Cybersecurity audit & NIS2 support
We help operators of essential and important services meet the Cybersecurity Agency (ASC) requirements under HG 562/2025 and the obligations of the EU NIS2 Directive - from gap assessment to audit-ready evidence.
If you run services others depend on, this applies to you
Designated service providers
Public institutions
Suppliers to regulated entities
Companies working with the EU
49 ASC controls, 6 domains, one compliance matrix
Each control is scored against your current practice, with the evidence that proves it and the action that closes the gap.
Governance
Identify
Protect
Detect
Respond
Recover
Start with an assessment, add what you need
Readiness assessment
- Scoping and interviews
- Compliance matrix of all 49 controls
- Gap report and prioritised roadmap
Cyber risk management
- Asset and service inventory
- Risk register and assessment
- Risk treatment plan
Policies & incident readiness
- Security policies and procedures
- Incident response and reporting plan
- Business continuity and recovery
Compliance as a service
- Periodic reviews and evidence updates
- Support during ASC audits
- Staff awareness sessions
Five steps to audit-ready
- 01
Scope
Agree on services, systems and sites in scope.
- 02
Assess
Interviews, document review and technical checks.
- 03
Report
Compliance matrix, gap report and roadmap.
- 04
Implement
Policies, risk process and controls put in place.
- 05
Prove
Evidence pack ready for ASC review or audit.
Frequently asked
Does this apply to my organisation?
It applies to providers designated by ASC and, increasingly, to their suppliers. A short scoping call is usually enough to tell.
What is the difference between ASC requirements and NIS2?
ASC requirements are Moldovan law (Law no. 48/2023, HG 562/2025). NIS2 is the EU directive. Both follow a similar risk-based model, so one assessment can cover both.
How long does a readiness assessment take?
It depends on the number of services and systems in scope. We confirm the timeline after scoping.
Do you also implement the controls?
Yes. We can prepare the documentation and processes, coordinate technical work with your IT team or suppliers, and support you during the audit.
Find out where you stand before the regulator does
Book a short call and we will scope a readiness assessment for your organisation.
