Frequently asked questions on NIS2, the AI Act, the Diagnostic, CISO as a service, the AI Officer and the CDO

Frequent questions

Your questions.Our answers.

The ones we get on every first call, with the answers we give on the phone.

Does this concern us?

Four sentences come up more often than any other. They are fair, and here are our answers.

Scope depends first on your sector, not only on your size. The Diagnostic settles it: it is the first thing it establishes.

Your provider keeps IT running, and that matters. We work alongside them: compliance, evidence and risk steering are our part.

The benefit does not wait: knowing where you stand and closing the gaps pays off from now.

Writing down what you do clarifies it and speeds up decisions. And many clients require it before they sign.

Wherever you are, on site or remotely. Sessions and workshops are delivered in French or in English.

Cyber, CISO as a service

NIS2, CyberFundamentals, and what happens when we hold the role of your security lead.

Scope depends first on your sector, then on your size. It is the first thing the Diagnostic establishes.

In a company your size, this work does not always fill a position. What matters is that it is held, by someone whose name sits at the bottom of the decisions. That is the role we hold.

Everything we produce is in your name and stays with you. The day the engagement ends, there is nothing to get back.

The Diagnostic is quoted, based on your size and scope, and fixed before we start. Ongoing support runs on time and means: we agree on an envelope, and you use what you need.

AI, AI Officer

The AI Act, your AI uses, training your teams, and what an AI Officer holds.

As soon as your teams use an AI tool in their work, you are a deployer under the regulation, whatever your size. Article 4, AI literacy, has applied since 2 February 2025: an obligation of means, and the regulation attaches no fine amount to article 4.

No. You need to know who uses it, for what, with which data, and to have decided it. That is what the Diagnostic establishes and what the AI Officer holds.

Everything we produce belongs to you and stays with you, from the first month to the last. The day the mandate ends, there is nothing for you to retrieve.

The Diagnostic is quoted, based on your size and scope, and fixed before we start. Ongoing support runs on time and means: we agree on an envelope, and you use what you need.

No, and that is the point. ISO/IEC 42001 shares the harmonised structure of ISO/IEC 27001: the same chapters, the same review mechanisms, the same documentation requirements. The AI system sits beside the security one inside a single management system and reuses what already runs. A certified company has done a good part of the work without knowing it.

Transformation, CDO

Turning digital and data into a growth lever, without breaking everything.

No. We start from your goals and your processes, not from a tool. People first, process next, the tool last.

No. We take the time to understand you, so the changes we propose reuse what you already have instead of breaking it.

Everything is in your name and stays with you. The goal is for your teams to hold it alone: support that is not designed to shrink is a dependency.

The Diagnostic is quoted, based on your size and scope, and fixed before we start. Ongoing support runs on time and means: we agree on an envelope, and you use what you need.

There is always one question that is not on this list.

A first thirty-minute call, free of charge, to lay out your case and see what is worth doing at your company. If the answer is that you need nothing for now, you will hear that too.

Ask for a first call →