PMBA

Cybersecurity audit & NIS2 support

We help operators of essential and important services meet the Cybersecurity Agency (ASC) requirements under HG 562/2025 and the obligations of the EU NIS2 Directive - from gap assessment to audit-ready evidence.

Built on the official framework
Law no. 48/2023 on cybersecurityThe national legal framework, supervised by ASC.
HG 562/2025Cybersecurity requirements that designated providers must meet.
ASC methodological guides (2026)Implementation guide (Order no. 09) and risk management procedure (Order no. 18).
NIS2 Directive (EU) 2022/2555For organisations operating in, or supplying to, the EU.
Who it is for

If you run services others depend on, this applies to you

Designated service providers

Designated service providers
Operators of essential and important services under ASC supervision.

Public institutions

Public institutions
Central and local public authorities running services for citizens and businesses.

Suppliers to regulated entities

Suppliers to regulated entities
IT, telecom and service companies asked by clients to prove their security.

Companies working with the EU

Companies working with the EU
Organisations that fall under NIS2 directly or through their EU customers.
What we assess

49 ASC controls, 6 domains, one compliance matrix

Each control is scored against your current practice, with the evidence that proves it and the action that closes the gap.

Governance

Governance
Roles, responsibilities, policies and management oversight of cybersecurity.

Identify

Identify
Assets, services, suppliers and the risks that affect them.

Protect

Protect
Access control, secure configuration, data protection and awareness.

Detect

Detect
Monitoring and logging to spot incidents early.

Respond

Respond
Incident handling, analysis and mandatory reporting.

Recover

Recover
Backup, continuity and restoring services after an incident.
Service packages

Start with an assessment, add what you need

Start here

Readiness assessment

Duration and price: on request
Readiness assessment
Where you stand today against every applicable requirement.
  • Scoping and interviews
  • Compliance matrix of all 49 controls
  • Gap report and prioritised roadmap
Risk

Cyber risk management

Duration and price: on request
Cyber risk management
A working risk process that follows the ASC procedure guide.
  • Asset and service inventory
  • Risk register and assessment
  • Risk treatment plan
Implementation

Policies & incident readiness

Duration and price: on request
Policies & incident readiness
The documents and routines the requirements expect.
  • Security policies and procedures
  • Incident response and reporting plan
  • Business continuity and recovery
Ongoing

Compliance as a service

Monthly retainer: on request
Compliance as a service
A partner who keeps you compliant after the project ends.
  • Periodic reviews and evidence updates
  • Support during ASC audits
  • Staff awareness sessions
How an engagement runs

Five steps to audit-ready

  1. 01

    Scope

    Agree on services, systems and sites in scope.

  2. 02

    Assess

    Interviews, document review and technical checks.

  3. 03

    Report

    Compliance matrix, gap report and roadmap.

  4. 04

    Implement

    Policies, risk process and controls put in place.

  5. 05

    Prove

    Evidence pack ready for ASC review or audit.

Questions

Frequently asked

Does this apply to my organisation?

It applies to providers designated by ASC and, increasingly, to their suppliers. A short scoping call is usually enough to tell.

What is the difference between ASC requirements and NIS2?

ASC requirements are Moldovan law (Law no. 48/2023, HG 562/2025). NIS2 is the EU directive. Both follow a similar risk-based model, so one assessment can cover both.

How long does a readiness assessment take?

It depends on the number of services and systems in scope. We confirm the timeline after scoping.

Do you also implement the controls?

Yes. We can prepare the documentation and processes, coordinate technical work with your IT team or suppliers, and support you during the audit.

Find out where you stand before the regulator does

Book a short call and we will scope a readiness assessment for your organisation.