NIS2 compliance GAP analysis

We compare your current state with the requirements of the NIS2 Directive and its national implementing rules, and you get a clear list of gaps, priorities and a plan you can act on with confidence.

Aligned with the NIS2 Directive and its national rules Output your management can understand No obligation
IT HELP consultant walking a client through the NIS2 compliance GAP analysis over a clear report

The first step to compliance: a precise map of the gaps

The NIS2 Directive significantly raises cybersecurity requirements, and once you fall within its scope you have only a limited window to put security measures in place. It sounds like plenty of time, but without a clear brief it is easy to spend it on the wrong priorities. A GAP analysis tells you straight what you already meet, what is missing and what makes sense to tackle first, so that every euro goes where it actually moves you closer to compliance.

What the GAP analysis covers

Assessment of whether NIS2 applies to you

We check your sector and the size criteria (50+ employees or turnover above €10 million) and whether you are an operator of an essential or an important service. NIS2 is based on self-identification, so the responsibility to assess this rests with you.

Comparison against the required measures

We go through your organisational and technical measures point by point against the NIS2 Directive and its national implementing rules, from risk management and access control to business continuity.

Review of your technical setup

A real look at your network, firewall, backup, monitoring, logging and device protection. Not a paper exercise: we see how things actually run at your company.

Review of your security documentation

We identify which policies, directives and records required by NIS2 you already have, which are missing and which simply need updating.

Incident readiness

We check whether you can detect and report a cyber incident within the deadlines set by NIS2: an early warning within 24 hours, a notification within 72 hours and a final report within one month.

Output: a GAP report with priorities

An overview of the gaps against NIS2 sorted by severity, a proposal of concrete steps, an effort estimate and a quote for the implementation.

How the GAP analysis works

1 Initial consultation and scope We get to know your situation, services and systems and agree on the scope of the analysis.
2 Information gathering Guided interviews with IT and management, a review of documentation and a technical inspection of your environment.
3 Evaluation against NIS2 We mark every requirement of the NIS2 Directive and its implementing rules as: met / partial / missing, with its impact on you.
4 Report, plan and presentation We hand over the GAP report with priorities and pricing and present it in person to both management and the IT team.

What you get at the end

A GAP report that both management and IT can understand: what you meet, what is missing, in what order to tackle it and how much it will cost. It also serves as evidence with which the statutory body can demonstrate that it is managing cyber risk, because NIS2 places responsibility for it directly on company management.

IT HELP consultant reviewing the results of the NIS2 compliance GAP analysis with a client

Why start with a GAP analysis

You know exactly what you are missing for compliance, no investing blind.
Priorities by severity: first what reduces the biggest risk.
A basis for budgeting and management decisions, including a cost estimate.
You prepare for an audit or self-assessment well in advance, not under stress.
We can move smoothly from the analysis to implementing the measures, all from a single partner.
No obligation, and you can work with the report using your own IT or another supplier.
What comes after the GAP analysis

From report to real compliance

The GAP report shows exactly what you are missing. We can also close those gaps directly through our 4 pillars: an audit, network and device protection, monitoring with logging and training, plus the role of a cybersecurity manager. All from a single partner, with no juggling of suppliers.

View the pillars →

Why IT HELP

We are certified to ISO 27001, so we meet the requirements for information security management on ourselves too. We speak a language that both management and IT understand.

30+years of IT experience
ISO27001 & 9001 certified
4pillars to implement the measures

We carry out GAP analyses on site across your region and nationwide, partly remotely too.

Our partners

Microsoft partner ESET partner Dell partner Synology partner VMware partner Epson partner TeamViewer partner Veeam partner KROS partner

Frequently asked questions

How do we find out whether the rules apply to us at all?

It comes down to your sector (the sectors listed in the NIS2 Directive) and your size, as a rule from 50 employees or turnover above €10 million, with some entities covered regardless of size. You can get a preliminary idea yourself, but the precise assessment is the first part of our analysis.

Is a GAP analysis the same as a cybersecurity audit?

No. A compliance audit is carried out by an independent auditor and verifies that your obligations under NIS2 are met. A GAP analysis is the preparation: it maps the gaps and gives you time to close them before an audit or inspection finds them.

We haven't registered yet. What now?

Under NIS2 you have to register once you start meeting the criteria. If you are not sure whether or how to register, we will go through it together, it is a simpler step than it looks.

How long does the analysis take?

Depending on the size of your environment and the scope, a matter of weeks rather than months. We agree the scope and timing in advance at the initial consultation.

How much does a GAP analysis cost?

The price depends on the number of locations, systems and the range of services you provide. After a short, no-obligation consultation you receive a specific quote.

Does the analysis commit us to further services?

No. The report is yours and you can use it however you like. Most clients, however, appreciate that we can act on the findings directly through implementation: an audit, network protection, monitoring and training.

Find out where you stand on NIS2

Order a GAP analysis and get a clear map of the gaps and a plan to close them. The first consultation is free of obligation.

„Your trust inspires us“

Next step

Implementing measures, the 4 pillars of IT security

Implementing the measures

We close the identified gaps through our 4 pillars: protection, monitoring and training.

→ View the pillars
Cybersecurity manager as a service

Cybersecurity manager

We provide the role required by NIS2 as an external service.

→ View the service
NIS2 and cybersecurity compliance

NIS2 and your compliance obligations

An overview of the obligations, deadlines and the whole path to compliance.

→ View the overview

IT HELP Hotline

+421 948 07 97 07

+421 2 5244 2951

+421 948 07 97 07

hotline@ithelp.digital

Where to Find Us

IT HELP
Čajakova 26, Bratislava, Slovakia
Franz Mika Weg 7/1/25, Wien, Austria
Svatošská 23, Karlovy Vary, Czech Republic

We are available on business days Monday – Friday, 8:00 AM – 5:00 PM (or by arrangement)