Your partner for NIS2 compliance and ISO 27001 certification
From gap analysis to a passed audit: NIS2 and ISO 27001 without detours
NIS2 has been in force in Belgium since 18 October 2024, and clients ask for an ISO 27001 certificate more and more often. Both take more than policy on paper: you have to show how risks are managed and which measures actually work.
dotNET lab guides organisations to NIS2 compliance and ISO 27001 certification. We map the current situation, set priorities and translate requirements into achievable steps, all the way to the audit.
Clear sight first: where do you stand today against the requirements and risks that really matter?
Workable measures
Measures that fit your teams and technology. Otherwise your password policy ends up as a post-it under the keyboard.
Evidence
Not just arranged, but demonstrable: documentation that matches practice, not that one folder marked "do not touch".
Actionable roadmap
Clear priorities with ownership and order, at a pace that is realistic. Security is a marathon, not a sprint.
Proven in practice
FWO achieved ISO 27001 with our guidance
For FWO (the Research Foundation Flanders) we implemented and maintain an ISO 27001-compliant ISMS: from risk analysis and measures to the evidence that passed the external audit.
Many organisations know security is becoming more important, but run into fragmented measures, unclear ownership and documentation that does not match reality.
NIS2 and ISO 27001 make that need more visible. They ask for structure, demonstrability and continuous improvement.
We help close the gap between what is required and what your teams can carry today. Not with heavy theory, but with clear choices, practical priorities and technical depth.
Recognisable situations
When demonstrable security becomes important
Guidance pays off when security has to become demonstrable, repeatable and easier to govern.
You want to know where you stand today
You have measures, tools or policy, but no clear view of the most important gaps and risks.
NIS2 or ISO 27001 is getting closer
You want to translate requirements into concrete actions, responsibilities and evidence in time.
Security lives too much in loose documents
Policy, processes and technical controls do not connect well or are not followed up consistently.
Clients or partners ask for more assurance
You have to be able to show how you handle risks, access, incidents and continuity.
You want to keep security feasible for teams
Measures have to fit your organisation, technology and maturity. Otherwise they get quietly bypassed.
Access management is a core measure in every NIS2 and ISO 27001 track: who may touch which systems, and how do you prove it? If you would rather run your identity provider in-house instead of at an external cloud service, we help with that too. See ProAuth, the self-hosted identity provider we distribute in the Benelux
What we do
From gap analysis to audit-ready
We combine analysis, advice and guidance so security does not get stuck in abstract recommendations.
01
02
03
04
05
01
Gap analysis
We review policy, processes, systems and existing controls against the relevant requirements and risks.
02
Improvement roadmap
We make priorities clear and translate them into a realistic plan with ownership and order.
03
Technical measures
We help with security choices around identity, logging, vulnerabilities, cloud, backups and secure engineering.
04
Documentation and evidence
We make sure measures do not just exist, but become demonstrable and understandable.
05
Awareness and follow-up
We support teams with agreements, routines and practical follow-up so security stays alive.
How we work
First get sight, then improve with focus
A compliance project works best when it stays sharp, phased and usable.
01
We determine scope and context
We look at which regulation, standard, systems, processes and stakeholders are relevant.
02
We analyse how things work today
We test policy, technical controls and operational routines against the desired situation.
03
We prioritise risks and gaps
Not everything has the same impact. We make visible what comes first and why.
04
We translate into concrete actions
We make measures, ownership, evidence and planning practically executable.
05
We guide implementation and follow-up
We support where needed with execution, documentation, evaluation and further improvement.
What does an ISO 27001 certification project cost?
That depends on your size, scope and maturity. Count on three cost blocks: the guidance and implementation, the internal time of your own team, and the external audit by the certification body. After a gap analysis we make the project and the budget concrete for your situation.
How long does it take to get ISO 27001 certified?
Typically a few months to a year, depending on where you stand today and how much time your team can free up. The gap analysis quickly gives a realistic picture of the lead time for your organisation.
Do you issue the ISO 27001 certificate yourselves?
No, and that is how it should be. We make your organisation audit-ready: gap analysis, measures, documentation and evidence. The certificate itself is issued after an external audit by an independent accredited certification body, such as Vinçotte, DNV or Kiwa.
What is the difference between CyberFundamentals and ISO 27001?
CyberFundamentals is the framework of the Centre for Cybersecurity Belgium (CCB) to comply with NIS2, with levels that match your risk profile. ISO 27001 is the international standard for information security that clients and tenders often ask for. They overlap strongly: whoever tackles one well is already far along for the other. We look together at which route, or which combination, delivers the most for your organisation.
Who falls under NIS2 in Belgium?
The Belgian NIS2 law has been in force since 18 October 2024 and applies to essential and important entities in sectors such as energy, transport, health, digital infrastructure, manufacturing and government, and through client requirements increasingly to their suppliers too. In doubt? In a short call we make clear whether and how NIS2 applies to your organisation.
Is this only for large organisations?
No. SMEs and scale-ups also face security and evidence requirements from clients, partners or regulation more and more often.
Do we already need policy and documentation?
No. We can start with what is there and help build the missing parts practically.
Do you also look at technical controls?
Yes. Where relevant we look at identity, cloud, logging, vulnerabilities, backups, deployment and application security, among others.
First step
Want to know how ready your organisation is for NIS2 or ISO 27001?
Tell us which requirements are coming your way, which systems are critical and what already exists today.
Then we look together at which steps are needed to make security concrete, feasible and demonstrable.