Compliance

NIS2 & CRA Compliance

Fixed-price readiness for NIS2 and the Cyber Resilience Act.

I turn the directives into a prioritised, costed plan the board can approve — with the price agreed before I start.

  • Independent and agnostic
  • Evidence-driven analysis
  • Clear, actionable recommendations
  • Senior attention, end to end

The challenge

A directive is not a decision.

NIS2, DORA and the Cyber Resilience Act set obligations, not priorities. Read on their own, they leave a board with a legal text and no clear answer to the only questions that matter: what applies to us, where we fall short, and what we do first. Left unresolved, that ambiguity turns into either over-spending on the wrong controls or exposure the supervisor will eventually notice.

What I do

From directive to decisions the board can take.

A focused assessment and a roadmap you own — usable with a board, a supervisor or a customer.

How I work
  • Scope Determination

    Confirm whether, and how far, NIS2 and the CRA reach you.

  • Gap Assessment

    Where you stand against the obligations, with evidence.

  • Prioritised Roadmap

    What to do first, why, and what it takes — sequenced to the deadlines.

  • Board-Ready Report

    A document you can table, and reuse, with anyone.

  • Policies & Templates

    The governance artefacts to start from, not from scratch.

  • Ongoing Support

    Optional help to execute and stay ready.

My approach

A structured path to proportionate compliance.

I confirm scope, assess against the obligations, and hand you a plan — not a binder.

Explore my method
  1. 01

    Scope

    Confirm which obligations reach you, and how far.

  2. 02

    Discover

    Collect controls, governance and evidence.

  3. 03

    Assess

    Measure the gap against NIS2 and, where relevant, the CRA.

  4. 04

    Report

    Findings and a prioritised, costed roadmap.

  5. 05

    Support

    Optional help to execute and maintain readiness.

Outcomes

What you own at the end

Book a consultation
  • A clear answer on whether, and how far, each obligation applies to you.
  • A prioritised, costed roadmap the board can approve and act on.
  • A board-ready report you can reuse with a supervisor, a customer or an auditor.
  • Governance artefacts you keep and build on, not a binder that dates on the shelf.

Case study

DORA readiness for a mid-sized financial institution

A DORA readiness programme that closed the main gaps in ICT risk management, incident reporting, and critical ICT providers, with an operational resilience testing cycle in place.

Read the case study

Frequently asked

Questions I get asked.

How do you price this?

The readiness assessment is fixed-price, agreed before I start, so the cost is known in advance. Any follow-on support to execute the roadmap is scoped separately.

Do we already fall under NIS2 or the CRA?

That is the first thing I confirm. Scope depends on sector, size and role in the supply chain, and getting it wrong in either direction is expensive. I establish it before assessing anything else.

Can you cover DORA as well?

Yes, where it applies. For financial-sector companies I align the same readiness approach to DORA, so overlapping obligations are handled once rather than three times.

Do you guarantee compliance?

No one credibly can. I give you an accurate view of where you stand and a defensible plan to close the gaps. Compliance is a determination for you, your auditors and the supervisor — my job is to make it reachable and evidenced.

Ready to start?

Let’s talk about your case.

Every situation is unique. Tell me the context and I’ll help you define the best approach.

Book a consultation