Standards / Information security, privacy and AI

NIS 2 EU network and information security

Cybersecurity risk management and incident reporting for essential and important entities in the EU.

Core documents AMS builds

  • Risk management measures
  • Incident reporting procedure
  • Supply chain security
  • Management training records

Drafted from your actual processes and systems, then kept under version control with review dates.

The path to NIS 2

Six steps from first conversation to NIS 2. AMS and our consultants handle each one with you.

  1. 1Scope

    Define which sites, teams, processes and systems NIS 2 will cover.

  2. 2Gap assessment

    Compare what you do today with every NIS 2 requirement and list what is missing.

  3. 3Documents

    Write the policies, procedures and records NIS 2 expects, starting with the risk management measures.

  4. 4Implement and collect evidence

    Put the processes into daily work and capture proof that they run, on a schedule.

  5. 5Internal review

    Check readiness with an internal audit or self-assessment, and close the findings.

  6. 6Ongoing compliance

    There is no single certificate. You keep records current, answer regulators and customers, and review controls as the rules change.

NIS 2 questions

Planning NIS 2? Talk to our team

How long does NIS 2 implementation take?

Most organizations need about 12–20 weeks, depending on size, number of sites and how much is already in place. A gap assessment gives a firm estimate.

What documents does NIS 2 require?

Core documents usually include: risk management measures, incident reporting procedure, supply chain security, management training records. AMS drafts them from your actual processes and keeps them under version control.

Can NIS 2 be combined with other standards?

Yes. NIS 2 is often run together with ISO/IEC 20000-1, ISO/IEC 27001, ISO/IEC 27701. AMS maps shared requirements, so one record can count toward several standards.

How does AMS help with NIS 2?

AMS runs the full NIS 2 program: scoping, gap assessment, documents, evidence capture, internal audits, corrective actions and the audit pack for your reviewers.

Let's look at your operation together

A 30-minute call. Tell us how you work today and we'll show you the product that fits, configured around your process.