---
title: "NIS2 readiness | R&D COPILOT"
lang: en
canonical: https://rdcopilot.com/services/nis2-readiness/
content_version: a6d976dd56b7f479b17a7d93a25c4c82a14bb1cbaa0bc29dc922f869e03d3d85
contact: https://rdcopilot.com/contact/
---

[Home](https://rdcopilot.com/)/[Services](https://rdcopilot.com/services/)/NIS2 readiness

AI + engineering services

# Security measures you can show evidence for

NIS2 applies directly to many organisations depending on their sector and size. It reaches many more through supplier contracts and security questionnaires. Whether it applies to you depends on how your country has transposed it, so we start by gathering the facts your adviser needs: sector, size, services and the countries you operate in. Then we do the engineering. We inventory systems, accounts and suppliers and review controls such as multi-factor sign-in, backups, patching and logging. Then we fix the gaps that matter most, starting with the most important. We prepare an incident process with clear roles and the deadlines for early warnings and reports, and rehearse it with your team. Management gets a short, honest summary of where things stand and what is left to do.

[Request a scoped quote](https://rdcopilot.com/contact/?service=nis2-readiness) [Request access](https://rdcopilot.com/account/?service=nis2-readiness)

Start with your workflow. We agree the first deliverable, data boundaries, scope and budget before work begins.

What we can deliver

## What your team receives.

-   Applicability facts: sector, size, services and jurisdictions
-   Inventory of systems, privileged accounts and critical suppliers
-   Control review and technical fixes in priority order
-   Incident response and reporting procedure, with a tabletop exercise
-   Management summary and an evidence folder

Workflow in focus

### NIS2 readiness

A software supplier to a regional hospital network receives a 90-question security questionnaire. Many of the answers depend on things nobody has written down: who has admin access to production, when a backup was last restored and how a breach would be reported. We collect that evidence and close the gaps we find along the way. Then we help the team answer each question with something it can show.

The final design follows your systems, documents and operating requirements.

## Keep your team in control.

### Data protection

Map approved data sources, access rules, retention and provider use before connecting AI to company information.

### EU infrastructure options

Scope EU servers or self-hosting and disclose the processing location of model APIs, logs and backups.

### Human approval

Agree where AI may suggest, where it may act and where a person must approve the next step.

Can we start small?

Yes. Start with one workflow, one team and an agreed outcome. We scope the pilot after learning about your data, systems and constraints.

Can our data stay in the EU?

We can scope EU-hosted or self-hosted options. The proposal identifies where each component processes and stores data, which providers are involved, and any transfer or remote-access implications. EU hosting alone does not establish compliance.

Do you help with the AI Act, NIS2 and CRA?

We help prepare inventories, data flows, security controls, documentation and remediation work for specialist review. Applicability depends on your role, sector, jurisdiction and product. We do not offer a blanket compliance certificate.
