NIS2 DIRECTIVE & LATVIAN NKDL COMPLIANCE
Gap analysis, risk management frameworks, supply chain controls, and incident reporting procedures for essential and important entities.
Last reviewed: August 2026 (ENISA & National Cyber Security Guidelines)
Is this right for you?
When to choose this service
NIS2 Implementation Roadmap
- 1. Entity classification (Essential vs. Important) and scope confirmation
- 2. Baseline GAP Analysis evaluating technical controls against national law mandates
- 3. Developing risk management, supply chain security, and cryptography policy frameworks
- 4. Setting up incident notification workflows aligned with CSIRT / CERT requirements (24h early warning, 72h report)
What you receive
- Applicability and boundary-assumption document for legal approval
- Requirement and control matrix with status, owner, evidence and deadline
- Registers of critical services, systems and suppliers
- Cyber-risk assessment and prioritised treatment plan
- Incident and regulator-communication playbook with exercise scenario
- Leadership reporting and training materials
- Readiness report with gaps, quick improvements and long-term roadmap
Delivery flow
From scope to a verified result
Scope and safety boundaries. Confirm the objective, systems, roles, environment, exclusions, authorised actions and emergency stop contact.
Information and access. Receive only the documentation, accounts, configuration or evidence needed for the work through a secure channel.
NIS2 Directive Compliance Assessment. We map existing security controls against regulatory mandates and incident reporting workflows.
Validation and reporting. Confirm findings, remove false positives and connect each risk to business impact and an accountable owner.
Workshop and follow-through. Explain priorities, answer delivery teams, agree remediation timing and perform a retest where included.
Before we start
Frequently asked questions
How long does an engagement usually take?
Timing depends on the number of systems, roles, environments, available documentation and agreed constraints. After initial information is received, the scope states the stages, customer involvement and a specific schedule.
What should we prepare before work starts?
Usually we need a system or process owner, current scope, access and test accounts, architecture or process information, critical business scenarios and an emergency contact. Never send passwords through a normal website form.
Will we receive only a technical report?
No. The standard output includes an executive summary, prioritised detail, evidence, remediation guidance and a results workshop. Where relevant, the engagement includes a retest or implementation roadmap.
Can BR²SEC legally determine that NIS2 or Latvian law applies to us?
We can structure the facts, sectors, services, size, dependencies and possible statuses and identify uncertain points. A binding conclusion should be validated by qualified legal counsel and, where needed, the competent authority.
Is policy documentation enough?
No. Readiness requires operating technical and organisational controls, trained people, incident and supplier processes, management oversight and retained evidence. Documentation must describe what actually happens.
Related next steps
Baltic States
Coordinate technical security testing in one unified Baltic scope while handling national legal nuances (NIS2, local CERTs) cleanly per country.
Cybersecurity Audit
Independent assessment of technical controls, governance, and architecture against recognized baselines.
Incident Response
Prepare your organization for cyber incidents before they happen: response retainer readiness, playbooks, and tabletop simulation exercises.
Critical Infrastructure
Cybersecurity frameworks engineered for manufacturing, energy, logistics, and utility operators across the Baltics.