AresISEC NIS2 GAP Readiness Assessment

A clear view of NIS2 readiness and the areas that need improvement

The NIS2 GAP analysis provides a realistic view of your organisation’s current level of readiness, without unnecessary complexity or generic recommendations.

The NIS2 Directive and the Croatian Cybersecurity Act set higher expectations for organisations that provide important and essential services. Compliance is no longer just a matter of documentation. Organisations must understand their risks, implement appropriate security measures, define responsibilities clearly and be able to respond to incidents in a timely manner.

AresISEC uses a structured GAP analysis to assess the organisation’s current level of NIS2 readiness. The analysis shows what is already in place, where gaps exist, which areas are not sufficiently covered and what should be addressed first.

The NIS2 GAP analysis is a practical assessment of the organisation’s current position against relevant cybersecurity requirements. It covers organisational and technical aspects of security, together with the way security measures are implemented through existing processes. It does not replace a formal regulatory review or legal interpretation of obligations.

The focus is on actual readiness. We do not only check whether policies and procedures exist, but also whether security measures are applied in practice, whether suitable evidence is available and whether existing controls reflect the organisation’s real business risks.

Our approach combines a review of available documentation and a structured questionnaire with discussions with responsible personnel, as well as an assessment of technical areas that may affect the organisation’s cyber resilience.

The result is a practical overview that gives management and responsible personnel a clear basis for setting priorities and making further security investment decisions.

How we approach the analysis?

Our approach is practical and risk-focused. We do not create an impression of compliance where there is no clear evidence or where security measures are not actually implemented.

The analysis is based on what the organisation can demonstrate in practice: documents, records, process descriptions, technical information, existing security practices and other available evidence.

Where evidence is missing, the area is clearly identified as a gap or as something that requires further clarification. Where technical uncertainty remains, a targeted assessment through additional security services may be recommended.

Why AresISEC?

AresISEC combines experience in security testing and technical risk assessment with practical security consulting. This allows us to look at NIS2 not only as a regulatory requirement, but also through the organisation’s actual resilience.

The goal is to identify where the organisation currently stands, which weaknesses create the greatest risk, what should be addressed first and where further investment is most justified.

What do we assess?

As part of the NIS2 GAP analysis, we review security risk management and responsibilities, incident management and business continuity, supplier and access security, asset and vulnerability management, as well as backups, recovery and the technical exposure of systems.

The content of the analysis is adapted to the organisation, the available information, the way it operates and its role in relation to NIS2 requirements.

What do you receive?

After the assessment, you receive an overview of the current state and identified gaps, together with priority recommendations and suggested next steps.

The report can be used for internal planning and management communication, preparation of security improvements, and decisions on technical or organisational investments.

Depending on the selected level of analysis, the client receives:

  1. an overview of the current level of NIS2 readiness
  2. identified gaps and areas where supporting evidence is insufficient
  3. an overview of key services, systems, suppliers and relevant security areas
  4. priorities assessed according to risk and business impact
  5. recommendations for further activities and a basic implementation plan
  6. a concise or full NIS2 GAP report, depending on the selected level of analysis

The NIS2 GAP analysis is not a legal opinion on the organisation’s regulatory status and is not an official regulatory submission. It is also not a formal self-assessment or an implementation service. The service does not include drafting client policies, procedures or registers unless that work is agreed separately.

Who is the service for?

The NIS2 GAP analysis is intended for organisations that want to understand their actual level of readiness before starting broader compliance activities or major technical improvements.

It is particularly useful for organisations that are unsure whether their current policies and technical controls are sufficient, or whether existing records and security practices provide enough evidence that NIS2 requirements are being implemented in practice.

Additional technical validation

Additional technical validation is not a mandatory part of the NIS2 GAP analysis. It is used when the organisation wants to confirm the actual technical condition of its systems, or when the analysis identifies higher risk or insufficient evidence.

These assessments can be agreed separately as an addition to the initial or standard NIS2 GAP analysis.

Additional security assessments

  • Vulnerability security assessment helps verify the actual technical exposure of systems, including vulnerabilities, outdated components and misconfigurations.
  • Penetration testing complements the GAP analysis when it is necessary to determine whether identified weaknesses can be exploited in a realistic attack scenario.
  • Security infrastructure design helps when the analysis identifies a need to improve segmentation and access, security zones, monitoring or system architecture.
  • Ransomware protection and recovery complements the GAP analysis by assessing backup protection and recovery capabilities, as well as readiness for a serious security incident.
  • Source code security analysis is useful for organisations that develop their own applications and want to identify vulnerabilities that may not be visible through external testing alone.
Contact AresISEC and request an assessment of your NIS2 readiness.
Scroll to top