How an engagement runs

Every engagement starts with an audit. What follows is determined by what that audit finds. There are no standard packages: the amount of work depends on your sector, your size, your IT estate and on what is already in place.

Updated 25 September 2026

24 hours
To your first written analysis
4
Phases after the baseline
1
Dossier for NIS2 and ISO 27001 together

With a new client, it starts with a baseline assessment

Without a baseline every plan is an assumption. So we begin by establishing the actual situation: which frameworks apply, which measures exist, which of those are demonstrable, and where the gap sits against what the law requires. Only then is the work determined.

Background

Our team comes from the large accountancy firms. That is not the same as certifying or supervising, and we do not confuse the two. What it does give is the discipline an outside assessor requires: evidence counts only when it is dated, traceable and reproducible. That is how we build a file.

The baseline assessment covers

  • Determining applicability: NIS2, ISO 27001 or both
  • Inventory of existing measures, policy and documentation
  • Testing demonstrability: does the evidence exist, and is it current
  • Assessment of the IT estate and the supplier chain
  • Gap analysis against every framework that applies
  • A report with findings, prioritisation and a substantiated scope
  • What your existing management system already covers. If you hold ISO 9001, both standards share the same clause structure and we take your document control, internal audit programme, management review and corrective-action process as the starting point.

What you are left with

A written audit report with findings per framework, a prioritisation based on risk and enforcement exposure, and a scope the follow-on work can be costed against. The report is yours, including if you decide to place the follow-on work elsewhere.

Four phases, scoped to what the audit finds

The phases are fixed, the content is not. What happens in phase 2 at an organisation with an existing ISMS differs from what happens at one starting from nothing. The baseline sets the size.

Phase 01

Analysis

Applicability check, baseline assessment and gap analysis. Determination of the scope, and registration where the law requires it.

  • Applicability check
  • Baseline and gap analysis
  • Scope, and registration where the law requires it
Phase 02

Implementation

Execution of the control set that applies to you: the ten NIS2 duty-of-care elements or the 93 ISO 27001 controls. Policy, procedures and file formation.

  • Execution of the control set
  • Policy and procedures
  • File formation per measure
Phase 03

Verification

Internal audit, penetration test and supplier assessment, by a team separate from the implementation or by a third party. Under ISO 27001 also the management review, which is your top management's; we supply the inputs.

  • Internal audit, separate from the build
  • Supplier assessment
  • Penetration test, where agreed
Phase 04

Management

The system keeps running between audits: continuous monitoring of what surfaces about you outside your network, nonconformities and corrective actions, and the annual review. Detection inside your own environment and incident response only where agreed.

  • Continuous external monitoring
  • Nonconformities and corrective actions
  • Detection and response, where agreed

Phases can overlap. At an organisation already under supervision, phase 4 often runs alongside phase 2.

Who does what

We can take on most of the operational work. What the law places with the board, we cannot: Article 24 of the Cyberbeveiligingswet, and under ISO 27001 the decisions the standard reserves for top management and the risk owners. Beyond that, part of the work stays with your own organisation in practice, because it concerns your systems, your suppliers and your people. Whoever built a part of the system does not audit that part.

Legally with the board

4
  • Approval of the measures, the strategy and the acceptance of residual risk

    Art. 24 Cbw

  • Knowledge and training requirement for board members

    Art. 24 Cbw

  • Ultimate accountability towards the supervisor

    Stays with the entity

  • Management review and acceptance of residual risk by the risk owners

    ISO 27001 clauses 9.3 and 6.1.3

Not transferable

In practice with your organisation

4
  • Implementing technical measures in your own environment, by your administrators or your suppliers

    We design, test and document

  • Supplying evidence: logs, tickets, contracts and interviewees

    Determines the duration of the baseline

  • Registration via mijn.ncsc.nl using your eHerkenning, where the Cbw applies

    We prepare the submission

  • Board and staff attendance at training and crisis exercises

With us

9
  • Determining applicability and preparing the registration

  • Risk analysis, policy and procedures

  • Design, testing and documentation of the measures

  • File formation per measure, with the date of the last test

  • Internal audit and effectiveness review

    By a colleague who had no part in building the system, or by a third party

  • Continuous external monitoring

    Detection inside your network and incident response where agreed

  • Drafting notifications within the deadlines

    Under your responsibility

  • Supplier assessment and supply chain risk

  • Support during an inspection or certification audit

An organisation without its own security function can therefore place most of the programme with us. What remains is more than three lines, but it is bounded: the obligations the law and the standard place with the board, and the work that can only happen inside your own organisation.

Why there is no price list

The amount of work varies between organisations by a factor no package can absorb. A sixty-person software company with an existing ISMS and a financial institution with fifteen ICT suppliers run the same four phases, but the work does not compare.

What determines the size
Sector and classification, headcount, complexity of the IT estate, number of relevant suppliers, documentation already in place, and how many frameworks apply.
Fixed price
The baseline assessment. Scope and duration are agreed in advance, as is what the report contains.
After the audit
A quotation per phase or for the whole, with an ongoing rate for management in phase 4. You can decide phase by phase.
Contract form
One-off for implementation, or ongoing for implementation and management. Termination and handover of the dossier are agreed in advance.

A quotation therefore follows the baseline assessment rather than preceding it. What the baseline assessment costs is fixed, and confirmed in writing beforehand.

Frequently asked questions

The operational work, yes. Three obligations, no: board approval of the measures, the knowledge and training requirement for board members, and ultimate accountability towards the supervisor. The law places those with the entity and no service provider can stand in between. Everything else, from registration through to notifications, can sit with us.

Start with the applicability check

The check establishes which frameworks apply to your organisation. That is the question the audit has to be preceded by, and there is no cost attached.