Strategic Assessments Measurable Certainty

The Diagnostic Foundation for EU Regulatory Compliance & Risk Reduction

In a landscape where "adequate" security is no longer enough, our Assessments & Diagnostic Services provide the clarity you need to lead with confidence. We move beyond surface-level audits to deliver deep-dive technical and strategic evaluations. Utilizing our Unified Sentinel Protocol, we map your current state against global benchmarks to identify not just where you are, but exactly where you need to be.

Choose Your Assessment Path

Our assessments are designed to build logically on one another, creating a clear and progressive understanding of your security posture.

You can start with a single targeted assessment if you need answers to a specific question, or choose one of our pre-defined Assessment Bundles for maximum value and efficiency. For a full list of individual services check out our A - Z Directory

Pro tip: Choosing one of our bundled programmes typically delivers better insights, stronger deliverables, and clear cost savings compared to purchasing the individual assessments separately.

Not sure which path is right for you? Book a short scoping call and we’ll recommend the most suitable assessment or bundle based on your current situation and regulatory pressures, usually within 72 hours.

Strategic Assessment Bundles


NIS2 Readiness Assessment Bundle -
NIS2 Quick-Scan & Gap Programme

Price: €11,900 (save €2,700 compared to individual assessments)

A fast, practical starting bundle designed to get you NIS2-compliant quickly. It combines obligation mapping, current-state baseline assessment, gap analysis, and a prioritised remediation roadmap — all tailored to the Dutch Cyberbeveiligingswet.

Ideal for: Organisations newly in scope of NIS2 who need clear visibility on where they stand and what to do first.

ISO 27001 Readiness Assessment Bundle - ISO 27001 Pre-Certification Gap Programme

Price: €13,900 (save €3,100 compared to individual assessments)

A targeted assessment package that evaluates your readiness for ISO 27001 certification. It includes Scoping & Gap Assessment against ISO 27001:2022, Risk Assessment, Control Analysis, Statement of Applicability support, and a detailed pre-audit readiness report.

Ideal for: Companies planning to achieve or renew ISO 27001 certification and need an honest, structured gap analysis before committing to full implementation or external audit.


Framework & Maturity Assessment Bundle -
Choose the Right Framework & Measure Maturity

Price: €10,900 (save €2,700 compared to individual assessments)

Helps you decide which framework(s) best fit your organisation and objectively measures your current security maturity. Includes Framework Assessment, Maturity Assessment, Control Analysis, and Gap Analysis.

Ideal for: Organisations that are unsure whether to focus on NIS2, DORA, ISO 27001, BIO, or a combination, and want an independent view of how mature their security programme really is.

Full Risk & Vulnerability Assessment Bundle - Comprehensive Risk Deep-Dive

Price: €15,900 (save €3,700 compared to individual assessments)

An in-depth risk-focused bundle that delivers a complete picture of your threats, vulnerabilities, and business impact. Includes Baseline Assessment, Threat Assessment, Vulnerability Assessment, Risk Assessment, and Consolidation Assessment.

Ideal for: Companies that want a thorough, business-oriented understanding of their real risks before investing in remediation or resilience processes.

Tangible Deliverables

You receive a "Ready-to-Present" executive package which, depending on the assessment, may comprise of:

  • Executive Scorecard: A high-level maturity rating (0-5) suitable for Board or Supervisory Authority briefings.

  • Prioritized Risk Register: A list of weaknesses ranked by business impact, not just technical severity.

  • Framework Alignment Report: A direct mapping of your current controls to regulatory requirements.

  • The Consolidation Plan: Specific recommendations on which controls to implement, merge or eliminate to save costs.

Transparent Flat-Fee Pricing

We Believe in Building Trust through Transparency. Strategic assessments are delivered as fixed-scope projects to ensure budget predictability. Every assessment is guided by our unified methodology.

  • Financial Predictability: By utilizing a flat-fee model, we eliminate "consultancy creep." You receive a fixed-price engagement with zero hidden costs, allowing for precise budget allocation and easier internal approval.

  • Outcome-Linked Pricing: We tie our fees to tangible deliverables. You aren’t paying for "hours spent," but for the surgical insights and the Executive Roadmap required to secure your perimeter.

Forculus facilitates strategic alliances to bridge the gap between regulatory demands and operational security resilience.

Board-Ready Logic

The cost of a single NIS2-related fine or data breach far outweighs the diagnostic investment. Our clients typically identify and consolidate 15 to 20% of redundant security controls within their first assessment cycle, immediately freeing up operational budget.

This diagnostic suite is designed for Compliance Officers, Risk Managers, and IT Directors within the European mid-market sector who are tasked with navigating the shift toward regulatory compliance with, for example, NIS2, BIO2, ISO27001 and NEN 7510. It is the ideal entry point for organizations that need a technical and organizational baseline before committing to large-scale security investments.

Who is this for?

This is not a fit if:

  • You need a "Rubber Stamp": We provide honest, critical data. If you are looking for an assessment that ignores real risks to satisfy a checkbox, we are not the right partner.

  • You are a Micro-Business: Our assessments are optimized for the complexity of Dutch and EU medium-to-large enterprises; smaller entities may find the depth of our Unified Sentinel Protocol excessive.

  • You only want automated scans: While we use tools, our value is in the expert analysis of that data. We are not a low-cost automated scanning service.