Legal diagnosis for NIS2

NIS2 gap analysis: which obligations still require attention?

An NIS2 GAP analysis shows how the current governance, risk approach, processes and security measures relate to the NIS2 obligations and the Dutch Cybersecurity Act. Kynexis Information Security brings together strengths, gaps and dependencies in a prioritized improvement plan, allowing governance and organisation to focus on deciding which step to take.

Do you recognize this?
  • The applicability of NIS2 is clear, but the translation into concrete measures and evidence is fragmented.
  • Board-level responsibility, duty of care and chain control are not yet invested everywhere.
  • There's a lot of information about the Dutch Cybersecurity Act, but no prioritized organizational image.
  • You want to know which improvements are needed first and what is already demonstrably in order.

What are the risks? Without a coherent NIS2 GAP analysis, organisations can carry out many separate actions while important obligations, dependencies or evidence are not given sufficient attention.

Our promise of service

An actual NIS2 image with an executable improvement plan

The NIS2 GAP analysis links the Dutch Cybersecurity Act to your governance, risks, measures, suppliers and evidence.

  • Strengths and gaps per obligation
  • Risk-driven priorities for improvement
  • Roadmap with ownership and need for proof

NIS2 GAP Analysis

What is NIS2 GAP analysis?

An NIS2 GAP analysis shows how the current governance, risk approach, processes and security measures relate to the NIS2 obligations and the Dutch Cybersecurity Act. Kynexis Information Security brings together strengths, gaps and dependencies in a prioritized improvement plan, allowing governance and organisation to focus on deciding which step to take.

FOR WHOMFor essential and important entities
WHENWhen does this NIS2 GAP analysis fit?
RESULTA substantiated baseline assessment with priorities and next decisions

When does this service fit?

When does this NIS2 GAP analysis fit?

Choose this route when you don't just want to orient, but want to know where the organisation is. The terms NIS2 baseline assessment, NIS2 compliance check and NIS2 GAP analysis often meet the same demand in the market. Kynexis Information Security therefore brings that intention together on one full service page, with scope and depth appropriate to your organisation.

For essential and important entitiesFor governance and oversightFor critical chain suppliers

Research area

The key issues of NIS2 in a single coherent assessment

We determine in advance which entities, services, locations, processes, systems and suppliers are being investigated. The assessment shall use relevant documentation, interviews with owners and selected evidence from practice.

Governance and governance

Responsibility, knowledge, decision-making, oversight and periodic reporting.

Risk management measures

Policy, risk analysis, incidents, continuity, access, cryptography and basic security.

Incident Notification

Detection, classification, escalation, reporting periods, communication and reporting.

Suppliers and Chain

Selection, agreements, monitoring, critical dependencies and chain risks.

Continuity and recovery

Backup, crisis organisation, recovery ability, practice and learn from disruptions.

Evidence and improvement

Demonstrability, ownership, registration, follow-up and board-level direction.

Your result

A substantiated baseline assessment with priorities and next decisions

You will receive a report that distinguishes between what is demonstrably present, which requires confirmation and which GAPs require improvement. The outcome allows a realistic choice between direct implementation, in-depth research and subsequent independent review.

  • Scope, principles and information assessed
  • NIS2 GAP matrix for relevant liabilities and risks
  • Findings on governance, measures, suppliers and incident processes
  • Priorities for risk, relevance, dependencies and feasibility
  • Actions with owner, need of proof, order and next decision
  • Management discussion with board-level decision-making points
KYNEXISNIS2 GAP Analysis
4Urgent GAP9Under development10At Level
FocusDuty of care and board-level assuranceRisk-driven and enforceable

How we work

This is how we perform the NIS2 GAP analysis

  1. 01

    Define Scope and Input

    Identify entity status, critical services, chain position, research questions, documents, interlocutors and evidence sources.

  2. 02

    Research documents and practice

    Review policies, risk analyses, decisions, registrations and technical or organisational evidence and discuss with owners.

  3. 03

    Differences and risks

    Identify what is demonstrable, what still requires verification and which shortcomings have the greatest impact or dependence.

  4. 04

    Priorities and follow-up decisions

    Report, actions, owners, need of evidence and discuss logical order with the board and management.

NIS2 implementation route

Training, diagnosis and execution remain recognizable from each other

A Quickscan supports the first orientation, board-level training builds up knowledge and the NIS2 GAP analysis then examines the design, available evidence and improvement priorities independently and more thoroughly.

01 ORIENTATION

NIS2 Quickscan

Compact to identify the first areas of concern and what follow-up step is appropriate.

View this phase →
04 IMPLEMENTATION

NIS2 implementation

Improving measures, processes, suppliers' agreements and evidence in a targeted way.

View this phase →
05 ASSESSMENT

NIS2 audit

Assess the demonstrable effect of established control with evidence.

View this phase →
06 ASSURANCE

Internal control

Use internal control to organise progress, deviations, evidence and board-level reporting on a recurring basis.

View this phase →
Make your next step concreteHave NIS2 run GAP analysis?

Discuss what you want to explore, what parts fall within the scope and what depth fits your organisation.

Schedule an intake call

Frequently Asked Questions

Practical answers on NIS2 GAP Analysis

What is an NIS2 GAP analysis investigating?

The analysis examines relevant governance, risk analysis, technical and organisational measures, supplier control, incident processes, continuity, documentation and evidence. The precise selection follows from the pre-arranged scope.

What is the difference between a NIS2 Quickscan and a NIS2 GAP analysis?

The NIS2 Quickscan is a compact first orientation on points of attention and follow-up steps. The NIS2 GAP analysis examines the agreed scope more thoroughly with documents, conversations and selected evidence and provides a prioritized improvement plan.

What is the difference between a NIS2 baseline assessment, compliance check and GAP analysis?

These terms are often used for the same decision question: Where are we and what's missing? Kynexis Information Security therefore brings them together in one route. A slight baseline assessment can be more compact; A complete GAP analysis explores more context and evidence. Scope, depth and result are explicitly agreed in advance.

Is the GAP analysis intended only for NIS2 entities?

No. Suppliers and organisations that are contractually required to meet NIS2-related requirements may also use the analysis to set up their chain obligations and evidence in a targeted manner.

What is the difference with a risk analysis information security?

The NIS2 GAP analysis compares the current facility with relevant NIS2 and Cybersecurity legislation obligations. A risk analysis information security is primarily based on threats, scenarios, opportunity, impact and risk appetite. Both can complement each other, but have a different starting point.

How do board member training and NIS2 GAP analysis relate to each other?

Training, briefing, masterclass and webinar through NIS2BoardroomTraining.nl build up board-level knowledge and skills. The NIS2 GAP analysis and baseline assessment of Kynexis Information Security investigates the organisation's design, evidence and priorities. In this way, learning goals, research results and evidence remain clearly distinguished.

Can an existing ISO 27001-ISMS be reused?

Yes. A well-equipped ISMS offers many useful building blocks. The GAP analysis makes it visible which NIS2 specific topics or additions are still needed.

What happens after the report?

You determine which actions are carried out internally and where Kynexis supports Information Security based on risk and feasibility. This can be about NIS2 implementation, in-depth research, an audit or periodic assurance. The diagnosis remains recognizable in substance from subsequent implementation guidance.

Wouter Parent

NIS2 requires demonstrable control. A checklist with no ownership, proof and follow-up is not very valid in an incident.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates