NIS2
Expands risk-management and incident-reporting duties across critical and important sectors, including smaller companies through critical roles and supply chains.
We support the entire regulatory journey, including AI regulation, from initial assessment through certification, with procedures and timelines aligned to your organization.
Request your free GAP analysis →The regulatory map has become dense and confusing: NIS2, DORA, ISO 27001, ENS, the AI Act and industrial standards, each with its own scope, language and deadlines.
SMEs often freeze because they assume the rules do not apply, or rush into certification under client pressure. We first determine exactly what applies, then build a realistic plan that does not paralyze daily operations.
Expands risk-management and incident-reporting duties across critical and important sectors, including smaller companies through critical roles and supply chains.
The EU digital operational resilience regulation for finance, also reaching many software, cloud and IT-support suppliers through contracts.
The voluntary international standard for an Information Security Management System, increasingly required by major customers.
Spain’s mandatory security framework for public administrations and, contractually, many of their suppliers.
Regulates AI by risk level and also affects non-technology companies using chatbots, assistants, automated recruitment or generative tools.
Security requirements for industrial control systems that increasingly overlap with NIS2 in critical and important sectors.
AI Act compliance requires clear internal rules for how AI is used. We create a framework proportionate to your business and can align it with ISO/IEC 42001 where useful.
Compliance should not be a legal threat or an isolated paperwork exercise. Done well, it organizes security, builds trust with clients and partners, and prepares you for requirements that will eventually reach your business.
Yes, if it performs a critical or unique function or supplies an obligated entity that passes security requirements down by contract.
ISO 27001 is a voluntary international standard. ENS is mandatory for Spanish public administrations and many suppliers. Their shared principles make progress in one useful for the other.
It may affect you contractually if you provide software, cloud or IT support to a financial entity.
It depends on your starting point and scope. A GAP analysis provides an estimate tailored to your situation.
Very likely. You do not have to develop AI; using it in daily business can create transparency, training and governance obligations.
A set of internal rules defining approved tools, permitted data, mandatory human oversight and staff training.
No. The AI Act is law; ISO/IEC 42001 is a voluntary standard that helps structure AI management.
We work for you, so you can stay focused on your business without worries or disruption.
Start with a free GAP analysis →