NIS2 readiness for a logistics group
The group knew NIS2 applied to them. Beyond that, the position was honest and common: nobody could say how far they were from meeting it, and no two people gave the same answer about who owned the problem.
They had been quoted for a gap analysis twice. Both would have produced a document. Neither would have produced a plan anyone was accountable for.
Starting from the obligations
We began with which parts of the directive actually apply to this business, because a general readiness assessment against everything is a document nobody reads. That gave a much shorter list than the one they had been carrying.
Against that list we assessed what already existed. A good deal did. Incident handling was informal but real; supplier requirements existed in contracts nobody had connected to security; backups were tested, which is rarer than it should be.
- Governance and accountability, which was the largest genuine gap
- Incident reporting, against the directive's timelines rather than their own
- Supply chain requirements, already half-present in existing contracts
- Business continuity, largely in place and needing evidence rather than work
The biggest gap was not technical. It was that no named person was accountable for any of it, so every improvement stalled at the point of decision.
The plan
Each item got an owner, a date and a definition of done. Where something already existed we said so and moved on, rather than rebuilding it to look like compliance work.
Where it left them
Named people, dated commitments, and a paper trail that stands up. The management team can now say what state they are in and what remains, which is what the directive asks of them and what neither previous quote would have delivered.