Readiness workflow

How the ConformityAgent process works

The same core workflow is used for NIS2 and ISO/IEC 27001: we collect structured information, assess readiness, organize evidence, and prepare human-reviewed recommendations. The difference comes from the selected framework, deliverables, and depth of analysis.

ConformityAgent
NIS2 readiness and evidence preparation for Romanian and EU SMEs.

NIS2 process

For NIS2, the process focuses on applicability, security measures, risk management, incidents, suppliers, continuity, and evidence useful for management or discussions with consultants and auditors.

View NIS2 steps

ISO/IEC 27001 process

For ISO/IEC 27001, the process focuses on the ISMS scope, risk assessment, risk treatment plan, controls, evidence, and Statement of Applicability.

View ISO 27001 steps
Readiness workflow

The shared process core

Regardless of the selected framework, the ConformityAgent process follows the same core logic: structured information, analysis, recommendations, human review, and management-ready deliverables.

1

Initial request

The company submits basic information about the organization, sector, size, technology context, and reason for the request.

2

Framework selection and scope clarification

We determine whether the request concerns NIS2, ISO/IEC 27001, or a combined package. We clarify the assessment scope and expected level of detail.

3

Structured questionnaire

The client completes a questionnaire adapted to the selected framework. Questions are grouped around areas such as governance, risks, access, incidents, suppliers, backup, continuity, and evidence.

4

Answer analysis

The answers are analyzed to identify the current readiness level, covered areas, gaps, and remediation priorities.

5

Evidence organization, where applicable

For standard or advanced packages, relevant evidence can be structured: policies, procedures, registers, technical documents, responsibilities, and actions.

6

AI-assisted draft and human review

The platform prepares a structured draft of the report or deliverables. The human team reviews consistency, adjusts recommendations, and checks whether the result is usable.

7

Final management package

The client receives a report or preparation package that can support internal decisions, remediation planning, and discussions with consultants, auditors, certification bodies, or legal partners.

NIS2-specific process

For NIS2, the focus is on understanding the directive’s applicability, readiness against relevant security measures, risk management, incident response, supplier security, and evidence that can support management decisions.

  • preliminary NIS2 applicability check
  • sector and organization size analysis
  • NIS2 readiness questionnaire
  • assessment by areas: governance, risks, incidents, access, backup, suppliers, continuity
  • initial or detailed risk list, depending on the package
  • initial or detailed evidence list, depending on the package
  • prioritized recommendations
  • management report
Request NIS2 check

ISO/IEC 27001-specific process

For ISO/IEC 27001, the focus is on structuring the Information Security Management System, defining the ISMS scope, risk assessment, risk treatment plan, controls, evidence, and Statement of Applicability.

  • ISMS scope clarification
  • ISO/IEC 27001 readiness questionnaire
  • high-level gap analysis
  • initial control applicability check
  • risk register structure
  • risk treatment plan for advanced packages
  • control-to-evidence mapping
  • draft Statement of Applicability for relevant packages
  • preparation for discussions with auditors, consultants, or certification bodies
Request ISO 27001 readiness
NIS2 + ISO/IEC 27001

Combined NIS2 + ISO/IEC 27001 process

For combined packages, we work with a shared evidence structure. The same policies, registers, procedures, controls, and documents can support both NIS2 readiness and ISO/IEC 27001 preparation. The objective is to avoid duplicated work and build a reusable compliance base.

View combined package pricing

Important clarification

ConformityAgent provides readiness, gap analysis, evidence organization, and compliance management support services. The process does not represent an official audit, accredited certification, legal advice, or a guarantee of compliance. For formal audits, certification, or legal opinions, we can discuss collaboration with auditors, certification bodies, lawyers, or specialized consultants.