NIS 2 strengthens cybersecurity and operational resilience requirements across a wide range of critical sectors.
For entities in scope, it is no longer sufficient for cybersecurity to be managed solely by the IT department. Management must approve the company's security measures, oversee their implementation and possess the necessary knowledge of cybersecurity risk management.
RSM helps you determine whether and how the rules apply to you, identify gaps and translate the requirements into specific processes, controls and responsibilities.
Are you directly in scope, or do you face the requirements through your customers?
The Danish NIS 2 Act covers public and private entities in a number of critical sectors. Companies are classified as essential or important entities depending on factors including their sector, size and importance.
Even if your company is not directly in scope, you may be affected through your customers. Entities in scope must manage risks in their supply chains and impose relevant security requirements on direct suppliers and service providers.
This may result in new requirements relating to contracts, security documentation, incident reporting, resilience and supplier follow-up.
How we help you
Gain an overview
We clarify your scope, key obligations and organisational responsibilities.
This typically includes:
- governance and management responsibility
- cybersecurity risk management
- incident management and reporting
- resilience, backup and recovery
- supplier and supply chain security
- vulnerability management and access control
- cybersecurity training and awareness
The Danish NIS 2 Act requires appropriate and proportionate technical, operational and organisational measures in these areas.
Identify gaps
We assess your existing processes, controls and documentation against the relevant requirements.
You receive a prioritised roadmap showing:
- what is already in place
- where the most significant gaps are found
- which activities should be carried out
- who should be responsible
- how progress can be evidenced
Implement the requirements in practice
If required, we help establish or improve the necessary policies, processes and controls.
The aim is not merely to prepare documentation, but to create an operational security framework that management can govern and that will function during an actual cyber incident.
Do you need to provide customers with assurance regarding your controls?
For suppliers to entities covered by NIS 2, internal policies and self-assessments may be insufficient. Customers may request independent assurance regarding the controls supporting the service.
In these circumstances, an ISAE 3000 report on NIS 2-related controls may be relevant.
The report can be tailored to selected NIS 2-related controls and give relevant customers insight into:
- which systems, services and controls are covered
- how the controls were tested
- whether the controls have been established and implemented
- whether they operated throughout a defined period
- any exceptions identified
An ISAE 3000 report is not an official NIS 2 certification.
Advisory services and any subsequent assurance engagement are planned in accordance with the applicable auditor independence requirements.
A targeted engagement
- Clarification: We assess how the rules affect the company and your services.
- GAP assessment: We identify gaps in processes, controls and documentation.
- Roadmap and implementation: You receive a prioritised plan, and we help implement the necessary measures.
- Assurance: Where required by customers, a separate ISAE 3000 report on NIS 2-related controls may be the next step.
Find out where you stand
Contact us for an initial discussion about your NIS 2 obligations, most significant gaps and need to provide customers with assurance.