NIS2 in force · ISO 27001

NIS2 and ISO 27001 — without panic, with a clear plan

I help management understand what actually needs to be done, where to start, and what to show a client, auditor or regulator. Practical, not theoretical — from self-check to a working system.

Who this is for

When cybersecurity becomes a management responsibility

Practical support for organisations that need more than technical controls: responsibilities, decisions, documentation and evidence for clients, auditors or management.

Management

Decision clarity

What must be decided, who owns the risk and what can be shown to clients, auditors or regulators?

Suppliers

Evidence for clients

When clients ask for NIS2, ISO 27001 or security control evidence, organisations need structured proof, not vague assurances.

Growing companies

ISO 27001 direction

Understand whether ISO 27001 is needed now, what the scope might be and what resources would be required.

Teams

A working system

Documentation, risk management, suppliers, incidents and management reviews need to work in day-to-day operations.

The problem I solve

Documents are necessary. Governance creates readiness.

The gap is rarely only missing documentation. The real issue is often unclear cyber governance: decisions, responsibilities, evidence and operational reality are not connected.

Unclear ownership

Who makes decisions about risk, incidents, suppliers, access and continuity?

Weak evidence readiness

Documents may exist, but the organisation cannot clearly show how cyber risk is governed.

NIS2 or ISO seen too narrowly

A regulatory or certification issue becomes an IT task, while the real need is a management system.

Quick check

Start with a short readiness self-check

The assessment helps identify whether responsibilities, evidence, incident escalation, supplier risk and management decisions are clear enough for NIS2-related expectations or client security questionnaires.

Who owns NIS2 readiness evidence and action coordination?
Does management know what decisions should be made in the first hours of an incident?
Can you show documented responsibilities, risk logic and supplier oversight?
Could you respond to a client security questionnaire with evidence, not only statements?

5 questions, under 2 minutes, with an instant result showing which readiness stage you are in. If you want a deeper picture, you can continue to the full assessment.

Services

NIS2 readiness, evidence and ISO 27001 implementation support

The scope is selected based on the organisation’s situation: from initial NIS2 readiness assessment to full ISO 27001 implementation support before certification audits. If you are still unsure whether you need NIS2 or ISO 27001, start with a short explanation — then it is clear what to ask for.

NIS2

NIS2 readiness assessment

Assessment of responsibilities, documentation, incident governance, supplier risk, business continuity, management involvement and evidence readiness.

NIS2 documentation

Governance documents and evidence

Practical support with NIS2-related documents, responsibilities, risk management logic, incident escalation and supplier risk governance.

ISO 27001

ISO 27001 consulting and implementation

Support with ISO/IEC 27001 business case, ISMS structure, documentation, responsibilities, risk management and readiness for certification audits.

Client evidence

Supplier questionnaires

Support in preparing a clear structure of answers and evidence when clients request NIS2, ISO 27001 or cybersecurity control information.

ISO 27001

Three practical paths

Not every organisation needs a full implementation project immediately. The right first step is to choose the path based on business need, maturity and available internal resources.

Path 1

Business Case & Roadmap

A management decision document: realistic scope, priorities, implementation options, 3-year cost logic and potential business value.

Path 2

Methodological supervision

Your internal team leads the project, while I provide direction, reviews and feedback on risk assessment, SoA, policies and audit readiness.

Path 3

Full certification readiness support

ISO 27001 implementation support from ISMS scope, risk assessment and SoA to readiness for Stage 1 and Stage 2 certification audits.

I help organisations practically prepare for ISO/IEC 27001:2022 certification audits: ISMS structure, risk management, documentation, responsibilities, evidence and management readiness. Not sure whether you need ISO 27001 or NIS2? Comparison here →

ISO 42001 · AI governance

Your people already use AI. The question is whether you govern it.

ChatGPT, Copilot and other tools are already running inside your organisation — often without rules or visibility. When a client or regulator asks how you manage AI risk, words won't be enough. You'll need to show it. ISO/IEC 42001 is the first international AI management standard — the same evidence logic as ISO 27001, now applied to artificial intelligence.

Assessment

AI governance gap analysis

Where your organisation stands today: which AI tools are in use, what data moves through them, and what's missing against the standard.

Implementation

Building the AI management system

Policies, controls, accountability and risk management for AI use — practical, without bureaucracy, sized for SMEs.

Audit readiness

Certification readiness

I prepare your AI management system so you pass the audit with something to show — a working system, not paperwork on a shelf.

In 2 minutes, check whether your organisation governs AI use — or just hopes it's fine.

How the work is structured

From situation assessment to a clear implementation path

The process is focused on management clarity, practical decisions and usable evidence — not documentation for its own sake.

Situation assessmentWe clarify the business context, regulatory pressure, client requirements, existing documents and operational reality.
Clear roadmapWe define what to fix first, who needs to make decisions and what evidence will be needed.
Implementation or review supportDepending on the selected model, I help create documents, review materials, support readiness and prepare for audits or client questionnaires.
About

Cybersecurity governance support for management

My work helps management treat cybersecurity as a question of governance, accountability and business continuity.

Practice

  • Ongoing NIS2 compliance implementation projects in the manufacturing sector
  • Security assessment of an IT services company against an aviation sector client's 28-question security questionnaire — gap analysis, plan and implementation instructions
  • Delivered cyber resilience training for a tourism sector company
  • Cyber resilience training for a non-profit organisation (pro bono)

Darius Jasiulionis

ISO 27001:2022 Lead Implementer providing consulting support on NIS2 readiness, cybersecurity governance, ISO 27001 implementation and certification audit readiness.

  • ISO 27001:2022 Lead Implementer
  • ISO/IEC 42001 (AI management system) Lead Implementer
  • 600+ hours of cybersecurity training
  • NKSC (National Cyber Security Centre) cybersecurity qualification
  • Services provided by UAB StarPrus
Contact

Need to assess NIS2 or ISO 27001 readiness?

If you are still considering — start with a quick 2-minute check to see where you stand. If you already know the situation – send me an email, and I will suggest a rational first step.

Cyber governance · NIS2 readiness assessment · ISO 27001 consulting · ISO 27001 implementation · documentation · client evidence

Cookie settings