NIS2 compliance · Independent ITSM consultancy

NIS2 is built inside your ITSM tools.

Asset mapping, 24h/72h incident notification, provable security measures: every NIS2 obligation has an ITSM equivalent. We turn the directive into an operational setup that holds up in an audit. 45 minutes to scope your perimeter, free of charge.

  • Independent ITSM consultancy
  • ITIL v4
  • 180 implementations
  • Reply within 48h
Book my NIS2 consultation

En soumettant ce formulaire, vous acceptez d'être contacté par SMC Consulting.

The 12 ITSM platforms we master

4me
BMC Helix
Cherwell
EasyVista
Freshservice
HaloITSM
Ivanti Neurons
Jira Service Management
ManageEngine ServiceDesk Plus
ServiceNow
SymphonyAI Summit
TOPdesk

We configure your NIS2 compliance on the platform you already run.

Trusted by

Brussels Airport
ING
CPH Banque
DKV
Lotto
Mercy Corps
BNP Paribas Fortis
AXA
KBC
Proximus
18
critical sectors covered by NIS2
50 staff
minimum threshold for application
24h
legal deadline for incident notification
€10M
maximum fine for non-compliance

Does NIS2 apply to you? Two criteria are enough.

The NIS2 directive targets 18 critical sectors and applies from 50 employees upwards. Ten seconds is enough to know whether you are in scope.

🏛️Essential entity

≥ 250 employees, or turnover ≥ €50M / balance sheet ≥ €43M. Energy, transport, banking, health, water, digital infrastructure, public administration. Subject to ex ante supervision. Fines up to €10M.

🏢Important entity

50 to 249 employees, or turnover between €10M and €50M. Postal services, waste management, manufacturing, digital providers, food, research, chemicals, IT suppliers. Fines up to €7M.

⚠️Out of scope, or not sure?

If you operate in one of the 18 sectors and employ more than 50 people, NIS2 most likely applies. A 45-minute consultation is enough to settle it.

NIS2 is not a legal file: it is an ITSM subject.

Compliance is not won with a binder of procedures. It is won with an operational setup. Every NIS2 obligation has a concrete ITSM equivalent.

1

Mapping critical assets → ITSM CMDB

Continuous inventory of your assets, relationships between components, criticality per business service. A well-maintained CMDB carries 80% of this obligation.

2

24h / 72h incident notification → ITSM incident workflow

Initial alert within 24 hours, interim report within 72 hours, final report within one month. A configured workflow, a timestamped log, pre-approved templates. Without that foundation, the obligation is unworkable.

3

Provable security measures → ITSM catalogue + knowledge base

Encryption, access control, backups, business continuity: every measure traced, versioned and defensible in front of an auditor. A measure that is not traced in the tool does not exist for the supervisor.

4

Management accountability → ITSM dashboards

NIS2 holds management bodies personally accountable. Dashboards, incidents by criticality, SLAs met, measures deployed, give the executive committee the visibility its liability depends on.

Have 45 minutes? We will tell you where you stand on NIS2, free of charge.

Book my NIS2 consultation →

Our method, in 4 steps.

A defensible deliverable at every step. Not a binder of procedures: an operational setup embedded in your ITSM tool.

  1. 1

    NIS2 diagnostic + ITSM baseline

    Joint assessment of your scope (essential / important) and of your current ITSM maturity. Initial mapping of critical assets, and identification of the gaps between where you are and what NIS2 requires.

    📋 NIS2 diagnostic report + ITSM baseline

  2. 2

    Gap analysis and costed plan

    Detailed gap analysis, prioritisation by urgency and impact, estimated effort (man-days) and costs (licences, configuration, training). A plan you can defend to your board and your CFO.

    📋 Gap analysis + costed 3-year NIS2 roadmap

  3. 3

    Operational compliance build

    Configuration of your ITSM tool (existing or new) against the four obligations: a CMDB enriched with regulatory criticality, a 24h/72h/30-day incident workflow, a documented catalogue of measures, and governance dashboards. Documentation produced as we go.

    📋 A NIS2 setup, live and documented inside your ITSM

  4. 4

    Audit preparation

    Audit simulation, full-scale test of the incident notification procedure, completeness check of the compliance file, and training for the executive committee on its personal obligations.

    📋 Audit-ready compliance file + trained teams

What our ITSM clients say

SMC Consulting helped us structure our incident management and our asset mapping on ServiceNow. What started as an ITSM optimisation became our compliance foundation.
CIO · Manufacturing company (≥ 1,000 users)
A pragmatic approach: they looked at what we already had before proposing what needed adding. A lot of reuse, very little waste.
IT Manager · Healthcare sector
An ITSM consultancy that understands the regulatory dimension, which is rare. Concrete recommendations, usable deliverables, teams trained by the end.
Compliance Manager · IT supplier sector

Why SMC Consulting on a NIS2 subject?

An independent ITSM consultancy, not a law firm

NIS2 compliance does not live in a binder. It lives in your tools. That has been our trade for five years: turning a regulatory requirement into defensible ITSM configuration. 180 implementations · ITIL v4 · independent consultancy.

Compliance that holds up in an audit, not a slide deck

We build operational setups, not PDF files. Every measure we put in place is configured in your tool, traced, tested and defensible in front of the supervisory authority.

A European consultancy

We support organisations in Belgium, France, Luxembourg and Switzerland. We know the national NIS2 authorities (CCB in Belgium, ANSSI in France) and how they work in practice.

ITSM tools we configure your NIS2 compliance on

We work with what you already have, or help you choose if you have no tool yet. ITSM has been our trade for five years, across platforms.

ServiceNowFreshserviceJira Service ManagementTOPdeskIvanti

Already have an ITSM tool? You are further ahead than you think.

"Our ITSM tool is underused."

A needs audit, then targeted NIS2 configuration. No migration, no disruption. Most obligations are already 60–80% answered by a well-configured existing ITSM tool.

"Our ITSM tool is poorly aligned with our processes."

A NIS2 gap diagnostic, then optimisation of the existing workflows and CMDB. NIS2 becomes the trigger to consolidate your IT operation for the next five years.

"We do not have an ITSM tool yet."

Tool selection and rollout designed around NIS2 from the start. The compliance project funds the ITSM foundation you were going to need anyway.

Frequently asked questions about NIS2

Book your NIS2 consultation: 45 minutes, free of charge.

An SMC Consulting consultant establishes your NIS2 baseline with you: which regime applies, which obligations follow, where your ITSM tool stands today, and what to do first. You leave with a clear view, no commitment.

Free · 45 min · Reply within 2 working days

En soumettant ce formulaire, vous acceptez d'être contacté par SMC Consulting.