NIS2 · CRA · DORA · AI Act

Regulatory compliance and cyber security for cloud-native organisations.

NIS2, CRA, DORA, and the AI Act are in force or entering enforcement. Organisations that are not ready face fines, operational disruption, and personal director liability. Epitechnic helps organisations across the UK and EU get ready and stay compliant.

Offices in London, Warsaw, and Berlin. UK and EU jurisdictions covered in a single engagement.

What we do

Three service lines. One proposition.

Epitechnic delivers regulatory compliance programmes, the technical security controls those programmes require, and the governance layer that connects them to the management body.

Regulatory Compliance Programmes

NIS2, CRA, DORA, and AI Act. From a five-day diagnostic establishing scope and readiness, through programme design and phased delivery, to sustained compliance after programme close.

NIS2 services

Technical Security Delivery

The security controls a compliance programme requires. Identity and access management, infrastructure and system security, supply chain security, zero trust architecture, and application security.

About Epitechnic

Security Governance

Board reporting, governance design, policy frameworks, and evidence and audit readiness. The governance layer that sits above the technical controls and connects the programme to the management body.

About Epitechnic
Why Epitechnic

Three things that are difficult to replicate.

Regulatory depth

We work across NIS2, CRA, DORA, AI Act, and their UK equivalents. Each engagement draws on direct programme experience across all four frameworks, not generic compliance advisory.

One firm, three jurisdictions

Offices in London, Warsaw, and Berlin give Epitechnic the ability to advise on UK cyber resilience frameworks and NIS2 obligations under German and Polish national transposition law from a single engagement team. No coordination overhead between national advisers.

Senior-led throughout

The people who sell the work deliver it. No partner-led sales and associate-led delivery. Senior involvement from the diagnostic through to programme close.

Entry product

The NIS2 Readiness Diagnostic.

Five days. Fixed scope. Six defined outputs. The diagnostic establishes where the organisation stands before committing to a full programme, and produces a programme readiness brief written for the management body.

Six outputs from five days
  • Provisional scope statement — which entities are in scope, under which national laws, and what the key uncertainties are
  • Governance readiness assessment — whether the sponsorship and board conditions exist for a programme to succeed
  • Article 21 domain maturity map — where the organisation stands across all ten NIS2 obligation domains
  • Incident readiness assessment — whether the organisation could meet the 24-hour early warning obligation today
  • Supply chain exposure map — which supplier relationships carry the most significant security gaps
  • Programme readiness brief — a four-page executive document summarising findings and decisions, written for the management body

Epitechnic holds Cyber Essentials Plus certification, independently verified by a UKAS-accredited certification body.

Start the conversation

Tell us where you are with NIS2, CRA, DORA, or the AI Act.