HodeiShield: The European TPRM platform with native NIS2, ENS, and DORA
ISMS implementation, security master plans, and compliance roadmaps for NIS2, ENS, DORA, and ISO 27001, sustained afterward by HodeiShield so compliance doesn't depend on a one-off audit.
Illustrative readiness by framework
Illustrative readiness levels (sector-average estimate), not a real client figure. The entry-into-force dates are real.
No security master plan — reactive security costs 3x more than preventive and every audit catches you unprepared
NIS2, ENS, and DORA all at once — three regulations with overlaps and divergences that without experts end up as triple work
ISO 27001 as a never-ending project — certification can be structured in 9-12 months with a proper gap analysis and documentation from the start
Consultants who don't know your sector — a generic master plan doesn't work for critical infrastructure or financial services
Four pillars that apply to every service and every solution, not a one-off slogan.
The same team that attacks in the pentest runs the SOC and builds the AI models. Offensive insight informs defense, and AI is applied where we already operate, not bolted on as an extra layer.
HodeiShield, our own platform, automates continuous assessment, control mapping, and evidence generation — so manual work no longer sets the pace of regulatory compliance.
Infrastructure on OVHcloud (France/EU). You speak with the people who sign off on the work, not an account manager who forwards your request to another department.
HodeiShield isn't a third-party product we resell: we build and operate it ourselves, and that's what lets us offer faster compliance and evidence that's always current.
Deliverables and results you will receive with this service.
Assessment of current state against the target regulatory framework (NIS2, ENS, DORA, ISO 27001) with identification of critical gaps and risk-based prioritization.
Roadmap prioritized by impact and effort with milestones, owners, estimated budget, and tracking metrics.
Security policy, procedures, records, and complete documentation ready for ISO 27001 or ENS certification audit.
Support during ISO 27001 or ENS Medium/High certification, including prior internal audit and gap remediation.
Training of the internal team on implemented controls to ensure management system sustainability.
Discovery, execution, delivery, and follow-up — the framework we follow on every project.
Thorough gap analysis against the target regulatory framework (NIS2, ENS, DORA, ISO 27001) to identify your current position and critical gaps.
We design the master plan and implement it: policy and procedure documentation, technical control configuration, and step-by-step support for your team.
Internal audit verifying effective control implementation and remediating identified gaps before external certification.
We support the external certification process and response to auditor findings, and leave your internal team trained to sustain the management system.
Structured methodology to ensure measurable and repeatable results.
Thorough gap analysis against applicable regulatory frameworks. We identify your current position and gaps against NIS2, ENS, DORA, or ISO 27001.
We design the security master plan with control prioritization based on risk reduction vs implementation effort.
Documentation of policies, procedures, and records. Technical control configuration. Step-by-step support for your team.
Internal audit to verify effective control implementation. Remediation of identified gaps before external certification.
Support during external certification process (ISO 27001 Stage 1 and 2, or ENS). Support in responding to auditor findings.
A real scenario of how we work, not a marketing figure.
The ENS gap analysis reveals missing documented incident-management procedures. Instead of handing over a report that just flags the gap, we draft the procedure together with your team, test it in a drill, and leave it operational before the external auditor asks for it.
This service is designed for organizations that identify with these profiles.
No names — here's how we work differently, with verifiable facts.
| Criteria | Generalist integrator | Hodeitek |
|---|---|---|
| Focus | Dozens of business lines; cybersecurity is just one of them | 100% cybersecurity and AI |
| Point of contact | An account manager who forwards your request to another department | Direct contact with the founders |
| Regulatory compliance | One-off reports per regulation, manual evidence management | HodeiShield automates evidence and cross-framework NIS2/ENS/DORA mapping |
| Product | Resells third-party licenses | Builds and operates HodeiShield, its own platform |
How what this service already includes relates to NIS2, DORA, and the AI Act — article by article, with no invented coverage.
| Framework | Article | What it requires | How this service helps |
|---|---|---|---|
| NIS2 | Art. 21 | Adopt appropriate and proportionate technical, operational and organisational cybersecurity risk-management measures. | The Regulatory Gap Analysis and the Security Master Plan cover that cycle: they identify the gaps against NIS2 and prioritize measures by risk, with the ISMS Documentation as evidence. |
| NIS2 | Art. 23 | Notify significant incidents: early warning within 24h, incident notification within 72h, and a final report within 1 month. | The ISMS Documentation includes incident-management procedures — as this service's operational example shows, we draft and test them with your team before an auditor asks for them, the basis for being able to meet these notification deadlines. |
| DORA | Art. 5–16 | Maintain a documented and proportionate ICT risk management framework. | For financial entities, the Security Master Plan and ISMS Documentation are already built against DORA, as the service description states, structuring the ICT risk framework this block requires. |
Informational mapping, not legal advice: it describes how what we already do in this service helps comply with or provides evidence for each article — it doesn't replace a compliance assessment tailored to your organization.
Talk to our team of experts to design a plan tailored to your organization's needs.
Response within 24h
How we've applied this service in real projects.
Assess, monitor, and govern the cybersecurity risk introduced by your vendors, third-party software, and your organization's Nth-party dependencies.
Comprehensive guidance to achieve and maintain compliance with the European NIS2 cybersecurity directive.
Specialized protection for industrial control systems (ICS), SCADA, PLCs, and operational technology environments.