NIS2 DIRECTIVE & LATVIAN NKDL COMPLIANCE

Gap analysis, risk management frameworks, supply chain controls, and incident reporting procedures for essential and important entities.

Last reviewed: August 2026 (ENISA & National Cyber Security Guidelines)

Best suited forOrganisations determining status or responding to a regulator request
Primary outcomeApplicability and boundary-assumption document for legal approval
Scope1. Entity classification (Essential vs. Important) and scope confirmation
Typical timingTiming depends on the number of systems, roles, environments, available documentation and agreed constraints.

Is this right for you?

When to choose this service

Organisations determining status or responding to a regulator requestEssential and important entities building their first complete programmeLeadership required to demonstrate governance, oversight and evidenceCompanies preparing for an audit, self-assessment or incident exercise

NIS2 Implementation Roadmap

  • 1. Entity classification (Essential vs. Important) and scope confirmation
  • 2. Baseline GAP Analysis evaluating technical controls against national law mandates
  • 3. Developing risk management, supply chain security, and cryptography policy frameworks
  • 4. Setting up incident notification workflows aligned with CSIRT / CERT requirements (24h early warning, 72h report)

What you receive

  • Applicability and boundary-assumption document for legal approval
  • Requirement and control matrix with status, owner, evidence and deadline
  • Registers of critical services, systems and suppliers
  • Cyber-risk assessment and prioritised treatment plan
  • Incident and regulator-communication playbook with exercise scenario
  • Leadership reporting and training materials
  • Readiness report with gaps, quick improvements and long-term roadmap

Delivery flow

From scope to a verified result

  1. Scope and safety boundaries. Confirm the objective, systems, roles, environment, exclusions, authorised actions and emergency stop contact.

  2. Information and access. Receive only the documentation, accounts, configuration or evidence needed for the work through a secure channel.

  3. NIS2 Directive Compliance Assessment. We map existing security controls against regulatory mandates and incident reporting workflows.

  4. Validation and reporting. Confirm findings, remove false positives and connect each risk to business impact and an accountable owner.

  5. Workshop and follow-through. Explain priorities, answer delivery teams, agree remediation timing and perform a retest where included.

Before we start

Frequently asked questions

How long does an engagement usually take?

Timing depends on the number of systems, roles, environments, available documentation and agreed constraints. After initial information is received, the scope states the stages, customer involvement and a specific schedule.

What should we prepare before work starts?

Usually we need a system or process owner, current scope, access and test accounts, architecture or process information, critical business scenarios and an emergency contact. Never send passwords through a normal website form.

Will we receive only a technical report?

No. The standard output includes an executive summary, prioritised detail, evidence, remediation guidance and a results workshop. Where relevant, the engagement includes a retest or implementation roadmap.

Can BR²SEC legally determine that NIS2 or Latvian law applies to us?

We can structure the facts, sectors, services, size, dependencies and possible statuses and identify uncertain points. A binding conclusion should be validated by qualified legal counsel and, where needed, the competent authority.

Is policy documentation enough?

No. Readiness requires operating technical and organisational controls, trained people, incident and supplier processes, management oversight and retained evidence. Documentation must describe what actually happens.

Related next steps