
Is your company covered by the NIS2 Directive - or do you provide IT solutions to someone who is?
ISAE 3000 - documenting your NIS2 compliance
Is your company covered by the NIS2 Directive - or do you provide IT solutions to someone who is?
With an ISAE 3000 statement, you can prove that your security efforts meet the requirements of NIS2 and that your processes are designed and implemented correctly.
What is an ISAE 3000 statement with a focus on NIS2?
It is an independent auditor's report that assesses whether your controls and processes match the requirements of the NIS2 Directive - e.g. in terms of risk management, incident management, governance and documentation.
The statement can be used to demonstrate compliance to customers, partners, regulators and your own management.
When is ISAE 3000 NIS2 relevant?
- When you are directly covered by NIS2 (critical or important sector)
- When customers or partners demand documented NIS2 compliance
- When board and management want assurance on liability and risk management
- When you need to prove your maturity and readiness to authorities
- When you want an alternative to certification
Do you need help getting ready?
Many companies don't have a complete setup yet - and start with a maturity check and an action plan.
We help you get a handle on the requirements and necessary controls.
Read more about our consulting services here
Ready to get an NIS2 declaration?
We prepare ISAE 3000 declarations based on NIS2 requirements - customized to your size, industry and risk profile.
Read more about our declarations here
Tool: Lexoforms
Lexoforms can be used to gather your documentation, risk assessments, controls and follow-ups - so you can easily prepare for an ISAE 3000 declaration.
Frequently asked questions (FAQ)
Is an ISAE 3000 statement a requirement in NIS2?
No - it's not a direct requirement. But it is a strong and recognized method to prove your compliance to both customers and authorities.
Does the declaration need to cover the entire company?
No - it can be limited to the system, business area or function covered by NIS2.
What is the difference between Type 1 and Type 2?
Type 1 assesses the design and implementation of controls at a point in time.
Type 2 also assesses whether they have worked effectively in practice over a period of time (typically 6-12 months).
Contact us - we'll guide you through the process with confidence
Want to show that you take NIS2 seriously and are on top of your cyber security?
We guide you all the way from maturity check to declaration.
Contact Simon
-
Simon Okkels
Simon Okkels is a Certified Information Systems Auditor (CISA®) - a global certification that guarantees deep knowledge of audit processes, reporting and compliance procedures within IT auditing and IT and information security.
Contact John
-
John Richardt Søbjærg
John Søbjærg is a state-authorized public accountant with in-depth knowledge of small and medium-sized companies in many industries. He has many years of experience in advising companies and issuing auditor's reports.
Contact Rasmus
-
Rasmus Lykke Sørensen
We are always ready to meet
Let's have a no-obligation conversation about what you and your business need and what we can offer. Just fill in the fields in the form and we will contact you shortly.
You are also welcome to call us at +45 39 53 50 00 or send an email to


Employees
140

Customers
3900

Revenue
+150 million

Year of establishment
1986



