NIS2 / cyber-resilience evidence review

Make the NIS2 questions in your operating perimeter explicit.

A scoped service for organisations that need to organise cybersecurity governance, risk measures, incident evidence and cross-border responsibilities around a defined context.

Who this is for

Security and resilience leads

People responsible for security measures, incident readiness, suppliers and evidence across an operating environment.

Leadership and compliance teams

Owners who need a bounded view of responsibilities, dependencies and questions requiring local legal interpretation.

Questions this addresses

An unclear operating perimeter

Entities, services, suppliers and dependencies are not yet connected to one evidence and responsibility picture.

Evidence under pressure

Incident, continuity, risk and reporting records need to be located, related and tested against the agreed question.

What we examine

Governance and accountability

The selected roles, decisions, risk process, security measures and oversight records in the engagement perimeter.

Operational evidence

Incident handling, continuity, supplier dependencies, access, monitoring and improvement records relevant to the question.

What you receive

Responsibility and evidence map

A structured view of entities, services, owners, dependencies and relevant evidence sources.

Readiness action register

A bounded register of open questions, evidence gaps and proportionate next actions for the agreed context.

What success looks like

Clear ownership

The organisation can identify who owns each priority question and which evidence supports the current view.

Traceable response path

Incident and resilience questions have a documented next verification step and escalation route.

Cross-border perimeter

Entity and service boundaries

Cross-border entities, critical dependencies, suppliers and evidence custodians are recorded explicitly.

Central and local coordination

Common security themes are separated from local authority, reporting and language questions.

Limits and dependencies

Local transposition matters

The review does not decide national applicability or replace advice on local implementation and reporting duties.

No blanket conclusion

The output is limited to the entities, services, suppliers, records and time window agreed for the assignment.

Engagement levels

Readiness review

A first, bounded review of roles, evidence and open questions. It identifies what to clarify; it is not assurance, an audit or a certification.

Assurance

An evidence-led conclusion for the agreed scope, evidence date and criteria. It does not create a universal compliance conclusion.

Audit

A more formal examination of agreed criteria, records and controls. The audit scope, method and reporting basis are set in the engagement letter.

Certification

Certification is a separate route performed by an appropriate certification body. This service does not issue a certificate or replace that body’s process.

Scope note

This is a bounded evidence review around selected NIS2-related questions. It is not legal advice, an audit opinion, regulatory approval or a certification.

Official contacts

Maison Sasson ltd - United Kingdom

Email: info@ai-eu-act.xyzWhatsApp: +393381639136Legal entity: Maison Sasson ltd - United Kingdom