NIS2 readiness
First we establish whether your firm qualifies as an essential or important entity, or is pulled in indirectly as a supplier to one. Next comes a risk assessment, then measures like MFA, backups and logging, an incident drill that has actually been practised, and evidence fit to show the competent authority.