Millecam

NIS2: from directive to demonstrable compliance

The European cybersecurity directive for essential and important entities, transposed into Belgian law. Relevant from a certain size or sector onward, with director liability if nothing is done about it.

Who is this relevant for?

Essential or important entity

Your organisation falls under one of the NIS2 sectors (energy, transport, digital infrastructure, healthcare, and more) and exceeds the size threshold.

A client or insurer asks for demonstrability

You supply an essential or important entity, and they ask you to prove for yourself that your risk management is in order.

No internal compliance officer

You know NIS2 is relevant, but no one on the team has the time or background to set this up structurally.

Not sure whether this affects your organisation? Take the short NIS2 check.

What Millecam does

A scoping analysis determines whether, and as what, your organisation falls under NIS2. This is followed by a GAP analysis against the risk management measures from Article 21: where you stand today, scored on both documentation and effective implementation. Findings are translated into a concrete action plan: not eighty pages of jargon, but a list of what needs to happen first, and by whom.

What you actually get

  • Scoping analysis: whether you fall under NIS2, and as an essential or important entity
  • GAP report against the NIS2 risk management measures (Article 21), with scoring per measure
  • Prioritised action plan with ownership and a realistic timeline
  • Tailored policy documents and procedures: access management, supplier management, business continuity, incident response
  • Incident notification procedure aligned with the NIS2 reporting deadlines
  • Preparation of the management body for its NIS2 responsibility and reporting structure
  • Support during verification or oversight by the competent authority

How a NIS2 track unfolds

Step 1

Scoping & GAP analysis

Whether you fall under NIS2, and where you stand today against the risk management measures.

Step 2

Implementation

Findings translated into policy, procedures and technical measures. You stay in control.

Step 3

Demonstrability

Documentation and evidence in order, ready for a possible audit.

More about the approach

Result

Demonstrable compliance with the NIS2 risk management measures: working risk management instead of documentation alone, a management body that knows its responsibility, and an incident notification process that is ready before it is needed.

Why Millecam

One fixed point of contact, no rotating team. Direct contact with whoever does the work: no junior consultant, no escalation chain. More about Robin.

Ready to get started?

A no-obligation thirty-minute conversation is enough to determine whether, and how, Millecam can help.

Discuss your NIS2 track