SecOps ForcesNIS2: what actually changes

Compliance

NIS2 does not askfor an annual report.It asks for evidence.

The directive expects risk management over time, not a snapshot taken once a year. That shift is what surprises most: a dated audit does not demonstrate an ongoing process, and the process is what you will be asked to prove.

Information page · No offer on this page · Updated August 2026

What changes in practice

Four shifts
that affect everyone.

We will not walk through the text article by article — others do that better, and your legal counsel is better placed for it. Here is what we observe, on the technical side, at organizations preparing for it.

Scope

Many more entities covered

Well beyond traditional operators, a large number of mid-sized companies fall in scope, often without knowing it. That question is settled with the competent national authority, not with a vendor.

Supply chain

Your customers now audit you

Even out of scope, a company receives questionnaires from customers who are in scope: the requirement spreads through contracts long before regulation.

Leadership

Accountability moves up

The topic stops being fully delegable to IT: management bodies are explicitly involved in risk management.

Continuity

Evidence must be continuous

A dated finding is no longer enough. What counts is showing that gaps are detected, handled and verified over time.

What we cover

Our part of the subject, clearly bounded.

Email security

Anti-spoofing, domain authentication, monitoring of senders and lookalike domains: the most used way in, documented continuously.

DMARC, SPF, DKIM

Microsoft 365 configuration

Identities, privileged access, sharing, logging: gaps measured, fixed, then monitored so they do not come back.

300+ controls

Timestamped evidence

The history of gaps and fixes, exportable: enough to answer a customer or insurer questionnaire without a week of manual collection.

PDF & CSV

Where to start

Measure before you declare.

The first question on any questionnaire is about your actual state. It is better to know it before answering.

Microsoft 365 audit

The dated assessment that serves as a starting point: 300+ controls, scanned in 30 to 60 minutes.

Optional · €2,500

Frequently asked

Common questions about NIS2.

Are we in scope?
That is a question for your legal counsel and the competent national authority, not for us: scope depends on your sector, your size and your role in supply chains. What we do observe is that many out-of-scope companies still receive questionnaires from customers who are in scope.
Is an annual audit enough?
To produce a finding, yes. To demonstrate risk management over time, no: between two audits the configuration moves, and nothing documents it. That gap is exactly what continuous monitoring fills.
Can you make us compliant?
Nobody can honestly promise that: compliance covers organization, governance, incident handling and supply chain, far beyond technology. We cover the security of your email and your Microsoft 365, and we produce the corresponding evidence. The rest belongs to your organization and your advisers.
What do insurers ask on top?
Most often: multi-factor authentication everywhere, tested backups, privileged access management and usable logging. Our reports cover several of these directly, with the dated history that is usually missing.

Where do you stand today?

Thirty minutes to look at your situation. If your deadline is regulatory, we will tell you frankly what falls to us and what does not.