Offer · Project Management

Project management for regulatory programmes

An experienced project manager who leads your NIS2, DORA, ISO 27001 or GDPR programme from requirements definition to audit-ready delivery, with structure, risk management and reporting in business language.

NIS2DORAISO 27001GDPRAudit-ready

Who it is for and when

Suits organisations that need to deliver a regulatory programme and lack the time or experience to lead it, especially when technology, policies and training must be coordinated across several departments.

  • A NIS2 or DORA programme must be delivered with a deadline and nobody internally has time to lead it.
  • An ISO 27001 certification must be reached within a year.
  • An ongoing programme has lost momentum and management wants control of status, risks and costs.
  • Many vendors and stakeholders are involved and there is no consolidated plan.

What we do

  1. Goals and scope. We establish what is to be achieved, which requirements apply, which parts of the organisation are affected and how success is measured.
  2. Plan and governance. Project plan, schedule, budget, roles and steering group are set up from the start, with a risk register and reporting routines.
  3. Delivery. We drive the work packages for policies, technical changes, supplier contracts and training, coordinate stakeholders and remove obstacles.
  4. Follow-up and reporting. Status meetings, management briefings and dashboards in business language so that decisions can be made in time.
  5. Closure and handover. Deliverables are handed over to the permanent organisation with documentation, and benefits realisation is followed up.

You get

  • Project plan with schedule, budget and roles
  • Risk register and action plans
  • Regular status reporting to management and steering group
  • Coordinated deliverables in technology, policies and training
  • Audit-ready handover with documentation

Scope and price

The engagement runs for the length of the programme, often six to twelve months, part-time or full-time depending on the size of the programme.

The price varies from engagement to engagement and depends on scope, length and how many days per week are needed. You get a proposal with set-up and cost after the first conversation.

How it works

  1. A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
  2. A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
  3. Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.

Frequently asked questions

Do you work agile or traditional?

Both, and often a hybrid. Regulatory programmes with clear requirements and deadlines get a structured model with phases and milestones, while technical parts are often run iteratively. We adapt the method to your culture.

Can you also do the subject-matter work, not just lead?

Yes. Our strength is that we understand the subject matter in information security, data protection and IT. If you want help with, for example, gap analysis, policies or risk work we combine project management with specialists from our other areas.

How do you report to management?

Through status meetings, management briefings and dashboards adapted to your needs, and always in business language so that management can take a position and make decisions.

Reviewed by Kristensson i Skåne AB. .

Sources: Project Management Institute (PMI) · EUR-Lex: Directive (EU) 2022/2555 (NIS2) · EUR-Lex: Regulation (EU) 2022/2554 (DORA)

Want to know how we would lead your programme?

Contact us