Sample audit report — see how a Hackerbane report is structured. Open the report →

NIS2 compliance

Network and information security readiness for essential and important entities. Hackerbane audits your risk-management measures, supply-chain controls, and incident-handling process against NIS2 and helps you fix what falls short before your authority reviews it.

What NIS2 is

NIS2 is the European Union's second Network and Information Security Directive. It replaces the original NIS rules, widens the list of sectors they cover, and sets a minimum list of cybersecurity risk-management measures every in-scope organisation must have in place: risk analysis, incident handling, business continuity, supply-chain security, secure development, access control, cryptography, and training.

Because it is a directive, each member state transposes it into national law and names a competent authority to supervise it. NIS2 also makes management bodies accountable for approving and overseeing the measures, and sets tight deadlines for reporting significant incidents.

Who it applies to

  • Essential entities: large organisations in sectors such as energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, and public administration.
  • Important entities: medium and large organisations in those sectors and in others such as digital providers, manufacturing, postal services, and ICT service management.
  • Digital infrastructure and ICT service providers, including cloud, data centre, and managed security providers, regardless of where their customers sit.
  • Financial entities already covered by DORA follow DORA for the overlapping requirements. We help you work out which regime governs which system.

What Hackerbane does

  • Gap assessment: we map your existing controls to each NIS2 risk-management measure and to the national law that applies to you, and list what is missing or unevidenced.
  • Technical security audit: penetration testing and code review of the systems that make you an essential or important entity, including blockchain infrastructure and AI systems where they run production.
  • Supply-chain review: we assess the security of your key suppliers and the contractual and technical controls you have over them.
  • Incident handling: we test your detection, escalation, and reporting playbook against the NIS2 deadlines, and check that the evidence you would need is actually being logged.
  • Management oversight: we prepare the briefing your management body needs to approve the measures and show they understand them.
  • Remediation and audit support: fixes are retested, evidence is assembled, and we support you through the authority's review.

What you get

  • A gap report against the NIS2 measures and your national transposition, with priorities and owners.
  • Technical findings with severity, proof for the serious ones, and a fix for each.
  • An evidence pack your competent authority and management body can read.
  • Verified remediation and an updated report once the fixes land.

Who signs off

NIS2 has no single certificate. Your national competent authority supervises compliance and can audit or request evidence. Hackerbane gets your controls and evidence ready for that review; the authority decides whether you meet the directive.

Questions

Are crypto and AI companies in scope of NIS2?
It depends on your sector and size. Digital infrastructure and ICT service providers are in scope directly; financial entities follow DORA where the two overlap; an AI product sold into an in-scope sector will be treated as part of its customers' supply chain. We help you work out which regime applies to which system before the audit starts.
Do you handle incident response?
Hackerbane audits and tests your incident-handling process and the reporting playbook behind it, and the continuous security review retainer keeps auditors who already know your system available for retests after a change or an incident. We are not a managed detection service.
Does ISO 27001 cover NIS2?
It covers a large part of it. An ISO 27001 management system gives you the framework, and many NIS2 measures map onto its controls. NIS2 adds sector-specific obligations, incident-reporting deadlines, and management liability that the standard does not. We run both against the same evidence pack when a client needs both.

Next step

Request an audit

Tell us which sector and entity class you fall under, which systems are in scope, and when your authority expects to see evidence. We will propose a gap assessment and audit plan with an estimate.