NIS2 · DORA · ISO/IEC 27001 · CIS CSC

We read the regulation and the configuration.

M3 Consulting is a small, senior team built around one belief: compliance and cybersecurity aren't two different disciplines. We work across your controls, your architecture and your audit evidence — so nothing gets lost in translation between the compliance function and the engineers who have to implement it.

Directive (EU) 2022/2555 — NIS2 Regulation (EU) 2022/2554 — DORA ISO/IEC 27001:2022 CIS Controls v8

What sets us apart

Not another slide deck between compliance and engineering.

NIS2 Art. 21

Compliance that maps to architecture

Every recommendation traces from a regulatory clause to a concrete control or design decision — not the other way round.

ISO 27001 Annex A

Senior consultants, always

No bench of juniors learning on your engagement. Every project is staffed by people who have implemented what they audit.

CIS CSC

Right-sized, not off-the-shelf

Recommendations are scoped to your actual risk profile and resources — not a generic maturity template copied between clients.

Services

Different challenges, one team.

Each service can stand alone or run together as part of a wider compliance and security programme.

Directive (EU) 2022/2555 · Reg. (EU) 2022/2554

NIS2 & DORA Compliance

Gap assessments, risk management frameworks, incident reporting procedures and ICT third-party risk management, built for essential entities and financial institutions alike.

Read more →
ISO/IEC 27001:2022

ISO 27001 Certification Support

Full-lifecycle ISMS support — scoping, risk methodology, Statement of Applicability, internal audits and certification-audit readiness.

Read more →
Independent technical & process audit

IT Audit

Independent audits of IT general controls, access management, change management and vendor oversight, with a prioritised remediation plan.

Read more →
CIS Critical Security Controls v8

Security Architecture Review

Network, identity, endpoint and cloud architecture assessed against the CIS Controls, mapped to the Implementation Group that fits your organisation.

Read more →

How we work

Tailored to your organisation, not a template.

We turn away work that doesn't fit our model. In exchange, every client gets direct access to the consultants doing the work — no account managers relaying messages between you and the people who understand your systems.

More about M3 →
  • ✓Direct access to senior consultants throughout the engagement
  • ✓Findings connected to evidence an auditor will actually accept
  • ✓Recommendations scoped to your risk profile, not a generic checklist
  • ✓One team across compliance, audit and technical architecture

Insights

Recent writing

Who actually falls in scope, and what changes first

A practical read on entity classification and the first 90 days of obligations.

Read →

What belongs in your register of information

Getting ICT third-party risk documentation right before the auditor asks for it.

Read →

Choosing the right Implementation Group

Why IG1 is often the right ambitious answer, and when it isn't.

Read →

Let's talk about where you actually stand.

A first conversation costs nothing and commits you to nothing. Tell us what's driving the engagement — an audit, a deadline, a board request — and we'll tell you honestly what it will take.

Get in touch