NIS2 does not prescribe a fixed frequency, but organizations should:
- Conduct assessments periodically (e.g., annually)
- Update assessments after:
- Major changes
- New threats
- Significant incidents
The approach should be risk-based and proportionate.
NIS2 does not prescribe a fixed frequency, but organizations should:
The approach should be risk-based and proportionate.
Our expert consultants are ready to help you build and implement a tailored programme that meets regulatory requirements and protects what matters most.