When it makes sense
When the organisation may fall within NIS2 scope, depends on critical services or suppliers, or needs to demonstrate cybersecurity governance and risk management maturity.
Specific service
Support for organisations preparing for NIS2 obligations, from scope assessment to governance, risk management, supplier dependencies and evidence.
When the organisation may fall within NIS2 scope, depends on critical services or suppliers, or needs to demonstrate cybersecurity governance and risk management maturity.
A defensible view of applicability, clear priorities and an implementation roadmap supported by evidence and governance.
Representative work
Context: a multinational industrial group with scattered regulatory exposure and critical suppliers left unassessed.
Intervention: internal audit (including SOX scope), technical and contractual third-party due diligence within SOC 2, ISO 27001 and NIST, actionable recommendations and an executive-level roadmap.
Result: a significant reduction in compliance risk, documented decisions and clear reporting to the management body.
Anonymised example of the founder's work in previous roles — not an Ahkoris client engagement.
FAQ
It may. NIS2 covers many sectors and classifies entities as essential or important depending on sector, size and services. Self-excluding without a documented scoping analysis can create regulatory exposure.
Yes. Supply chain security is a core NIS2 requirement: assessing critical suppliers, reflecting requirements in contracts and monitoring third-party dependencies are all part of the scope.
The management body. NIS2 makes leadership directly accountable for approving and overseeing the measures, including training — it cannot be fully delegated to IT.
Would you like to understand how NIS2 may affect your organisation?
Book a diagnostic conversation