a roadmap of the major milestones and a recommended retainer tier.

  4. 4

    Continue on a retainer

    From €950 a month

    If the roadmap makes sense to both of us, implementation runs inside the retained engagement. Part of what you paid for the starter door is credited against it.

How this becomes a retainer

Supplier readiness is rarely one document: customers come back with new questionnaires, audit requests, and revised clauses. The starter door produces the roadmap; the retained engagement is where it gets built. One senior practitioner, a fixed monthly hour cap, and a tier set after the starter door rather than guessed before it.

What is not included

No legal advice, and no declaration that an indirectly affected supplier is “NIS2 compliant”. The goal is to satisfy reasonable customer requirements, prove what exists, and show a credible roadmap for the rest.

NIS2 reaches most suppliers through contracts, not through the directive itself. The customer's security appendix is the real requirement.

Regulated by NIS2 directly? The Retained Security Partner path covers governance and the full control set.