NIS2 Consulting & IT Compliance
Compliance is an architecture decision, not a document.
Evolvice builds and operates the controls behind GDPR, BSI IT-Grundschutz, NIS2 and ISO 27001 in Europe, and NCA ECC, SAMA CSF and PDPL in Saudi Arabia — inside one delivery model, one audit trail and one incident framework.
Two regulatory stacks. One control set.
Most enterprises run a European programme and a Gulf programme in parallel, duplicating evidence and slowing releases. We map both onto a single set of technical controls.
Europe / DACH
- GDPR (EU 2016/679)
- BSI IT-Grundschutz & BSI C5
- NIS2 Directive
- ISO/IEC 27001:2022
- BaFin & KRITIS sector rules
Saudi Arabia / KSA
- PDPL (2023) & SDAIA guidance
- NCA Essential Cybersecurity Controls
- SAMA Cybersecurity Framework
- CCC cloud classification
- Vision 2030 digital mandates
For organisations that want to use AI with confidential data under GDPR and trade-secret constraints, our enterprise Private AI Workspace provides a controlled technical environment, separate from public AI services. It does not replace AI governance — policies and controls remain part of the compliance programme.
The services that carry the compliance workload
A compliance programme only holds if someone operates the controls. These five services produce the evidence auditors and regulators ask for.
Compliance questions we are asked first
What is NIS2?
NIS2 is EU Directive (EU) 2022/2555 on the cybersecurity of network and information systems. It requires in-scope organisations to implement risk-management measures, report significant incidents and hold management accountable. Germany transposes it through the NIS2 Implementation Act, supervised by the BSI.
Who is affected by NIS2?
In principle, medium-sized and large organisations in the sectors listed in Annexes I and II of the directive — such as energy, transport, health, digital infrastructure, manufacturing and digital services. Some entities are in scope regardless of size. A scoping check based on sector, size and activity confirms whether your organisation is affected.
What does NIS2 consulting at Evolvice cover?
A scoping check, a gap assessment against NIS2 requirements, a prioritised remediation plan and implementation of the technical controls — access management, logging, incident response and supplier governance — with audit-ready evidence. It connects with our security consulting and managed security services.
What are IT compliance services?
IT compliance services translate regulatory requirements into implemented technical controls, monitoring, and audit evidence. At Evolvice this covers gap assessment, control design, implementation, continuous monitoring and audit-ready reporting against GDPR, NIS2, ISO 27001, NCA ECC, SAMA CSF and PDPL.
Can one control set satisfy both EU and Saudi regulators?
Yes. Roughly 70% of the controls overlap — access management, logging, encryption, incident response and supplier governance. The remaining differences are residency, notification timelines and sector reporting, which we handle as jurisdiction-specific configuration rather than a second programme.
Does compliance work sit inside Managed Services or Cybersecurity?
Both. Cybersecurity delivers the assessments, testing and security operations; Managed Services operates the platforms and produces the evidence. The compliance hub is the shared governance layer between the two pillars.
How long does a first compliance gap assessment take?
A scoped gap assessment against one framework typically takes two to four weeks, ending in a prioritised remediation plan with owners, effort estimates and audit-window dates.