NIS2 process
For NIS2, the process focuses on applicability, security measures, risk management, incidents, suppliers, continuity, and evidence useful for management or discussions with consultants and auditors.
View NIS2 stepsThe same core workflow is used for NIS2 and ISO/IEC 27001: we collect structured information, assess readiness, organize evidence, and prepare human-reviewed recommendations. The difference comes from the selected framework, deliverables, and depth of analysis.
For NIS2, the process focuses on applicability, security measures, risk management, incidents, suppliers, continuity, and evidence useful for management or discussions with consultants and auditors.
View NIS2 stepsFor ISO/IEC 27001, the process focuses on the ISMS scope, risk assessment, risk treatment plan, controls, evidence, and Statement of Applicability.
View ISO 27001 stepsRegardless of the selected framework, the ConformityAgent process follows the same core logic: structured information, analysis, recommendations, human review, and management-ready deliverables.
The company submits basic information about the organization, sector, size, technology context, and reason for the request.
We determine whether the request concerns NIS2, ISO/IEC 27001, or a combined package. We clarify the assessment scope and expected level of detail.
The client completes a questionnaire adapted to the selected framework. Questions are grouped around areas such as governance, risks, access, incidents, suppliers, backup, continuity, and evidence.
The answers are analyzed to identify the current readiness level, covered areas, gaps, and remediation priorities.
For standard or advanced packages, relevant evidence can be structured: policies, procedures, registers, technical documents, responsibilities, and actions.
The platform prepares a structured draft of the report or deliverables. The human team reviews consistency, adjusts recommendations, and checks whether the result is usable.
The client receives a report or preparation package that can support internal decisions, remediation planning, and discussions with consultants, auditors, certification bodies, or legal partners.
For NIS2, the focus is on understanding the directive’s applicability, readiness against relevant security measures, risk management, incident response, supplier security, and evidence that can support management decisions.
For ISO/IEC 27001, the focus is on structuring the Information Security Management System, defining the ISMS scope, risk assessment, risk treatment plan, controls, evidence, and Statement of Applicability.
For combined packages, we work with a shared evidence structure. The same policies, registers, procedures, controls, and documents can support both NIS2 readiness and ISO/IEC 27001 preparation. The objective is to avoid duplicated work and build a reusable compliance base.
View combined package pricingConformityAgent provides readiness, gap analysis, evidence organization, and compliance management support services. The process does not represent an official audit, accredited certification, legal advice, or a guarantee of compliance. For formal audits, certification, or legal opinions, we can discuss collaboration with auditors, certification bodies, lawyers, or specialized consultants.