NIS2 Compliance

We guide you through the entire compliance process – from determining whether and to what extent you fall under NIS2, through developing a plan, to implementing specific security measures and documenting them.

Contact

The NIS2 Directive and the amendment to the National Cybersecurity System Act implementing it extend security obligations to further sectors and organisations – including IT service providers and entities within supply chains.

We support companies in clarifying their position with regard to NIS2 and in building a realistic path to compliance – a roadmap – so that regulatory requirements do not hinder the organisation’s day-to-day business operations.

Who is this service for?

NIS2 covers a significantly broader range of organisations than the previous regulation.

  • Companies in sectors covered by NIS2

     

    Energy, healthcare, transport, manufacturing, ICT, waste management and others.

  • IT providers

     

    Managed services, hosting, system maintenance.

  • Software houses

     

    Software developers and development teams.

  • Integrators

     

    Solution providers and implementation specialists.

  • Companies in the supply chain

     

    Subcontractors and partners of essential entities.

We combine compliance with IT implementation

We don’t limit ourselves to consulting and auditing – we actually carry out the work that NIS2 requires and integrate it into ongoing technology projects. This sets us apart from purely audit-focused firms and follows directly from GOTOMA GENERAL’s profile as a general contractor for integrated IT projects.

How do we support companies at every stage?

We don’t limit ourselves to consulting – we actually carry out the work that NIS2 requires of organisations and deliver it in the form of ready-made documents, implemented tools and working procedures.

Determining status and the scope of obligations

We map the organisation’s situation and determine which NIS2 obligations apply to it – with a legal expert where necessary.

Outcome: a clear classification and a list of obligations.

Implementation plan (roadmap)

We identify gaps and assign projects to them – in a version that is clear both for the management board and for the teams.

Outcome: a document demonstrating a structured path to compliance.

Implementation of technical security measures

We close the gaps: monitoring and event logging, incident reporting to CSIRT, access control, backups, updates and testing.

Outcome: working mechanisms, not just words on paper.

Documentation and organisational processes

We develop security and risk management policies, onboarding/offboarding procedures and training with accompanying documentation.

Outcome: a complete set of documents and a team ready for inspection.

Security of software development

For software developers, we integrate security testing into the development lifecycle (SCA, SAST).

Outcome: security built into the process, not checked after the fact.

Maintaining compliance over time

NIS2 means the continuous application of security measures – we provide support in maintaining tools, updating documentation and reporting.

Outcome: readiness for inspection at any time.

What do you get in the end?

Concrete results – ready-made documents, implemented tools and working procedures.

  • Organization status classification

    A clear determination of whether — and as what type of entity (essential/important) — your organization falls under NIS2.

  • Gap map against requirements

    An overview of areas requiring action — from technical measures to documentation and processes.

  • Roadmap to compliance

    An organized plan with priorities, projects, and an implementation timeline.

  • Policies and procedures

    A complete set of documents: security policies, risk management, onboarding/offboarding.

  • Implemented technical safeguards

    Working mechanisms: monitoring, event logging, access control, backups.

  • Support during the final audit

    Preparation of your team and documentation for inspection, plus assistance throughout it.

A plan instead of an audit

There is no such thing as a NIS2 certificate. Instead of a costly preliminary audit, we direct the budget straight into implementation – we define the scope, build a roadmap and close the gaps.

NIS2 in IT projects

We integrate the requirements into ongoing initiatives (ERP, e-commerce) as an assumption rather than a precondition for launch – without putting current projects on hold.

Time to get down to business, let's talk about the project.

Describe your needs and we will come back with a proposal tailored to your business.

Contact