Our service

NIS2 and GDPR compliance in the UK

Know where your company stands on NIS2 and the GDPR. Records, security policies and access management set up properly, so the evidence you present rests on verified facts.

NIS2 and GDPR compliance illustration
48 haudit delivery time

Clients of the group, among others

SocogetraKärcherMc Dérard ProSingerAB InBevGroupe IMASecurexD'IeterenTexardentEthiasFédération Wallonie-BruxellesLaurenty GroupUCMCMA CGMÉlectricité de StrasbourgNantes en CompagnieVille de LyonGroupe ESC ToulouseericAVille de ParisStade RennaisConnLeadsJost GroupGLCE ProtectKL MotorsportChâteau RougierProvince de Namur

The situation

How we document your compliance

Without an accurate assessment, every compliance effort is a gamble. So that is where we start.

Records, policies and access set up properly

Measures match your actual activity (data, sites, suppliers), not a catalogue of procedures. Compliance documents stay in your name.

Missing evidence is expensive

We say so before you invest in tools. The report is a note leadership can read.

Evidence drawn from your tools

Microsoft 365 logs or the monitoring console: we use what serves as evidence. Not a pile of procedures. Compliance documentation belongs to you.

What we do

Four priorities, ranked for your situation

We do not tackle all four at once. The IT audit shows which one is most urgent, and we start there.

01

Your documents

Records and policies in your name. We keep them up to date.

02

Useful measures

Access, logs, backups. Not a stack of unnecessary procedures.

03

Consent

Legal bases recorded, access restricted. Compliance and protected data.

04

Inspections and audits

Regulatory inspection or client audit: documented evidence and support.

Would you rather know what is at risk before you commit a budget?

Describe your environment. We state what is at risk, what it costs to fix, and in which order.

Get the 48h IT audit

The method

Six steps, each with a written deliverable

Each step produces a document you keep, even if the contract ends.

Step 1Inventory of what exists

Processing activities, policies, accounts, access.

Deliverable: written scoping note
Step 2Gap analysis

Requirements, responsibilities, priorities.

Deliverable: prioritised IT roadmap
Step 3Records and policies

Processing records, policies, internal approval.

Deliverable: inventory and access register
Step 4Access and logging

Access rights, authentication, logs.

Deliverable: inventory and access register
Step 5Suppliers and processors

Contracts, GDPR clauses, external access.

Deliverable: inventory and access register
Step 6Compliance report

A readable table, a written note on open points.

Deliverable: checks documented before and after
180+companies we support
+4countries served
17experts per sector
48 hOur average response time

Budget and scope

What a NIS2 and GDPR engagement includes

  • Written IT audit within 48 hours, ranked by priority
  • Admin accounts, licences and domain names in your name
  • A written scope for NIS2 and GDPR compliance, approved before we start
  • The deliverables of each step, listed in the written quote
  • Your documentation and admin access, handed over at the end
  • One technical manager and a written report on the agreed cadence

Common questions

What clients ask before an IT contract

Do you replace a legal adviser?

No. We put the technical measures and documentation in place, without giving a definitive legal opinion.

Vulnerability testing?

When the assessment and the risks justify it. Not by default.

Who holds the documents?

You. Always.

Do our administrator accounts, licences and domains stay in our name?

Yes. They are held in your name. We operate, you remain administrator.

Do we have to sign an annual contract to work with you?

No. We define a written scope. You fund the agreed services.

Do you work in Belgium and France?

Yes. Head office in Brussels, office in Paris. Each mandate follows the market: language, regulation, local providers.

Last step

Request your compliance quote

Describe your need in two lines. You receive a costed quote and a written audit of your IT environment within 48 working hours.

Written reply within 48 working hours. No unsolicited sales calls.