Q1 2026 Security & Compliance Report44 incidents, $482M in losses, insights from 11 industry leaders.
Read the report

NIS2 non-compliance is now a deal-blocker

Regulated buyers are pushing NIS2 obligations down their supply chains. If you can't show evidence, the deal waits — or moves to someone who can. Hacken gets you procurement-ready in weeks.

  • Know if NIS2 applies to you — in 2 weeks
  • Board-ready gap report, risk register & roadmap
  • Evidence pack that passes buyer due diligence
  • EU-regulatory track record: DORA, MiCA, NIS2 in-house
2017
securing Web3 leaders since
2,080
security assessments delivered
ISO 27001
2022 certified (SwissCert)
DORA · MiCA
EU-regulation readiness, in-house
BybitEBSiETH FoundationMetaMaskOKXSuiForgeADGM

NIS2 is now a procurement requirement

NIS2 expanded its scope: more sectors, higher security, quicker reporting, and risk oversight (Art. 20). Art. 21(2)(d) states a regulated entity is responsible for its critical suppliers' security, which your customer transfers to you in writing.

It shows up in three ways: security questionnaires that stall procurement, contract clauses you need to evidence, and a 24-hour / 72-hour incident-reporting clock most teams treat as "report early and resubmit later".

Dmytro Yasmanovych

Dmytro Yasmanovych

Head of GRC & Security Operations, Hacken

"NIS2 stopped being only a compliance line item the moment regulated buyers started asking suppliers to prove it. For most vendors selling into EU critical infrastructure, finance, healthcare, energy, and digital infrastructure, readiness is now a condition of doing business."

Are your supplier qualifications ready?

EU vendor contracts include a NIS2 clause. Show your readiness to keep business moving.

What NIS2 non-compliance costs

Lost and stalled deals

Buyers need NIS2 security evidence before signing. Without it, procurement stalls.

Management accountability

NIS2 assigns cybersecurity oversight to management, making it a board-level responsibility.

Incident-reporting exposure

Warning in 24h, notify in 72h. Many organizations lack this workflow.

Supply-chain liability

You are responsible for your suppliers' security, and your customers for yours.

Regulatory penalties

Fines can reach €10 million or 2% of global turnover for key entities, with varying penalties by country.

Reputational damage

A mishandled incident or a failed due diligence review erodes customer and partner trust quickly.

Are you in scope? Many EU suppliers are unaware

NIS2 affects you directly if in a covered sector, or indirectly through your customers.

Regulated entities

Direct scope

Confirm if you're an essential or important entity in one of NIS2's 18 sectors and your obligations.

  • Energy, transport, water & waste
  • Healthcare & medtech
  • Banking, fintech & payments
  • Digital infrastructure, cloud & data centers
  • DNS / TLD / CDN / trust services
  • Manufacturing, chemicals, food
  • Public administration & research

Critical suppliers

Indirect scope

Your regulated customers must manage supply-chain security under NIS2, affecting procurement.

  • SaaS & software vendors
  • Cloud / DevOps & MSP / MSSP
  • Data processors & AI vendors
  • Cybersecurity vendors
  • Web3 / blockchain infrastructure
  • Payment & fintech vendors
  • UA & Eastern-European tech selling into the EU

Not sure which applies to you?

The NIS2 pressure point in your industry

Energy

Energy

OT/ICS environments require high supervision.

Health & medtech

Health & medtech

Patient data and device risk under tight timelines.

Banks & fintech

Banks & fintech

NIS2 overlaps heavily with DORA.

Cloud & digital infra

Cloud & digital infra

Default dependency for regulated buyers.

SaaS suppliers

SaaS suppliers

Deals stalling on security questionnaires.

How we get you ready

We map your posture to NIS2 domains and show gaps.

NIS2 requirements

  • Governance and risk management
  • Incident handling and reporting
  • Business continuity and cryptography
  • Supply-chain security

What Hacken delivers

  • Board accountability model, risk framework, and NIS2 control matrix with owners.
  • Detect, triage, report workflow, IR procedure, and tabletop exercise.
  • BC/DR, backup review, cryptography, and access checks with validation.
  • Vendor risk tiering, security clauses, due diligence, and evidence pack.

Our methodology

A defined five-step path from first scoping call to mock exam — so you know exactly how the engagement runs before you commit.

Phase 1

Scope & applicability

Classify essential vs important; map direct and indirect exposure.

Phase 2

Control mapping

Map posture to the 12 NIS2 control domains with owners.

Phase 3

Evidence & validation

Interviews, evidence, light validation, maturity 0–5.

Phase 4

Gap analysis & risk

Gap report, risk register, prioritized remediation roadmap.

Phase 5

Report & board readiness

CISO findings and audit-ready pack.

Then sustain

Quarterly reviews, evidence maintenance, vendor reviews, and event-driven re-assessment via a vCISO retainer — readiness stays current as you, your suppliers, and the law change.

Deliverables for buyers and the board

NIS2 applicability and scope memo
NIS2 control matrix (12 domains)
Maturity score (0–5 per control)
Gap report and executive summary
Risk register
Prioritized remediation roadmap
Incident-reporting (24h/72h) readiness
Supplier security review
Evidence checklist & room
Board presentation

Where to start with NIS2 directive

Five engagements on readiness. Start with a scope check or gap assessment.

Popular

NIS2 Gap Assessment

For: companies that know they're in scope and need to know what to fix first.

3-6 weeksPricing scoped per engagement

NIS2 Scope Check

For: teams that need a fast, low-commitment applicability answer.

1-2 weeksStart here if unsure

NIS2 Audit Readiness

For: entities heading into a formal audit or heavy procurement scrutiny.

6-12 weeksPricing scoped per engagement

NIS2 Enterprise Readiness

For: groups standardizing readiness across multiple entities or jurisdictions.

8-16 weeksPricing scoped per engagement

Also available:

NIS2 Supplier Readiness

the procurement-focused track for vendors selling into regulated buyers.

NIS2 Managed Compliance / vCISO

quarterly evidence maintenance and re-assessment after the initial engagement.

A track record you can verify

12

NIS2 control domains assessed per engagement.

2 weeks

to a NIS2 applicability answer with the scope check

2,080

security assessments since 2017 in regulated sectors

Client scenario:

Deals were stalling on regulated buyers' NIS2 supply-chain security questionnaires. The vendor had controls in place but couldn't evidence them in the format buyers required. A Supplier Readiness engagement produced a control narrative, a structured evidence folder, and pre-filled due-diligence answers mapped to each buyer's specific requirements.

Result:
procurement moved forward — contracts advanced within two weeks of the evidence pack being delivered.

Composite based on real engagements. A case study is available under NDA.

Why regulated and high-growth companies choose Hacken

ISO 27001:2022 certified

With ISO and CCSS Lead Auditors on the team, we hold the same discipline we assess you against.

Active in standards bodies

We collaborate with EU and global regulators to ensure our guidance reflects NIS2's interpretation.

EU-regulatory experience

We already run DORA and MiCA in-house and apply the same programme to NIS2.

Controls we verify

Pentesters and DevSecOps engineers test your controls, ensuring your evidence reflects your company's setup.

Board-ready outputs

Summaries and risk registers for management accountability, ready for the board.

Independent and precise

Clear methodology, sample reports, and an independence statement on NIS2 requirements.

FAQ