Your partner for NIS2 compliance and ISO 27001 certification

From gap analysis to a passed audit: NIS2 and ISO 27001 without detours

NIS2 has been in force in Belgium since 18 October 2024, and clients ask for an ISO 27001 certificate more and more often. Both take more than policy on paper: you have to show how risks are managed and which measures actually work.

dotNET lab guides organisations to NIS2 compliance and ISO 27001 certification. We map the current situation, set priorities and translate requirements into achievable steps, all the way to the audit.

Illustration: two people mount a large shield with a light blue check mark onto the front of a building together, one on a stepladder with a screwdriver.

The core of the project

  • Gap analysis

    Clear sight first: where do you stand today against the requirements and risks that really matter?

  • Workable measures

    Measures that fit your teams and technology. Otherwise your password policy ends up as a post-it under the keyboard.

  • Evidence

    Not just arranged, but demonstrable: documentation that matches practice, not that one folder marked "do not touch".

  • Actionable roadmap

    Clear priorities with ownership and order, at a pace that is realistic. Security is a marathon, not a sprint.

Proven in practice

FWO achieved ISO 27001 with our guidance

For FWO (the Research Foundation Flanders) we implemented and maintain an ISO 27001-compliant ISMS: from risk analysis and measures to the evidence that passed the external audit.

Read the FWO case
  • Belgian public institution
  • ISMS implemented and maintained
  • Certificate achieved after an external audit

Why start now

From obligation to workable security

Many organisations know security is becoming more important, but run into fragmented measures, unclear ownership and documentation that does not match reality.

NIS2 and ISO 27001 make that need more visible. They ask for structure, demonstrability and continuous improvement.

We help close the gap between what is required and what your teams can carry today. Not with heavy theory, but with clear choices, practical priorities and technical depth.

Recognisable situations

When demonstrable security becomes important

Guidance pays off when security has to become demonstrable, repeatable and easier to govern.

  • Character examines a checklist on an easel with a magnifying glass, several rows already ticked off

    You want to know where you stand today

    You have measures, tools or policy, but no clear view of the most important gaps and risks.

  • Character calmly organises documents while a large shield approaches in the background

    NIS2 or ISO 27001 is getting closer

    You want to translate requirements into concrete actions, responsibilities and evidence in time.

  • Character gathers loose sheets fluttering around him into one folder under the arm

    Security lives too much in loose documents

    Policy, processes and technical controls do not connect well or are not followed up consistently.

  • Two characters at a table: one shows a folder with a shield emblem, the other examines it attentively

    Clients or partners ask for more assurance

    You have to be able to show how you handle risks, access, incidents and continuity.

  • Character comfortably carries a manageable shield while a far too large shield leans against the wall

    You want to keep security feasible for teams

    Measures have to fit your organisation, technology and maturity. Otherwise they get quietly bypassed.

Access management is a core measure in every NIS2 and ISO 27001 track: who may touch which systems, and how do you prove it? If you would rather run your identity provider in-house instead of at an external cloud service, we help with that too. See ProAuth, the self-hosted identity provider we distribute in the Benelux

What we do

From gap analysis to audit-ready

We combine analysis, advice and guidance so security does not get stuck in abstract recommendations.

Gap analysis

We review policy, processes, systems and existing controls against the relevant requirements and risks.

Improvement roadmap

We make priorities clear and translate them into a realistic plan with ownership and order.

Technical measures

We help with security choices around identity, logging, vulnerabilities, cloud, backups and secure engineering.

Documentation and evidence

We make sure measures do not just exist, but become demonstrable and understandable.

Awareness and follow-up

We support teams with agreements, routines and practical follow-up so security stays alive.

How we work

First get sight, then improve with focus

A compliance project works best when it stays sharp, phased and usable.

  1. 01

    We determine scope and context

    We look at which regulation, standard, systems, processes and stakeholders are relevant.

  2. 02

    We analyse how things work today

    We test policy, technical controls and operational routines against the desired situation.

  3. 03

    We prioritise risks and gaps

    Not everything has the same impact. We make visible what comes first and why.

  4. 04

    We translate into concrete actions

    We make measures, ownership, evidence and planning practically executable.

  5. 05

    We guide implementation and follow-up

    We support where needed with execution, documentation, evaluation and further improvement.

Under the bonnet

Security that demonstrably works

Compliance is not ticking off a checklist. Every measure has to survive three steps.

  1. Technically sound

    The measure really works in your systems, not just on paper.

  2. Operationally feasible

    Your teams can carry the measure, today and next year.

  3. Demonstrable

    The measure produces evidence that convinces: for audits, clients and the board.

That is why we watch traceability, ownership, technical quality and lasting follow-up.

What we pay attention to

  • clear scope and priorities
  • a risk-based approach
  • practical security measures
  • identity and access management
  • incident and continuity processes
  • evidence and documentation
  • awareness for teams
  • feasible follow-up routines

Control

From policy to execution

Policy only gains value when teams know what to do and measures are visibly followed up.

We help translate security into roles, processes, technical controls and clear agreements.

Engineering

Security close to the technology

Many risks sit in applications, identity, cloud configuration, deployment and operations.

That is why we combine compliance insight with engineering experience, so recommendations stay executable.

Who it is for

For organisations that have to make security concrete

This guidance is relevant for organisations that fall under NIS2, pursue ISO 27001 or face stronger client requirements around security.

Even without a formal certification project, this guidance helps organise risks, measures and follow-up better.

The best projects start pragmatically: making clear where you stand, what is urgent and what has to be built in for the long term.

Book an intro call
Illustration: three professionals from different organisations, the middle one holds a small shield firmly in both hands.

FAQ

Frequently asked questions

What does an ISO 27001 certification project cost?

That depends on your size, scope and maturity. Count on three cost blocks: the guidance and implementation, the internal time of your own team, and the external audit by the certification body. After a gap analysis we make the project and the budget concrete for your situation.

How long does it take to get ISO 27001 certified?

Typically a few months to a year, depending on where you stand today and how much time your team can free up. The gap analysis quickly gives a realistic picture of the lead time for your organisation.

Do you issue the ISO 27001 certificate yourselves?

No, and that is how it should be. We make your organisation audit-ready: gap analysis, measures, documentation and evidence. The certificate itself is issued after an external audit by an independent accredited certification body, such as Vinçotte, DNV or Kiwa.

What is the difference between CyberFundamentals and ISO 27001?

CyberFundamentals is the framework of the Centre for Cybersecurity Belgium (CCB) to comply with NIS2, with levels that match your risk profile. ISO 27001 is the international standard for information security that clients and tenders often ask for. They overlap strongly: whoever tackles one well is already far along for the other. We look together at which route, or which combination, delivers the most for your organisation.

Who falls under NIS2 in Belgium?

The Belgian NIS2 law has been in force since 18 October 2024 and applies to essential and important entities in sectors such as energy, transport, health, digital infrastructure, manufacturing and government, and through client requirements increasingly to their suppliers too. In doubt? In a short call we make clear whether and how NIS2 applies to your organisation.

Is this only for large organisations?

No. SMEs and scale-ups also face security and evidence requirements from clients, partners or regulation more and more often.

Do we already need policy and documentation?

No. We can start with what is there and help build the missing parts practically.

Do you also look at technical controls?

Yes. Where relevant we look at identity, cloud, logging, vulnerabilities, backups, deployment and application security, among others.

First step

Want to know how ready your organisation is for NIS2 or ISO 27001?

Tell us which requirements are coming your way, which systems are critical and what already exists today.

Then we look together at which steps are needed to make security concrete, feasible and demonstrable.