Introduction
Saros Consulting’s CyFun Readiness Assessment gives Irish organisations a scored, evidence-based position against the Cyber Fundamentals framework in five days.
This is not just an assessment and a report. We hand you a sequenced NIS2 compliance roadmap and the starter tools to close the gap yourself, fast: a scored position, an action plan, policy templates, and a board-ready case.
Our engagement starts before we arrive. We send you the CyFun self-assessment workbook and a short document list two weeks ahead, so our five days are spent closing gaps rather than gathering paper.
This assessment sits within our wider Regulatory Compliance and Security Governance practice, the same team behind our NIS2 and DORA compliance programmes.
The position we hand you is backed by delivery experience, not a one off exercise.
NIS2 Compliance in Ireland: The situation, in plain terms
Ireland has not finished transposing NIS2 into domestic law. On 8 July 2026 the European Commission referred Ireland to the Court of Justice of the European Union, seeking daily financial penalties until transposition.
That is a gap in legislation, not a gap in obligation. Your customers, insurers, and supply chain partners are not waiting for Dublin to catch up.
A formal national CyFun certification scheme is expected to become available in 2027, which many organisations are reading as permission to wait. It is not.
The framework is already the benchmark being used informally, by customers, insurers, and boards, today.When Irish NIS2 law lands, it applies immediately. There is no grace period for organisations that used the wait and see approach.
How we benchmark you against the Cyfun framework
We benchmark you against Cyber Fundamentals, CyFun, Ireland’s chosen national scheme, co owned by NCSC Ireland alongside Belgium and Romania, and built on NIST CSF 2.0 with control requirements drawn from ISO/IEC 27001 and the CIS Controls.
This is also the practical foundation behind NIS2, which applies across the EU, with fines for Essential entities reaching 10 million euros or 2 percent of global annual turnover, whichever is higher, and personal liability now reaching management.
Who needs a Cyfun and NIS2 readiness assessment
- Essential and Important Entities Under NIS2
- Organisations that already know, or suspect, they fall within scope and need a scored, evidenced position, not just a legal opinion.
- The Critical Supply Chain
- Organisations being asked by larger customers to prove their security controls as part of vendor risk assessments and procurement processes.
- Organisations Renewing Cyber Insurance
- Insurers are increasingly requesting framework based evidence of maturity, and its absence is now showing up in premiums and coverage terms.
- Heads of IT and Security
- Leaders who need a credible, externally recognised position to bring to the board, not an internal self assessment nobody outside the organisation will trust.
- Organisations Already Certified to ISO 27001
- You are further along than you think. We can provide a gap analysis against CyFun and NIS2 requirements, along with a remediation plan.
Why choose Saros for your Cyfun readiness assessment?
Without a clear, evidenced position, your organisation faces exclusion from supply chains, as Essential and Important entities are legally required to assess vendor risk, and unproven suppliers are the easiest ones to drop.
It faces rising insurance and financing costs, as insurers and lenders increasingly request framework-based evidence, pricing its absence as a risk. It faces a false sense of readiness, built on internal self assessment rather than an objective, externally recognised benchmark.
And it faces a larger, more expensive gap to close later, for every quarter spent waiting for legislative certainty instead of acting on it.
Our CyFun readiness assessment replaces all four with a scored position, a sequenced plan, and a set of ready to use assets you can put in front of customers, insurers, and your board this quarter.
Our five-day Cyfun assessment methodology
The Saros Consulting expert team works alongside you through a structured methodology, built to deliver maximum output within a single business week.
Day 1: Scoping and Target Level Setting
A kick off meeting with key stakeholders, applying the CyFun selection tool to determine which CyFun level applies to you, Basic, Important or Essential, factoring in organisation size, sector, and risk exposure alongside your status under NIS2.
This establishes which level your organisation should be aiming for, and why, giving the assessment a clear and defensible benchmark from day one.
Day 2 to 3: Control by Control Maturity Assessment
Structured workshops and a review of existing documentation across the six core functions: Govern, Identify, Protect, Detect, Respond, and Recover, benchmarked against the NIST Cybersecurity Framework.
We start with Govern, because it is where board accountability under NIS2 sits and it is usually the weakest function in organisations with capable technical controls. This scores your current maturity control by control and identifies precisely where you fall short of your target level.
Day 4: Gap Prioritisation and Asset Drafting
Consolidation of findings, classification of gaps by effort and commercial impact, and preparation of policy and control templates for the areas most likely to be tested by customer, insurer, or regulator due diligence. This separates quick wins from strategic investment, and puts the first drafts of your missing evidence in hand before the week is out.
Day 5: Handover and Boardroom Readiness
Our expert team consolidates all findings, templates, and scores into your full toolkit, presented directly to your leadership team. The final session is facilitated rather than presented.
We walk your board and leadership teams through what they are expected to be able to demonstrate, and what to ask for at each meeting. This leaves your leadership with a scored position, a sequenced action plan, and the assets to act on it immediately, not a report to file away.
What you walk away with
This is not a single report. It is a set of ready to use assets, built during the assessment, that you can act on and hand out from day six.
1. CyFun Maturity Scorecard: a scored, evidenced position against your target level.
2. 30, 60, 90 Day NIS2 Remediation Roadmap: a sequenced action plan with owners, effort estimates, and quick wins flagged for immediate action.
3. Policy and Control Templates: templates mapped to your highest priority gaps, such as your incident response playbook and supply chain security policy, so remediation starts with a head start, not a blank page.
4. Board Briefing Pack: a presentation built for your leadership team, so you walk into the boardroom with the case already made.
5. Customer and Insurer Assurance Statement: a ready to send document confirming you have completed an independent, framework aligned readiness assessment, something you can put in front of a customer or insurer immediately. The statement explicitly states that this is an advisory readiness assessment, not a CyFun verification, certification or label.
We combine deep NIS2, DORA, and CyFun domain knowledge with practical, on the ground implementation experience across the sectors most exposed to these regimes, backed by the same governance and cybersecurity expertise behind our wider regulatory compliance practice.
Get in Touch with
Saros Consulting
You Have a Window. It Is Closing.
Contact us today to schedule your CyFun Readiness Assessment, and walk away with a scored, evidenced, board ready NIS2 position, before the gap between where you stand and where the law expects you to be gets any harder to close.



