NIS2 · 90-Day Readiness Assessment

Where does your organisation stand on NIS2 — and can you show your board?

A fixed-scope, 90-day assessment for Irish organisations in scope of NIS2. You leave with a clear position, an executive report your board can act on, and a prioritised roadmap. No open-ended consultancy.

The regulator has already told boards what it expects.

Ireland has not yet enacted the National Cyber Security Bill that transposes NIS2, but the pressure to do so is now coming from Brussels and the obligations are arriving by other routes.

17 OCT 2024

EU transposition deadline

The date by which every member state was to have NIS2 in national law. Ireland's National Cyber Security Bill remains unenacted.

7 JUL 2026

NCSC board guidance published

The National Cyber Security Centre sets out what it expects of management boards in NIS2-scope organisations: cyber risk owned and overseen at the highest level of executive management.

8 JUL 2026

Ireland referred to the CJEU

The European Commission refers Ireland to the Court of Justice of the EU for failing to transpose NIS2.

The Bill can be enacted at any point, and the obligations it carries will not come with a grace period.

Organisations that assess now choose their own timetable. Those that wait will be working to someone else's.

Who is in scope

NIS2 reaches well beyond the utilities and infrastructure operators covered by the first directive. Most medium and large organisations in these sectors are in scope, and smaller organisations can be brought in where they provide a critical service.

Essential entities

Highest obligations and supervision
  • Energy — electricity, gas, oil, district heating, hydrogen
  • Transport — air, rail, water, road
  • Banking and financial market infrastructure
  • Health — providers, labs, pharma, medical devices
  • Drinking water and waste water
  • Digital infrastructure — data centres, cloud, DNS, telecoms
  • ICT service management (B2B)
  • Public administration
  • Space

Important entities

Same measures, lighter supervision
  • Postal and courier services
  • Waste management
  • Chemicals — manufacture, production, distribution
  • Food — production, processing, distribution
  • Manufacturing — medical devices, electronics, machinery, vehicles
  • Digital providers — marketplaces, search engines, social platforms
  • Research organisations
Not sure whether you are in scope, or which category applies? That question is answered in the first two weeks of the assessment.

What NIS2 asks of a board

The directive treats cybersecurity as a governance matter. Three articles carry most of the weight for senior management, and the penalties sit alongside them.

ARTICLE 20

Governance

The management body must approve the organisation's cyber risk-management measures, oversee their implementation, and can be held liable for failures. Board members must undertake cybersecurity training.

Supervisors will expect to see this recorded: decisions, minutes, evidence of oversight.

ARTICLE 21

Risk management

Ten mandatory measures: risk analysis and policies, incident handling, continuity and crisis management, supply-chain security, secure development and vulnerability handling, effectiveness testing, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication.

Each must be proportionate to your exposure and demonstrable on request.

ARTICLE 23

Incident reporting

A significant incident must be reported with an early warning within 24 hours, a notification within 72 hours, and a final report within one month.

That clock only works if you already know what counts as significant, who decides, and how the report is made.

PENALTIES

Fines and personal consequences

Up to €10 million or 2% of global turnover for essential entities; up to €7 million or 1.4% for important entities, whichever is higher.

Authorities can also suspend certifications and, for essential entities, temporarily bar individuals from management roles.

Most organisations cannot yet answer the question at the top of this page.

The reason is rarely a lack of technology. It is that nobody has measured the organisation against the directive, evidence is scattered across teams and suppliers, and the board has never been given a view it can understand and sign off. That is a governance gap, and it can be closed in 90 days.

The NIS2 Readiness Assessment

Fixed scope. Fixed duration. Delivered on the CyberPrism platform with a CRI practitioner guiding your team throughout — so the work is done with you, not to you.

DAYS 1–15

Onboarding and profile

Establish where you start from
  • Confirm scope and entity category
  • Capture business context and dependencies
  • Inherent risk profile — what an incident would cost you
DAYS 15–45

Assessment

Measure against the directive
  • Your team completes the assessment with our practitioner alongside
  • Evidence gathered as you go
  • Mapped to NIST CSF 2.0 and CyFun
DAYS 45–70

Gap analysis and dashboards

See the position clearly
  • Live dashboards against each NIS2 requirement
  • Findings validated and weighted by exposure
  • Executive report drafted
DAYS 70–90

Board and roadmap

Decide what happens next
  • Executive readiness report delivered
  • Prioritised remediation roadmap
  • Board or executive briefing in person

What you receive

Scope and category determination

A documented view of whether you are in scope, as an essential or important entity, and which obligations follow.

Inherent risk profile

What the organisation relies on, where it is exposed, and what an incident would mean for it.

NIS2 readiness assessment

Your position against Articles 20, 21 and 23, evidenced and mapped to NIST CSF 2.0 and CyFun.

Live dashboards

Your assessment, gaps and evidence on CyberPrism for the duration of the programme.

Executive readiness report

Written for a board, not an IT department. Where you stand, what matters most, and what closing the gaps will take.

Prioritised remediation roadmap

Actions ordered by exposure and effort, with owners and timeframes your team can commit to.

Board briefing

A session with your board or executive team, meeting the expectation that management understands and oversees cyber risk.

Threat intelligence tied to your gaps

ThreatLens matches current threat activity and vulnerabilities to where you are weakest, so the roadmap reflects what is happening now.

Built on CyberPrism

CyberPrism holds your assessment, evidence, dashboards and reports in one place — and keeps them current after the assessment ends, rather than leaving you with a document that dates on the day it is delivered.

The assessment is anchored on NIST CSF 2.0 and includes the CyFun framework recommended by the National Cyber Security Centre, so your position is expressed in terms Irish regulators already use. The same platform carries overlays for DORA, the EU AI Act and other regimes — which matters if NIS2 is not the only obligation you face.

NIS2CyFunNIST CSF 2.0DORAEU AI ActThreatLens
NIS2 readiness dashboard with compliance across key areas and incident handling scores
NIS2 — obligation areas, ENISA technical implementation status and incident-handling capability.Click to enlarge

Day 91

The assessment ends with a decision, not a filing cabinet. Most organisations choose one of two paths.

CONTINUOUS ASSURANCE

Keep your CyberPrism environment live. Track remediation, re-assess quarterly, receive ongoing threat intelligence and advisory, and give your board a standing view rather than an annual snapshot. This is the position supervisors will expect once the Bill is enacted.

DELIVER IT YOURSELVES

Take the report and roadmap and work through it with your own team or existing providers. Nothing in the assessment ties you to CRI, and the roadmap is written so it can be handed to whoever will deliver it.

Board oversight of cyber risk is now a standing agenda item, not an annual one.

Common questions

The Bill has not been enacted. Why act now?

Because the obligations are already arriving by other routes. The NCSC has published what it expects of boards. Customers and insurers are writing NIS2 clauses into contracts. And the European Commission is pursuing Ireland through the Court of Justice, which makes enactment a matter of when. Organisations that assess now choose their own timetable.

How much of our team's time does it take?

Typically a few hours a week from a coordinator, plus short sessions with the people who own each area — IT, operations, HR, procurement, legal. Our practitioner does the structuring, mapping and analysis so your team is answering questions, not writing reports.

We already have ISO 27001 or Cyber Essentials. Do we still need this?

Those are good foundations and the assessment credits them. NIS2 adds obligations they do not cover — board accountability, incident reporting timelines, supply-chain measures — and asks for those to be evidenced in the regulator's terms. The assessment shows exactly where your existing certification carries you and where it does not.

Is this an audit?

No. It is a readiness assessment. Its purpose is to give you an accurate position and a plan before any supervisor asks. The evidence base it produces is, however, what you would draw on if one did.

We are not sure we are in scope.

That is settled in the first two weeks. If it turns out you are not in scope, we will tell you — and you will still hold a clear view of your exposure and a short list of sensible actions.

Can our existing IT provider or MSP be involved?

Yes, and usually should be. They hold much of the evidence and will deliver part of the roadmap. We work alongside them; the assessment sits above the technology, not in competition with it.

What does it cost?

The programme is fixed-price for a defined scope, which is confirmed on the scoping call. We will not sell you a longer engagement than you need.

Know where you stand before someone else asks.

A 30-minute scoping call is enough to confirm whether you are in scope, what the assessment would cover for you, and when it could start.

Book a scoping call
CRI partner with eir business
Prefer to talk? Call +353 (0)1 905 3260.