NIS2 compliance without the panic
The EU cybersecurity directive now covers thousands of Latvian companies. We audit the gap, write the policies and set up the technical controls, so you pass checks instead of collecting fines.
What you get out of it
Clear gap picture
A structured audit shows exactly where you stand against NIS2 requirements and what to fix first.
Paperwork done
Risk register, security policies and incident procedures written for your company, not copied from a template.
Real technical controls
Backups, access control, network segmentation and monitoring implemented on your actual infrastructure.
Ongoing readiness
Re-checks after fixes and support during supervisory reviews, so compliance does not decay.
What the service includes
- Gap assessment against NIS2 requirements
- Risk register and security policy set
- Technical controls plan for your infrastructure
- Incident response playbook and reporting flow
- Management report in plain language
- Re-assessment after the fixes are in place
Scope defines the price: request a quote and we will size the project with you.
How it works
- 1
Scoping call
We map your services, systems and whether NIS2 treats you as essential or important.
- 2
Audit and report
We assess people, processes and technology, then hand over a prioritized gap report.
- 3
Fix and comply
We implement the controls with your team and prepare you for supervisory checks.
NIS2 questions
Does NIS2 apply to my company?
NIS2 covers essential and important entities in sectors like energy, transport, health, digital infrastructure, manufacturing and public services, and the thresholds pull in many mid-size companies that never dealt with this kind of regulation before. Whether you fall under it depends on your sector, your size and the services you actually provide, so a guess is not a safe answer. A half-hour scoping call with our engineers in Riga settles it definitively for your case: we map what you do, check it against the directive's categories and tell you honestly if you are outside its scope.
What is the NIS2 directive in simple terms?
NIS2 is the EU cybersecurity directive that obliges companies in critical sectors to manage cyber risks, protect their infrastructure and report serious incidents. A directive itself does not bind you directly: each member state turns it into national legislation, and in Latvia that is the National Cybersecurity Law, so compliance is a legal duty, not a recommendation. In practice it means your company must know its risks, have written rules for handling them and be able to react when something goes wrong. Our service covers the audit, the paperwork and the technical controls in one project, so you do not have to assemble three vendors for one obligation.
What are the main NIS2 requirements?
The core areas are risk management, security policies, incident response and reporting, business continuity with backups, supply chain security, access control and management accountability. Note that the list mixes paperwork with engineering: a policy binder without working backups fails, and good backups without documented procedures fail too, because supervisors look at both. Management accountability means the leadership has to understand and approve the risk decisions rather than delegate everything to IT. Our gap audit checks every one of these areas on your real infrastructure and processes, and hands you a prioritized fix list within 2 to 4 weeks, so you know what to tackle first and what can wait.
How long does a NIS2 gap audit take?
A typical gap assessment takes 2 to 4 weeks. The exact duration depends on the size of your infrastructure, how many systems and processes we need to review and how quickly your team can answer questions and provide access. During that time we interview the people responsible, examine configurations and documentation, and compare everything against the NIS2 requirements. The fixes themselves are planned separately after the report, because their timeline depends entirely on what the audit finds: some gaps close quickly, others need budgeting and scheduling. Once your team has implemented the changes, we run a re-assessment to confirm the gaps are actually closed rather than just marked as done.
What do we get at the end of the project?
You receive a gap report with clear priorities, a written set of security policies, an incident response playbook and technical controls implemented on your actual infrastructure, followed by a re-assessment once the fixes are done. The policies are written for your company and its real processes, not copied from a template, because supervisors notice generic paperwork quickly. The playbook tells your people who does what and who reports where when an incident happens, so nobody improvises under pressure. Management additionally gets a plain-language report without technical jargon that can be shown to the board or a supervisory authority as evidence that the work was actually done.
How much does NIS2 compliance cost?
There is no fixed price list, because the honest answer depends on scope: how many systems and locations you run, how complex your infrastructure is and how much is already in place. A company with documented processes and working backups needs far less work than one starting from zero, and it would be wrong to charge both the same. That is why we start with a half-hour scoping call, size the project together with you and only then put a number on it. Request a quote through the site, describe your setup briefly and we will come back with a proposal you can compare against doing it internally.
What happens if we ignore NIS2?
Supervisory authorities can order audits, issue binding instructions and impose significant fines, and company management can be held personally accountable for ignoring the obligations. There is also a quieter risk: an unmanaged incident tends to surface anyway, through customers, partners or the mandatory reporting of others, and explaining to a supervisor why nothing was in place is a much worse position than showing a documented plan with known gaps. Doing nothing does not make the duty disappear, it just moves the cost to the worst possible moment. A 2 to 4 week gap audit is the cheap way to find out how exposed you actually are before anyone else does.
Can you also run our security after the project?
Yes. Compliance has a shelf life: people change, systems get replaced and a control that passed the audit can quietly stop working over time. For the operational side we offer managed Fortinet firewalls and 24/7 monitoring run by our own team in Riga, so someone is actually watching your infrastructure instead of just keeping a report on file. We operate our own Tier 3+ data center in Riga and our own network AS58269, which means the engineers who audited you can also keep the controls running afterwards. Write to support with what you want covered and we will propose an operational setup that matches the audit findings.