Detecting…
LoginWhat is NIS2 The NIS2 Directive (EU 2022/2555) represents a fundamental shift in how cybersecurity is governed across Ireland and the European Union. It expands the scope of regulated sectors, introduces strict supervisory oversight, and places direct accountability on senior management. For organizations operating in regulated or critical sectors, NIS2 is not simply a compliance obligation, it is a regulatory expectation that cybersecurity risk is actively governed at board level. Across Ireland and the EU, regulators expect organizations to evidence not only compliance, but maturity, consistency, and continuous improvement in cybersecurity practices.

Kelmac Group uses the Cyber Fundamentals (CyFun) Framework as the core model for assessing cybersecurity maturity. CyFun provides a structured, measurable framework that translates complex regulatory requirements into practical, assessable domains. It enables organisations to evaluate their cybersecurity posture using a consistent maturity scale and clearly defined control areas. For organisations operating across Ireland and the EU, this structured approach is essential to demonstrate consistency and control effectiveness in line with NIS2 expectations.
CyFun provides a practical way for organisations to translate NIS2 requirements into measurable cybersecurity actions. It aligns governance, risk management, incident response, supply chain security, and resilience capabilities directly with key NIS2 obligations, particularly Articles 20 and 21. By structuring these areas into a clear maturity model, organisations can assess gaps, demonstrate accountability, and build audit-ready evidence. At the same time, CyFun is mapped to globally recognised standards such as NIST Cybersecurity Framework and ISO/IEC 27001, ensuring that improvements made for NIS2 also strengthen overall cybersecurity posture in line with international best practice.

· Establishes a structured governance framework aligned with the NIS2 Directive, enabling clear accountability and demonstrable compliance
· Defines a formal, business-aligned cybersecurity strategy tailored to organisational risk profile and regulatory obligations
· Embeds a risk-based approach to cybersecurity management, ensuring resources are prioritised against the most critical threats
· Strengthens cyber resilience through repeatable processes for incident response, recovery, and continuous improvement
· Enhances third-party and supply chain risk management in line with NIS2 requirements, reducing exposure from external dependencies
· Provides auditable evidence and reporting structures to support regulatory inspections, board oversight, and ongoing compliance assurance
A NIS2 maturity assessment evaluates your organisation’s cybersecurity capabilities against the requirements of the NIS2 Directive, providing a structured view of readiness and areas for improvement.
Yes. Ireland is required to transpose the NIS2 Directive into national law, and organisations operating in scope must comply with its requirements.
Regulators expect organisations to demonstrate not just compliance, but measurable cybersecurity maturity and effective risk management practices.
CyFun provides a structured framework that translates NIS2 requirements into measurable domains, enabling consistent assessment, benchmarking, and improvement.
No, but ISO 27001 alignment can support NIS2 compliance. A maturity assessment helps identify how your current controls align with both.
Organisations should begin assessing their readiness immediately, as regulatory expectations and supervisory activities are increasing across the EU.