AI & Cyber Maturity Assessments: ISO 42001, NIST AI RMF, AI Act, NIS2/CyFun

Know where you stand

AI & Cyber
Maturity Assessments

Two distinct assessments, one accountable partner. AI maturity across your whole organization, cyber maturity against NIS2/CyFun. Fixed scope, fixed price.

Governance plays out on two complementary planes: AI governance and cyber governance. It's the same conversation. Do one, the other, or both.

AI track

AI Maturity Assessment

Your AI governance & readiness, mapped to ISO 42001, NIST AI RMF and the AI Act.

€4,900

Fixed scope, fixed price

Request this assessment
Cyber track

Cyber Maturity Assessment

Where you stand on NIS2, across CyFun levels.

From €4,900

Basic. Important & Essential: quote based on your maturity

Request this assessment
Best value

Combined AI + Cyber

Both, because AI and security are one conversation.

€7,900

Fixed scope, fixed price

Request this assessment

Every assessment ships with

  • Light risk register
  • Compliance gap analysis
  • Prioritized project list with effort estimates
  • Remediation roadmap: 90 days, 6 months, 12 months
  • Management readout for board and executives

Cross-track option Shadow AI Analysis

See the AI your teams already use. Scoped to your stack.

On request

Inside each assessment

AI track

AI Maturity Assessment

Our own framework, built on MIT research.

  • Mapped to ISO/IEC 42001, NIST AI RMF and the EU AI Act
  • The whole organization, not just the technology
  • Six pillars, including people and change management

The six pillars we assess

Strategy

Where the business is going. What AI should serve. Who decides.

AI is a means, not an end. Without a clear business strategy, every AI initiative becomes a tactical experiment with zero compounding ROI.

Governance

Risk, compliance, AI Act, NIS2, GDPR. Guardrails before deployment.

AI without governance creates legal, regulatory and reputational exposure. In regulated industries, NIS2, AI Act, GDPR and ISO 42001 aren't optional, they're the price of operating.

People

Skills, change management, culture. AI fails when humans don't follow.

AI tools are useless if humans don't use them. Every AI deployment is fundamentally a change management project. Skip this and adoption stays under 20%, ROI stays at zero.

Process

Workflows, ownership, documentation. AI automates what's defined.

AI automates what's defined. If your processes live in tribal knowledge in people's heads, AI can't reach them. Documentation isn't bureaucracy, it's the precondition for automation.

Data

Quality, structure, access. AI is only as good as what feeds it.

AI quality is bounded by data quality. Bad data plus AI equals bad decisions at scale, with audit trails. Garbage in, traceable garbage out.

Technology

Stack, integrations, infrastructure. The plumbing AI runs on.

AI runs on infrastructure. Models, vectors, integrations, identity, monitoring. Get the plumbing wrong and you'll spend more on debugging than on building.

What your scorecard looks like: six pillars, four maturity levels.

ISO/IEC 42001The framework we use

Policies

AI usage rules, ownership, accountability

Risk

Identification, assessment, treatment plan

Controls

Technical and organizational guardrails

Monitoring

Continuous review, audit trails, KPIs

Cyber track

Cyber Maturity Assessment

Built on the Belgian CyberFundamentals framework (CyFun) from the CCB.

  • Aligned with NIST CSF and ISO 27001
  • Three levels: Basic, Important, Essential
  • Assessed across the five CyFun functions
Cyber trackThe five functions we assess

Identify

Know your assets, risks and responsibilities

Protect

Safeguards for systems, data and people

Detect

Spot incidents and anomalies fast

Respond

Contain and handle incidents when they hit

Recover

Restore operations and learn from events

Step 2 Governance Follow-up

Execute the roadmap with us alongside. Day rate, on demand.

Discuss follow-up

Frequently asked questions

The answers we give on every first call.

€4,900, fixed scope, fixed price. It covers the six pillars and maps you against ISO 42001, NIST AI RMF and the EU AI Act. You own the deliverables: gap analysis, risk register, prioritized roadmap and a management readout.

Your security posture against NIS2 through the Belgian CyFun framework (Identify, Protect, Detect, Respond, Recover), aligned with ISO 27001. The Basic level is €4,900; Important and Essential levels are quoted based on your maturity.

Strategy, governance, people, process, data and technology. Each pillar is scored, for an overall maturity score out of 48 across four levels: Initial, Developing, Defined and Optimizing.

Yes. The combined AI + cyber assessment is €7,900, our best value: one engagement, one accountable partner, both roadmaps.

Your teams or our vetted partners. We architect, scope and steer the delivery under our governance; the build is never ours. That keeps you in control of your stack and your data.

Yes: the free online diagnostic. Twelve questions across the six pillars, an instant score and a PDF scorecard you can bring to the first call.

Do you know where you stand?

If you've deployed AI without a structured assessment, you don't. Let's fix that.

Book your assessment

Cookie Preferences

We use cookies for our HubSpot contact form and analytics, and for anti-spam (hCaptcha) on the free diagnostic. No advertising. Privacy Policy