NIS2 · The 4-Week Readiness Assessment

Where does your organisation stand on NIS2 — and can you show your board?

A fixed-scope, four-week assessment for Irish organisations in scope of NIS2. You leave with a clear position, an executive report your board can act on, and a prioritised roadmap. No open-ended consultancy.

The regulator has already told boards what it expects.

Ireland has not yet enacted the National Cyber Security Bill that transposes NIS2, but the pressure to do so is now coming from Brussels and the obligations are arriving by other routes.

17 OCT 2024

EU transposition deadline

The date by which every member state was to have NIS2 in national law. Ireland's National Cyber Security Bill remains unenacted.

7 JUL 2026

NCSC publishes board guidance

The National Cyber Security Centre issues Guidance on Cyber Governance for Management Board Members in NIS2 Entities, written for CEOs, Accounting Officers and board members rather than IT teams.

8 JUL 2026

Ireland referred to the CJEU

The European Commission refers Ireland to the Court of Justice of the EU for failing to transpose NIS2.

The Bill can be enacted at any point, and the regulator has already published what it expects boards to have in place.

Organisations that assess now choose their own timetable. Those that wait will be working to someone else's.

What the NCSC has told boards

The National Cyber Security Centre's guidance for management board members is explicit about where responsibility sits and what it expects to see.

NIS2 places accountability for cyber risk management "at the highest level of executive management."

R.A. Browne, Director, National Cyber Security Centre — foreword to the NCSC's guidance for management board members in NIS2 entities
National Cyber Security Centre
Source: National Cyber Security CentreGuidance on Cyber Governance for Management Board Members in NIS2 Entities, ncsc.gov.ie

In the NCSC's framing, cyber risk is a business risk rather than an IT matter, and board members are personally accountable for four things:

  • Understanding the organisation's cyber risk posture
  • Approving the risk-management measures
  • Ensuring the organisation is prepared to respond and recover
  • Overseeing ongoing compliance

The guidance also sets out the questions it expects every board member to be able to answer — among them: what are our critical assets and systems, how are we managing supply-chain risk, how do we benchmark our cyber posture, when did we last test, and how prepared are we to detect and respond to an incident.

It names the Cyber Fundamentals framework (CyFun) as the NCSC's preferred approach to demonstrating NIS2 compliance, and notes that early supervisory attention will focus on governance.

NCSC ANNEX I

The regulator's own readiness checklist

Items from the NCSC's indicative NIS2 checklist for boards
  • NIS2 scope analysis performed
  • Board and management trained and aware of NIS2 obligations
  • Documented cyber governance framework with roles and responsibilities
  • CyFun self-assessment completed and validated
  • Gap analysis of current state against NIS2 requirements
  • Risk remediation plan and progress tracking
  • Risk assessments and evidence of compliance measures
Paraphrased from Annex I of the NCSC guidance. The NIS2 Readiness Assessment is built to deliver the scope analysis, CyFun assessment, gap analysis and remediation plan, and to give the board the evidence base behind them.

Who is in scope

NIS2 reaches well beyond the utilities and infrastructure operators covered by the first directive. Most medium and large organisations in these sectors are in scope, and smaller organisations can be brought in where they provide a critical service.

Essential entities

Highest obligations and supervision
  • Energy — electricity, gas, oil, district heating, hydrogen
  • Transport — air, rail, water, road
  • Banking and financial market infrastructure
  • Health — providers, labs, pharma, medical devices
  • Drinking water and waste water
  • Digital infrastructure — data centres, cloud, DNS, telecoms
  • ICT service management (B2B)
  • Public administration
  • Space

Important entities

Same measures, lighter supervision
  • Postal and courier services
  • Waste management
  • Chemicals — manufacture, production, distribution
  • Food — production, processing, distribution
  • Manufacturing — medical devices, electronics, machinery, vehicles
  • Digital providers — marketplaces, search engines, social platforms
  • Research organisations
Not sure whether you are in scope, or which category applies? That question is answered in the first week of the assessment.

What NIS2 asks of a board

The directive treats cybersecurity as a governance matter. Three articles carry most of the weight for senior management, and the penalties sit alongside them.

ARTICLE 20

Governance

The management body must approve the organisation's cyber risk-management measures, oversee their implementation, and can be held liable for failures. Board members must undertake cybersecurity training.

Supervisors will expect to see this recorded: decisions, minutes, evidence of oversight.

ARTICLE 21

Risk management

Ten mandatory measures: risk analysis and policies, incident handling, continuity and crisis management, supply-chain security, secure development and vulnerability handling, effectiveness testing, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication.

Each must be proportionate to your exposure and demonstrable on request.

ARTICLE 23

Incident reporting

A significant incident must be reported with an early warning within 24 hours, a notification within 72 hours, and a final report within one month.

That clock only works if you already know what counts as significant, who decides, and how the report is made.

PENALTIES

Fines and personal consequences

Up to €10 million or 2% of global turnover for essential entities; up to €7 million or 1.4% for important entities, whichever is higher.

Authorities can also suspend certifications and, for essential entities, temporarily bar individuals from management roles.

Most organisations cannot yet answer the question at the top of this page.

The reason is rarely a lack of technology. It is that nobody has measured the organisation against the directive, evidence is scattered across teams and suppliers, and the board has never been given a view it can understand and sign off. That is a governance gap, and it can be closed in four weeks.

The NIS2 Readiness Assessment

Fixed scope. Four weeks. Delivered on the CyberPrism platform with a CRI practitioner guiding your team throughout — so the work is done with you, not to you.

WEEK 1

Onboarding and profile

Establish where you start from
  • Confirm scope and entity category
  • Capture business context and dependencies
  • Inherent risk profile — what an incident would cost you
WEEK 2

Assessment

Measure against the directive
  • Structured working sessions with our practitioner — your team answers, we structure
  • Evidence gathered as you go
  • Mapped to NIST CSF 2.0 and CyFun
WEEK 3

Gap analysis and dashboards

See the position clearly
  • Live dashboards against each NIS2 requirement
  • Findings validated and weighted by exposure
  • Executive report drafted
WEEK 4

Board and roadmap

Decide what happens next
  • Executive readiness report delivered
  • Prioritised remediation roadmap
  • Board or executive briefing in person

What you receive

Scope and category determination

A documented view of whether you are in scope, as an essential or important entity, and which obligations follow.

Inherent risk profile

What the organisation relies on, where it is exposed, and what an incident would mean for it.

NIS2 readiness assessment

Your position against Articles 20, 21 and 23, evidenced and mapped to NIST CSF 2.0 and CyFun.

Live dashboards

Your assessment, gaps and evidence on CyberPrism for the programme and 30 days after it.

Executive readiness report

Written for a board, not an IT department. Where you stand, what matters most, and what closing the gaps will take.

Prioritised remediation roadmap

Actions ordered by exposure and effort, with owners and timeframes your team can commit to.

Board briefing

A session with your board or executive team, meeting the expectation that management understands and oversees cyber risk.

Threat intelligence tied to your gaps

ThreatLens matches current threat activity and vulnerabilities to where you are weakest, so the roadmap reflects what is happening now.

Built on CyberPrism

CyberPrism holds your assessment, evidence, dashboards and reports in one place — and keeps them current after the assessment ends, rather than leaving you with a document that dates on the day it is delivered.

The assessment is anchored on NIST CSF 2.0 and includes the CyFun (Cyber Fundamentals) framework, which the National Cyber Security Centre describes as its preferred approach to demonstrating NIS2 compliance — so your position is expressed in terms the Irish regulator already uses. The same platform carries overlays for DORA, the EU AI Act and other regimes — which matters if NIS2 is not the only obligation you face.

NIS2CyFunNIST CSF 2.0DORAEU AI ActThreatLens
NIS2 readiness dashboard with compliance across key areas and incident handling scores
NIS2 — obligation areas, ENISA technical implementation status and incident-handling capability.Click to enlarge

After the four weeks

The assessment ends with a decision, not a filing cabinet. Most organisations choose one of two paths.

CONTINUOUS ASSURANCE

Keep your CyberPrism environment live. Track remediation, re-assess quarterly, receive ongoing threat intelligence and advisory, and give your board a standing view rather than an annual snapshot. This is the position supervisors will expect once the Bill is enacted.

DELIVER IT YOURSELVES

Take the report and roadmap and work through it with your own team or existing providers. Nothing in the assessment ties you to CRI, and the roadmap is written so it can be handed to whoever will deliver it.

Board oversight of cyber risk is now a standing agenda item, not an annual one.

Common questions

The Bill has not been enacted. Why act now?

Because the obligations are already arriving by other routes. The NCSC has published detailed governance guidance for board members, including a readiness checklist. Customers and insurers are writing NIS2 clauses into contracts. And the European Commission is pursuing Ireland through the Court of Justice, which makes enactment a matter of when. Organisations that assess now choose their own timetable.

How much of our team's time does it take?

Typically two to three hours a week from a coordinator, plus one short session each with the people who own the relevant areas — IT, operations, HR, procurement, legal. Our practitioner does the structuring, mapping and analysis so your team is answering questions, not writing reports. Four weeks works because the platform holds the framework; nobody is building spreadsheets.

We already have ISO 27001 or Cyber Essentials. Do we still need this?

Those are good foundations and the assessment credits them. NIS2 adds obligations they do not cover — board accountability, incident reporting timelines, supply-chain measures — and asks for those to be evidenced in the regulator's terms. The assessment shows exactly where your existing certification carries you and where it does not.

Is this an audit?

No. It is a readiness assessment. Its purpose is to give you an accurate position and a plan before any supervisor asks. The evidence base it produces is, however, what you would draw on if one did.

We are not sure we are in scope.

That is settled in the first week. If it turns out you are not in scope, we will tell you — and you will still hold a clear view of your exposure and a short list of sensible actions.

Can our existing IT provider or MSP be involved?

Yes, and usually should be. They hold much of the evidence and will deliver part of the roadmap. We work alongside them; the assessment sits above the technology, not in competition with it.

What does it cost?

The programme is fixed-price for a defined scope, which is confirmed on the scoping call. We will not sell you a longer engagement than you need.

What if four weeks is not enough for us?

Four weeks suits most organisations with a single legal entity and a coordinator who can give it a few hours a week. Larger groups, multi-site operators or organisations with several subsidiaries in scope may need longer, and the programme can be extended by agreement at scoping or during week one. The scope, timetable and price are settled before work starts, so an extension is never a surprise.

Know where you stand before someone else asks.

A 30-minute scoping call is enough to confirm whether you are in scope, what the four weeks would cover for you, and when it could start.

Book a scoping call
CRI partner with eir business
Prefer to talk? Call +353 (0)1 905 3260.