Compliance

NIS2

The EU's Network and Information Security Directive (EU 2022/2555) sets legal cyber security and incident reporting duties for essential and important organisations - and reaches UK businesses that operate in, or supply into, the EU.

NIS2DirectiveTESTED
100% success record

Every client we have taken through an accreditation has achieved it - and kept it at every renewal.

We never mark our own homework

We submit ourselves to independent third-party testing. Certification is always issued by an independent body, never by us.

Physical tests, not questionnaires

We prove each control works on your real devices and services. Questionnaire answers can be inaccurate or optimistic; tests cannot.

Free assessment of where you are

We will look at your current position for free and tell you exactly which controls you need - with no obligation.

What is NIS2?

NIS2 replaced the original NIS Directive and has applied across EU member states since October 2024. It widens the sectors covered - from energy, transport, health and digital infrastructure to manufacturing, food, waste, postal services and managed IT providers - and makes senior management accountable for cyber risk.

In the UK, the NIS Regulations 2018 still apply and the government's Cyber Security and Resilience Bill is set to extend them to more organisations, including managed service providers. If you trade in the EU or supply organisations that are in scope, their NIS2 obligations will flow down to you through contracts.

Who needs it

The controls you will need

Risk management and policies

Documented risk analysis and information security policies, owned by management.

Incident handling and reporting

The ability to detect incidents and report significant ones: an early warning within 24 hours, a notification within 72 hours and a final report within a month.

Business continuity

Backups, disaster recovery and crisis management that are tested, not assumed.

Supply chain security

Security requirements for, and assessment of, your key suppliers.

Secure development and maintenance

Vulnerability handling and disclosure across the systems you build or run.

Cyber hygiene, training, MFA and encryption

Basic hygiene, staff training, multi-factor authentication, access control, asset management and appropriate cryptography.

How we get you there - and keep you there

  1. 1Free assessment

    We review your devices, cloud services and processes against NIS2 and show you where you stand.

  2. 2Close the gaps

    We fix or guide you through every control that would fail, in priority order.

  3. 3Test physically

    We prove each control works - scans, patch checks, malware tests, restores and MFA checks - before anyone else looks.

  4. 4Independent sign-off

    An independent assessor, auditor or certification body confirms it. We never certify our own work.

  5. 5Stay compliant

    We monitor your controls in real time and fix drift as it happens, so renewal is a normal day, not a cliff edge.

What sets Total Group apart

Compliance monitored in real time - not checked once a year

Our own intellectual property is how we run compliance: we monitor the major NIS2 controls in real time using the leading enterprise SaaS tools. That lets us map gaps and bridge controls quickly and accurately while you work towards accreditation - and then keep standards up, and risk down, every day after it.

Controls monitored in real time

We watch the major controls continuously using leading enterprise SaaS security and compliance tools - not once a year with a questionnaire.

Gaps mapped and bridged fast

Live data shows exactly which controls are missing or drifting, so we can map the gaps and bridge them quickly and accurately.

Compliant change management

Every change to your systems follows a compliant change process, so an upgrade or a new starter never quietly breaks a control.

Compliance that improves, not decays

Issues are picked up and fixed as they happen. Your risk goes down over the year instead of creeping up until the next audit.

HighLowaudit panic▬ Annual review▬ Total Group real-time monitoringControl health over 12 months
Annual review“We were compliant a year ago.”
  • Controls drift unnoticed for months
  • Renewal is a fraught cliff edge
  • Evidence is gathered in a rush
  • Risk rises until the next audit
Total Group real-time“We were compliant yesterday.”
  • Every major control watched continuously
  • Accreditation day is a normal day
  • Evidence is always current
  • Issues fixed as they happen, so compliance improves

Annual review is not viable in the current threat landscape. Attackers do not wait twelve months - so neither do we.

Stay compliant all year: Levels 1 to 3

Certification is a snapshot. Our compliance plans keep the controls tested, the evidence current and renewals handled - Level 1 demonstrates, Level 2 practises and Level 3 proves compliance continuously.

Level 1 - Demonstrate

CE and Digital GDPR Controls - Our consultants will complete the CE submission with input from your staff.

£163.50/month + VAT
£545 setup + VAT today, then 12 monthly Direct Debits of £196.20 inc VAT

Level 2 - Practice

CE, CE+ and Digital GDPR Controls -Monitoring & Submission as a Service (Submission following Quarter)

£599.50/month + VAT
£2,725 setup + VAT today, then 12 monthly Direct Debits of £719.40 inc VAT

Level 3 - Prove

CE, CE+, GDPR Governance, Supply Chain Audits, Pen Testing, Vulnerability Scanning, (Real-time Maintained) Compliance As A Service

£708.50/month + VAT
£4,360 setup + VAT today, then 12 monthly Direct Debits of £850.20 inc VAT

NIS2 questions and answers

Does NIS2 apply to UK companies?

Not directly in the UK, but it applies to your EU operations and it is increasingly written into contracts by EU customers. The UK is also strengthening its own NIS Regulations along similar lines.

What are the penalties?

Member states can fine essential entities up to €10m or 2% of global turnover, and important entities up to €7m or 1.4%, with personal accountability for management.

Where do we start?

With our free assessment: we map the NIS2 measures against how you work today and give you a prioritised gap list.

Does Cyber Essentials help?

Yes - it covers much of the cyber hygiene baseline. NIS2 goes further on governance, incident reporting, continuity and supply chain, which our Level 2 and 3 plans address.

What makes Total Group different from other compliance providers?

We monitor the major controls in real time using leading enterprise SaaS tools, with compliant change management behind every change. Gaps are found and bridged quickly, standards are maintained every day, and accreditation stops being a fraught cliff edge - you can say you were compliant yesterday, not a year ago.

Why is an annual review not enough?

Controls drift: devices miss patches, accounts change, new services appear. With an annual review that drift goes unnoticed for months while risk rises. Real-time monitoring catches it as it happens, so issues are fixed quickly and your compliance improves rather than decays.

Find out where you stand - free

Book a free, no-obligation NIS2 assessment. We will show you which controls you already meet, which you need, and the quickest route to getting certified.

Free resources

Related compliance