hyperlecture lab

Offer

NIS2 and GDPR compliance

Six weeks to establish your real exposure, build a compliance plan proportionate to your size and assemble a compliance file ready for an inspection.

Duration
6 weeks
Format
Fixed scope
Deliverable
Exposure assessment, compliance plan, compliance file ready for an inspection
Who it is for
SMEs in scope, or suppliers to entities in scope

A customer sends you a forty-question security questionnaire because they are covered by NIS2 and have to check their suppliers. A user asks what you do with their data. An insurer asks about your backups. You have no written answer, and you are not sure whether the first text applies to you, nor whether you apply the second beyond having put a banner on the website.

The engagement starts with the only question that matters: are you covered, and on what basis. NIS2 targets specific sectors and sizes, and reaches by ricochet everyone who supplies a covered entity. The GDPR applies to everyone, but not in the same way to a ten-person organisation and to a group. The qualification is written, it cites the texts, and it closes the door on the oversized measures you will be offered elsewhere.

Then comes the current state, then the file. The file is not a binder of copied policies: each document describes what you actually do, with your tools and your suppliers, so that it holds on the day someone reads it next to reality. The plan ranks what remains by urgency and cost, so that you can decide what you handle now and what you defer knowingly.

What you keep at the end: the qualification note, the processing record, the policies and procedures, the reviewed contracts and the plan, in your own files, with a yearly update procedure you can follow on your own. The price is set in the written note that follows the first call, with the qualification step priced separately.

What you get

  • A written, reasoned answer to the first question: are you covered by NIS2 directly, indirectly because one of your customers is, or not at all. If the answer is no, the engagement stops there and you pay for that step only.
  • Your record of personal data processing, as the GDPR requires you to keep it: what you collect, why, for how long, who has access, and with which processors.
  • An inventory of your existing security measures, set against what the two texts expect of an organisation your size, with the gaps named and ranked.
  • A proportionate compliance plan: what must be done within the month, the quarter, the year, with the cost of each action and the person who can carry it.
  • The documents to have to hand on the day of an inspection or a question from a customer: security policy, incident procedure, reviewed processor contracts, notices and consents on the website.
  • A standard answer to the security questionnaires your NIS2-covered customers send you, so that each request does not become a project again.

How it runs

  1. Weeks 1 and 2: qualification

    A reading of your activity, your customers and your contracts against the sectors and thresholds of the two texts. You receive a one-page note saying whether you are covered, on what basis, and what follows from it. This is the first decision point.

  2. Weeks 3 and 4: current state

    Interviews with you and with the person who runs your tools, review of the data you hold, of access, backups and contracts with your suppliers. Each gap is written down with the text it rests on.

  3. Weeks 5 and 6: file and plan

    Drafting of the record, the policies and the procedures, then of the compliance plan. A one-hour video call to go through it. You leave with the complete file and the list of what remains to be done, in order.

Guides linked to this offer

All guides

No linked guide yet.

A digital problem to put on the table?

Thirty minutes on video. You set out the situation, I say what I understand of it and whether I can help.