We map the organisation’s situation and determine which NIS2 obligations apply to it – with a legal expert where necessary.
Outcome: a clear classification and a list of obligations.
We guide you through the entire compliance process – from determining whether and to what extent you fall under NIS2, through developing a plan, to implementing specific security measures and documenting them.
The NIS2 Directive and the amendment to the National Cybersecurity System Act implementing it extend security obligations to further sectors and organisations – including IT service providers and entities within supply chains.
We support companies in clarifying their position with regard to NIS2 and in building a realistic path to compliance – a roadmap – so that regulatory requirements do not hinder the organisation’s day-to-day business operations.
NIS2 covers a significantly broader range of organisations than the previous regulation.
Energy, healthcare, transport, manufacturing, ICT, waste management and others.
Managed services, hosting, system maintenance.
Software developers and development teams.
Solution providers and implementation specialists.
Subcontractors and partners of essential entities.
We conduct the NIS2 compliance process in stages:
We don’t limit ourselves to consulting and auditing – we actually carry out the work that NIS2 requires and integrate it into ongoing technology projects. This sets us apart from purely audit-focused firms and follows directly from GOTOMA GENERAL’s profile as a general contractor for integrated IT projects.
How do we support companies at every stage?
We don’t limit ourselves to consulting – we actually carry out the work that NIS2 requires of organisations and deliver it in the form of ready-made documents, implemented tools and working procedures.
We map the organisation’s situation and determine which NIS2 obligations apply to it – with a legal expert where necessary.
Outcome: a clear classification and a list of obligations.
We identify gaps and assign projects to them – in a version that is clear both for the management board and for the teams.
Outcome: a document demonstrating a structured path to compliance.
We close the gaps: monitoring and event logging, incident reporting to CSIRT, access control, backups, updates and testing.
Outcome: working mechanisms, not just words on paper.
We develop security and risk management policies, onboarding/offboarding procedures and training with accompanying documentation.
Outcome: a complete set of documents and a team ready for inspection.
For software developers, we integrate security testing into the development lifecycle (SCA, SAST).
Outcome: security built into the process, not checked after the fact.
NIS2 means the continuous application of security measures – we provide support in maintaining tools, updating documentation and reporting.
Outcome: readiness for inspection at any time.
What do you get in the end?
Concrete results – ready-made documents, implemented tools and working procedures.
A clear determination of whether — and as what type of entity (essential/important) — your organization falls under NIS2.
An overview of areas requiring action — from technical measures to documentation and processes.
An organized plan with priorities, projects, and an implementation timeline.
A complete set of documents: security policies, risk management, onboarding/offboarding.
Working mechanisms: monitoring, event logging, access control, backups.
Preparation of your team and documentation for inspection, plus assistance throughout it.
There is no such thing as a NIS2 certificate. Instead of a costly preliminary audit, we direct the budget straight into implementation – we define the scope, build a roadmap and close the gaps.
We integrate the requirements into ongoing initiatives (ERP, e-commerce) as an assumption rather than a precondition for launch – without putting current projects on hold.
Describe your needs and we will come back with a proposal tailored to your business.