NIS2 Compliance and Readiness Services for Web3
EU-regulated buyers now push NIS2 obligations into procurement questionnaires. If you sell infrastructure, SaaS, or Web3 services into the EU and cannot prove your controls, the deal waits. Our NIS2 compliance services get you questionnaire-ready.
We respond within 24 hours
Who Is Subject to NIS2
NIS2 (Directive (EU) 2022/2555): EU Member States were required to transpose NIS2 into national law by 17 October 2024. The applicable obligations, competent authority and enforcement process depend on each Member State's implementing law. Whether you are regulated directly or reached through your customers' contracts, the costs of being unprepared are concrete.
Procurement waits for evidence.
Regulated buyers must manage supply-chain security under Article 21, so their vendor onboarding now includes NIS2 questionnaires. Without an evidence pack, there is no signature.
Incident reporting most teams can't do.
For significant incidents within the directive's reporting framework, Article 23 includes an early warning within 24 hours, an incident notification within 72 hours and a final report generally within one month. National procedures and competent-authority requirements must also be checked.
Fines with management accountability.
The directive provides maximum administrative fine thresholds of at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher. Actual enforcement is governed through national implementing law. Article 20 requires management bodies to approve and oversee cybersecurity risk-management measures. Liability and enforcement depend on the applicable national law.
Direct Scope vs Supply Chain Requirements
Many suppliers only discover NIS2 when a customer's questionnaire lands. There are two routes into scope, and Web3 businesses are usually reached by the second.
Regulated entities.
Essential or important entities in the directive's 18 sectors, generally 50+ employees or €10M+ turnover.
- Digital infrastructure and ICT service managementCloud, data centers, DNS/TLD, trust services, managed (security) service providers
- Energy, transport, health, water, space, public administrationThe high-criticality sectors of Annex I
- Digital providers, manufacturing, food, postal, researchThe "other critical" sectors of Annex II, including online marketplaces and social platforms
Critical suppliers.
Not named in an annex, but your regulated customers must manage your security under their Article 21 supply-chain obligations.
- Web3 and blockchain infrastructureNode/RPC providers, staking operators, custody tech, oracles, indexers serving EU-regulated customers
- SaaS, software, and API vendorsAnything embedded in a regulated buyer's operations, including AI and data processors
- DevOps, MSP/MSSP, and security vendorsPrivileged access to regulated environments makes you the supply-chain risk they must evidence
What Our NIS2 Compliance Services Include
Every engagement maps your posture to Article 21's ten risk-management measures, produces board-readable output, and feeds the next stage without rework or an open-ended consulting meter.
| Engagement | For | Duration | You get |
|---|---|---|---|
| Scope Check | Teams that need a fast, low-commitment applicability answer. | 1-2 weeks | Applicability and entity-classification memo (direct / indirect / out), obligations summary, recommended next step. |
| Gap AssessmentMost popular | Teams that know they're exposed and need to know what to fix first. | 3-6 weeks | Control matrix mapped to Article 21's measures, maturity score per domain, risk register, prioritized remediation roadmap. |
| Audit and Procurement Readiness | Vendors facing buyer due diligence or supervisory scrutiny. | 6-12 weeks | Remediation delivered, 24h/72h incident-reporting workflow built and exercised, evidence pack that passes questionnaires, board presentation. |
| Managed NIS2 Compliance | Teams that need readiness to stay current. | Quarterly, ongoing | Evidence maintenance, vendor re-reviews, incident-workflow drills, reassessment on regulatory or business change. |
Our NIS2 Readiness Process
A named engagement lead, a shared evidence workspace, and fixed-milestone pricing after the scope check. No open-ended consulting meter.
Answer applicability.
Entity classification: essential, important, indirect via customers, or out of scope, with the DORA/MiCA boundary resolved for crypto businesses.
Map the measures.
Your current posture mapped to Article 21's ten measures, with owners assigned per control domain.
Test the claims.
Interviews and evidence sampling confirm that controls documented on paper match how your team actually operates.
Close the gaps.
Prioritized fixes delivered with your team, the 24h/72h reporting workflow built and rehearsed, supplier reviews completed.
Pack and present.
A due-diligence-ready evidence pack and a board presentation, with management accountability documented and procurement questionnaires answerable in days.
Frequently Asked Questions
An EU buyer just sent the questionnaire? Answer it with evidence, not promises.
Tell us who is asking and leave knowing whether NIS2 reaches you directly or through your customers, and exactly what to show them.
We respond within 24 hours
QuillAudits provides NIS2 readiness, gap assessment, and compliance-support services. We do not provide legal advice; obligations under Directive (EU) 2022/2555 are determined by the national law of your member state.
Related frameworks: SOC 2 Type II Readiness · ISO/IEC 27001 Readiness
Related QuillAudits services
OTHER SERVICES
Sister compliance frameworks and ongoing security leadership for teams already on a readiness path.
- Gap assessment and Web3-aware control matrix for Type II readiness.
- Evidence orchestration through the observation window.
- CPA examination support through to a report buyers accept.
- ISMS design and Annex A implementation for Web3 operations.
- Internal audit and accredited Stage 1 / Stage 2 support.
- Certificate issued by an independent certification body.
- Embed QuillAudits experts into architecture and security decisions.
- Threat modeling and security roadmap without a full-time CISO hire.
- Continuous advisory through build, launch, and scale.






