1. Thesis
The Belgium NIS2 Conformity Evidence Desk sells Belgian essential and important entities a done-for-you, auditor-facing evidence packet that maps current controls, policies, incident-response records, supplier files, management-body oversight, and remediation exceptions to the Belgian NIS2/CyberFundamentals or ISO pathway. The buyer is not asked to operate an AI compliance tool; a human cybersecurity/compliance lead receives, reviews, and submits a source-linked workpaper set prepared by an internal AI evidence engine and approved at explicit expert chokepoints.
2. Discovery rationale
The run scanned cybersecurity regulation, AI governance, securities filing access, climate disclosure, consumer subscription rules, and medical-device laboratory deadlines. NIS2 Belgium won because it combined official, current regulatory timing with concrete evidence pathways, cross-sector buyer urgency, and a workflow that is heavily document-based but still requires human cyber judgment. Click-to-cancel and LDT were rejected because current court or FDA actions weakened the regulatory trigger; SB 261 was weakened by enforcement uncertainty; EDGAR Next was credible but narrower and less repeatable.
3. Candidate comparison
| Candidate | Buyer | Outcome | Score | Evidence | Dynasty type | Decision |
|---|---|---|---|---|---|---|
| Belgium NIS2 Conformity Evidence Desk | Belgian essential and important entities | CAB/CCB-ready CyFun or ISO evidence pack | 86/90 | High | Dynasty vertical blueprint | Selected: official April 18, 2026 milestone, concrete evidence pathways, broad cyber evidence pain, and bounded pilot. |
| EU AI Act High-Risk Deployer File Desk | Enterprises deploying high-risk AI in employment, credit, education, public services | Article 26/27 deployer file and FRIA workpaper | 78/90 | Medium | Dynasty vertical blueprint | Rejected this hour: strong 2026 signal, but current omnibus timing uncertainty weakens urgency. |
| EDGAR Next Lockout Recovery Desk | SEC filers, funds, issuers, filing agents | Recovered EDGAR access and account governance packet | 70/90 | High | Dynasty module bundle | Rejected: verified access pain, but narrower one-time remediation window and lower recurring service surface. |
| California SB 261 Climate Risk Report Desk | Large companies doing business in California | Public climate-related financial risk report and docket packet | 61/90 | Medium | Standalone business | Rejected: statutory need exists, but enforcement was reportedly paused by litigation; overlaps prior climate disclosure work. |
| FTC Click-to-Cancel Remediation Desk | Subscription businesses | Negative-option consent/cancellation compliance packet | 40/90 | Low | No fit | Rejected: federal rule was vacated, so the core regulatory trigger failed. |
| FDA LDT Phaseout Readiness Desk | Clinical laboratories | LDT registration/listing and quality file | 35/90 | Low | No fit | Rejected: FDA rule was vacated and reverted; current demand trigger collapsed. |
4. Hard disqualifier check
| Disqualifier | Status | Reason |
|---|---|---|
| Customer-facing co-pilot/SaaS | Pass | The offer is a done-for-you evidence production and remediation service; the buyer receives an auditor-ready packet. |
| Physical labor/site crews | Pass | Work is remote document, control, log, policy, incident, supplier, and evidence normalization. |
| Hourly billing dependency | Pass | Primary model is per-entity readiness packet plus per-control remediation bundle and renewal refresh. |
| Cannot reach 50%+ margin | Pass | Plausible after intake normalization and evidence reuse; initial pilots will be lower margin. |
| Unclear buyer | Pass | CISO, compliance lead, risk owner, general counsel, and management body sponsor at Belgian essential/important entities. |
| Non-repeatable workflow | Pass | CyFun/ISO pathway maps naturally to controls, evidence requests, exceptions, reviewer approvals, and submission artifacts. |
| Automates regulated judgment without review | Pass | Cybersecurity lead and accredited/auditor-facing reviewer remain chokepoints; the service does not certify compliance. |
| Duplicative of prior blueprint | Pass | Adjacent to DORA/NYDFS cybersecurity but uses Belgian NIS2/CyFun entity pathways and cross-sector evidence objects. |
| Duplicative of Dynasty Launcher/HVAC | Pass | This is regulated cyber evidence production, not service-business automation or a local-service module ladder. |
| Illegal/licensing impossible | Pass | The company prepares evidence and remediation packets; formal conformity assessment stays with CCB/CAB or ISO bodies. |
| Core demand claim unverified | Pass | Official CCB deadline and NIS2 risk-management/reporting obligations are verified. |
| Model progress commoditizes service | Unclear | Generic AI will draft evidence faster, but governed evidence chains, reviewer trust, and national framework mapping remain defensible. |
| Cannot be piloted | Pass | Pilot can cover one entity, one assurance path, and 30-40 controls before scaling. |
| Customer must operate AI | Pass | Customer supplies evidence and approves findings; internal AI performs extraction and mapping. |
5. Rubric scorecard
| Gate | Score | Explanation |
|---|---|---|
| Low trust burden | 4 | Cybersecurity compliance and audit preparation are already commonly outsourced, but sensitive evidence raises onboarding trust. |
| Low task-level judgment | 4 | Most work is extraction, mapping, completeness checking, and exception routing; true judgment sits at control adequacy and claim boundary. |
| High intelligence threshold | 4 | The work requires synthesis across controls, logs, policies, supplier files, incident plans, and national framework guidance. |
| Regulation as moat | 5 | NIS2, national transposition, CyFun/ISO pathways, and auditor handoffs create defensible process complexity. |
| No physical labor | 5 | Delivery is remote and evidence-based. |
| Sam Altman test | 4 | Better models improve mapping, extraction, and draft remediation, but generic AI may compress undifferentiated policy drafting. |
6. Opportunity
The wedge is not broad cyber consulting. It is turning scattered operational proof into a packet that a management body, CISO, and assessor can inspect without manually rebuilding the evidence chain.
7. Evidence quality and source-claim matrix
| Claim | Label | Source/Basis | Confidence | Business impact |
|---|---|---|---|---|
| NIS2 establishes cybersecurity risk-management and reporting obligations for covered sectors. | Verified | EUR-Lex NIS2 Directive text | High | Creates the compliance substrate for a managed evidence service. |
| Belgian essential entities had an April 18, 2026 milestone to demonstrate implementation and a recognized compliance pathway. | Verified | CCB April 18, 2026 deadline page | High | Creates post-deadline remediation urgency and auditor-facing packet demand. |
| Belgian entities had to register after the NIS2 law entered into force; registration details and timing are described by Safeonweb. | Verified | Safeonweb NIS2 law page | High | Defines intake data and buyer identity checks. |
| CyberFundamentals is Belgium's official step-by-step framework and references NIST CSF, ISO 27001/27002, IEC 62443, and CIS Controls. | Verified | Safeonweb CyberFundamentals Framework | High | Gives the service a deterministic control/evidence mapping backbone. |
| Belgian organizations face sustained 2026 pressure from ransomware, DDoS, account compromise, supply-chain attacks, and AI-enabled cyber operations. | Verified | CCB 2026 cyber threat landscape PDF | Medium | Supports why management bodies will care about current evidence, not static policy binders. |
| Ireland has joined CyFun as a co-owner, suggesting the framework may be reusable beyond Belgium. | Verified | Ireland NCSC CyFun page | Medium | Expands strategic option beyond one country while keeping the launch wedge narrow. |
| Accredited CyFun verification providers exist in Belgium. | Verified | Brand Compliance CyFun accreditation | Medium | Shows vendor/auditor ecosystem precedent and partner path. |
| NIS2 readiness services already sell governance, risk-management, incident response, and audit-ready evidence support. | Verified | Elevate Consult and Hyperproof pages | Medium | Shows outsourcing/vendor precedent but not direct willingness to pay for this exact desk. |
| A focused evidence desk can reach 55-65% mature gross margin. | Inferred | Based on repeatable control mapping, fixed-fee packets, and reviewer exception model | Medium | Key economic hypothesis to test in pilots. |
| Belgian essential entities that missed or underprepared for April 18 will buy remediation packets quickly. | Inferred | Official deadline plus vendor precedent; no direct buyer interviews in this run | Medium | Primary early-demand assumption. |
| The service should avoid claiming certification, legal advice, or guaranteed regulatory acceptance. | Verified | CCB/CAB pathway and general compliance-service boundary | High | Sets the claim boundary and reduces legal risk. |
| Dynasty can model this as a vertical blueprint with guided activation and control-evidence objects. | Inferred | Dynasty reference used only for buildability, not market proof | Medium | Determines internal build path. |
8. Why now
Verified
Belgium's CCB identified April 18, 2026 as a critical milestone for essential entities to demonstrate implementation and a recognized pathway. NIS2 requires risk-management and incident-reporting obligations across covered sectors. CCB's 2026 threat landscape says Belgian organizations remain under sustained pressure from ransomware, DDoS, account compromise, supply-chain attacks, and AI-enabled cyber operations.
Inferred
Post-deadline entities that have partial documentation will need remediation and evidence normalization more than generic policy templates. Ireland's CyFun adoption suggests the Belgian control-evidence architecture may become more reusable.
Unverified
No buyer interviews were conducted in this run, so willingness to pay for a specialized packet desk remains unverified until pilots.
9. Customer & PMF
| Role | Details |
|---|---|
| ICP | Belgian essential or important entity in energy, health, transport, digital infrastructure, water, food, manufacturing, public administration, or managed ICT services. |
| Economic decision-maker | CFO, CISO, general counsel, risk committee, or management body sponsor. |
| User | Security operations lead, GRC manager, compliance analyst, IT director, supplier-risk owner. |
| Urgent trigger | Missed/partial April 18 milestone, upcoming assessor request, incident-reporting drill failure, supplier audit, board review, insurance renewal. |
| Alternatives | Large consultancy, GRC software, internal spreadsheet, ISO consultant, MSP/MSSP evidence export. |
| Jobs-to-be-Done | Prove what is implemented, locate gaps, make evidence reviewable, and reduce assessor back-and-forth. |
10. The outcome we sell
Deliverable: a source-linked NIS2/CyFun or ISO evidence packet for one legal entity, with control map, evidence index, missing-proof register, remediation tasks, incident-reporting drill output, supplier-risk appendix, and management-body signoff memo.
Acceptance criteria: every claimed control status has linked evidence, owner, date, framework reference, reviewer decision, and exception path. Exclusions: formal certification, legal advice, penetration testing, and implementation of technical controls unless separately scoped. Rework policy: one assessor-feedback revision is included when the customer supplies the requested source evidence within ten business days.
11. Internal AI engine architecture
12. AI-vs-human operations pipeline
| Step | Owner | Output |
|---|---|---|
| Entity scoping and pathway selection | Operator + reviewer | Essential/important classification and CyFun or ISO route. |
| Evidence request generation | AI + rules | Control-specific request list. |
| Evidence ingestion and classification | AI-owned | Tagged source library. |
| Control status mapping | AI draft, reviewer approval | Green/amber/red control table. |
| Incident reporting drill | Rules + operator | 24h/72h/one-month simulation artifacts. |
| Exception and remediation register | AI draft, cyber expert approval | Prioritized gap backlog. |
| Board/management memo | AI draft, human lead | Plain-language accountability packet. |
| Assessor handoff | Customer-facing expert | Secure packet and review meeting. |
13. Operations as product
Variance is eliminated through a fixed kickoff questionnaire, framework-version lock, required evidence checklist, evidence freshness rules, confidence scoring, reviewer assignment by control domain, exception queues, source-link audits, and postmortems after every assessor comment. The operation becomes a factory for control evidence, not a bespoke consulting essay.
14. No-holes quality engine
- No hallucinated citations: every control assertion links to a customer source file or official framework source.
- No silent green statuses: green requires source, owner, effective date, reviewer, and test result where applicable.
- No stale evidence: policies, tests, incidents, suppliers, and board approvals get freshness thresholds.
- No certification claims: the service says readiness packet, not certified compliant.
- No hidden remediation: gaps become priced remediation tasks or exclusions.
15. Pricing, pricing legality, and unit economics
Primary pricing: fixed per-entity packet, starting at EUR 12k-25k for a 30-40 control pilot, EUR 35k-85k for full Important/Essential readiness depending on scope, plus EUR 2k-6k monthly refresh. These are inferred price hypotheses from compliance-consulting precedent and must be tested.
Why not hourly: hourly billing rewards slow evidence collection and prevents operating leverage. Pricing legality: avoid contingency based on regulatory outcomes; charge for packet production and remediation deliverables. Unit economics: pilot COGS EUR 7k-12k; mature COGS EUR 14k-25k on a EUR 45k packet; model cost under EUR 200; reviewer time target 6-12 hours per packet; mature gross margin target 55-65%.
16. Nonlinear scaling plan
Start with a 34-control pilot pack, then reuse control evidence schemas, request templates, source parsers, and assessor-feedback libraries. Target 70% automated evidence classification, 50% automated first-pass gap narratives, under 20% escalation rate, and two packets per reviewer per week once intake quality stabilizes.
17. Moat & Sam Altman test
Better models improve extraction from messy policies, SOC tickets, vendor questionnaires, and board minutes, which expands throughput and lowers reviewer time. The moat is not generic drafting; it is the versioned Belgian NIS2/CyFun evidence ontology, assessor-feedback corpus, secure chain-of-custody, partner network, and disciplined claim boundary. The strongest commoditization threat is GRC platforms adding good NIS2 evidence mapping; the counter is faster done-for-you packet delivery and CAB-ready remediation workflows.
18. Buyer-specific go-to-market
Selected GTM: founder-led outbound plus CAB, ISO consultant, MSSP, and cyber-insurance channel partnerships. First 50 prospects: Belgian mid-market essential/important entities with public NIS2 exposure, recent cyber incidents, supplier-risk intensity, or visible ISO/CyFun activity. Trigger events: missed April milestone, assessor scheduling, board cyber review, cyber-insurance renewal, incident tabletop failure. Outreach wedge: "we turn your existing evidence into a CCB/CAB-ready packet in 21 days and show the exact gaps you should not claim."
Conversion path: free 10-control evidence sanity check, paid 34-control pilot, full readiness packet, quarterly refresh. Expected sales cycle: 3-8 weeks. Proof before scaling: two paid pilots, assessor feedback accepted, reviewer time under target, and less than 15% quality rework.
19. Pilot design and early-demand trap mitigation
Run a capped pilot with three entities, one pathway, and 30-40 controls. Success means 95% source-linked claims, a board-ready memo accepted by the sponsor, assessor/cyber reviewer feedback with fewer than five major packet defects, and a repeatable evidence request list. Kill if buyers only want cheap template libraries, refuse secure evidence access, or require broad implementation labor before valuing the packet.
20. Competitive landscape
Incumbents: big-four cyber practices, ISO consultants, Belgian CAB ecosystem, MSSPs, GRC platforms. AI-native competitors: compliance automation vendors adding AI evidence mapping. Services firms: NIS2 readiness advisors, incident-response firms, supplier-risk consultants. Internal teams: CISO/GRC teams using spreadsheets and SharePoint evidence rooms. Do nothing: wait for assessor or regulator requests and respond reactively.
21. Regulation, compliance, and licensing boundary
NIS2 creates the risk-management and reporting basis; Belgium's CCB and CyberFundamentals materials define the local evidence pathway. The desk must not present itself as a CAB, ISO certification body, law firm, or regulator. Counsel-approved disclaimers should say the service prepares evidence and remediation workpapers, while formal assessments, certifications, regulatory decisions, and legal opinions remain with authorized professionals and authorities. Privacy controls include EU hosting, encryption, redaction, least-privilege reviewer access, retention limits, and immutable audit logs.
22. Compact founding team and expert map
| Role | Why needed | FT/fractional | Timing |
|---|---|---|---|
| Domain cyber/NIS2 expert | Maps framework and reviews control claims. | Fractional then FT | Day 1 |
| Operations lead | Runs packet factory and exception queues. | FT | Day 1 |
| AI automation engineer | Builds parsers, classifiers, evidence graph, packet renderer. | FT | Day 1 |
| Compliance/legal reviewer | Approves claim boundaries and engagement language. | Fractional | Before pilots |
| Channel sales lead | Builds CAB/MSSP/ISO consultant partnerships. | Fractional then FT | After first 2 pilots |
| QA owner | Owns source-link and contradiction checks. | Operator at first | Before full launch |
23. Exhaustive risk register
Deadline urgency may already have peaked Medium likelihood / High impact
Evidence label: Verified/Inferred. Mitigation: Target missed-deadline remediation, audit follow-up, and 2027 Essential-level progression rather than only pre-April prep. Owner: Sales lead. Leading indicator: Prospects say April work is complete and budget is gone.
Buyer treats NIS2 as generic consulting Medium likelihood / Medium impact
Evidence label: Inferred. Mitigation: Sell the packet acceptance criteria: evidence map, exception log, management-body proof, incident reporting drill, and CAB handoff. Owner: Founder. Leading indicator: Deals ask for broad security program delivery.
Formal certification boundary is misunderstood Low likelihood / High impact
Evidence label: Verified. Mitigation: Engagement letter says the desk prepares evidence and remediation workpapers; CAB/CCB/ISO bodies perform certification or assessment. Owner: Compliance reviewer. Leading indicator: Prospect asks for guaranteed CyFun label.
Sensitive security evidence creates trust friction Medium likelihood / High impact
Evidence label: Inferred. Mitigation: Use EU-hosted encrypted intake, least-privilege rooms, redaction, audit logs, and optional on-prem evidence index. Owner: Security owner. Leading indicator: InfoSec questionnaire blocks pilot.
Controls require actual implementation, not paperwork High likelihood / High impact
Evidence label: Verified. Mitigation: Separate evidence-ready controls from remediation gaps; price remediation packs by control cluster and partner for technical fixes. Owner: Operations lead. Leading indicator: Exception rate exceeds 40%.
Framework versions or national guidance shift Medium likelihood / Medium impact
Evidence label: Verified. Mitigation: Maintain versioned control library and update every packet with framework version and source date. Owner: Regulatory analyst. Leading indicator: CCB updates FAQ or CyFun control set.
Large consultancies bundle the same output Medium likelihood / Medium impact
Evidence label: Verified. Mitigation: Focus on fast packet production for mid-market entities and partner with consultancies that lack evidence normalization capacity. Owner: GTM lead. Leading indicator: Big-four proposal appears in first 10 deals.
AI extraction mistakes create false readiness Medium likelihood / High impact
Evidence label: Inferred. Mitigation: Require source-linked evidence, deterministic completeness checks, reviewer signoff, and no green status without cited proof. Owner: QA owner. Leading indicator: Reviewer overturn rate above 8%.
Incident-reporting artifacts become stale Medium likelihood / Medium impact
Evidence label: Verified. Mitigation: Include tabletop drill and monthly incident-log refresh; do not treat the packet as a one-time binder. Owner: Service owner. Leading indicator: Drill fails 24h/72h evidence simulation.
Cross-border expansion dilutes Belgian wedge Medium likelihood / Medium impact
Evidence label: Inferred. Mitigation: Do Belgium first, then Ireland CyFun alignment, then country-specific NIS2 packs only after partner validation. Owner: Strategy owner. Leading indicator: Roadmap includes three countries before two paid Belgian pilots.
Margins miss target due to remediation labor Medium likelihood / High impact
Evidence label: Inferred. Mitigation: Cap fixed scope, separate implementation work, track minutes per control, and automate evidence mapping before scaling. Owner: Finance owner. Leading indicator: Reviewer plus engineer time exceeds 8 hours per 34 controls.
Management-body accountability requires senior trust Medium likelihood / High impact
Evidence label: Verified/Inferred. Mitigation: Use named domain expert, counsel-reviewed claim boundaries, and board-ready acceptance memo. Owner: Domain expert. Leading indicator: CFO/board sponsor does not attend kickoff.
24. Tech stack & build plan
Stack: secure document intake, Postgres evidence graph, object storage with per-file hash, queue-based extraction workers, OCR for PDFs, LLM extraction/classification with schema validation, deterministic control rules, reviewer UI, packet renderer, and audit-log stream. Build sequence: framework library, evidence schema, intake checklist, control map renderer, reviewer queue, packet PDF/HTML export, incident-drill module, supplier appendix, and assessor feedback loop.
25. Dynasty translation layer
Classification: Dynasty vertical blueprint. Fit: clear buyer, paid outcome, repeatable inputs, deterministic controls, guided activation path, and strong evidence objects. Modules: entity scoping, pathway selection, secure evidence intake, CyFun/ISO control mapper, incident-reporting drill, supplier-risk appendix, exception queue, reviewer approval, packet renderer, refresh monitor. Tenant objects: entity, site, service, control, evidence item, supplier, incident drill, reviewer decision, exception, remediation task, framework version, board memo.
Activation path: guided; instant activation would be unsafe until evidence access, security review, and reviewer assignment are complete. Warranted claims: packet production, evidence mapping, gap register, and readiness workpaper. Unwarranted claims: certification, guaranteed compliance, legal advice, or regulator acceptance. Deployability guess: spec. Anti-duplication: unlike Dynasty's generic service-business automation/HVAC module ladder, this is a regulated Belgian cybersecurity evidence workflow with CAB-facing artifacts. Recommendation: pilot.
26. Metrics & KPIs
| Metric | Pilot target | Mature target |
|---|---|---|
| Packet cycle time | 21 business days | 10 business days |
| Evidence completeness | 90% on supplied documents | 97% |
| Reviewer overturn rate | <12% | <5% |
| Quality failure rate | <5 major defects per packet | <1 major defect |
| Gross margin | 25-40% | 55-65% |
| COGS per full packet | EUR 20k-35k | EUR 14k-25k |
| Revenue per FTE | EUR 250k run-rate | EUR 500k+ run-rate |
| Escalation rate | <35% controls | <20% controls |
| Automation rate | 40-50% first-pass mapping | 70%+ classification |
| Customer acceptance | 2 of 3 pilots expand | 70%+ convert to refresh |
| Deployability progress | Spec | Validated after 3 pilots |
27. What could kill this
The business fails if Belgian entities believe NIS2 is already solved, if the team cannot safely access sensitive evidence, if buyers demand broad cyber implementation rather than packet production, if assessors reject the packet format, if GRC tools produce equivalent evidence rooms, or if human review time stays too high for fixed pricing.
28. 90-day validation and launch plan
Weeks 1-2: interview CAB/ISO/MSSP partners, lock engagement boundary, build 34-control evidence checklist. Weeks 3-4: recruit three Belgian pilot entities and run free 10-control sanity checks. Weeks 5-7: deliver paid pilot packets, track minutes per control, reviewer overturns, and missing evidence causes. Weeks 8-10: incorporate assessor feedback, package remediation bundles, and publish anonymized sample packet. Weeks 11-13: close first quarterly refresh contracts and decide whether to expand to Ireland CyFun or stay Belgium-only. Kill if no paid pilot signs by week 6 or if packet COGS cannot fall below 55% by the third pilot.
29. Sources
- European Commission AI Act page
- EUR-Lex NIS2 Directive text
- CCB NIS2 April 18, 2026 deadline
- Safeonweb NIS2 law page
- Safeonweb CyberFundamentals Framework
- Safeonweb NIS2 and CyberFundamentals FAQ
- CCB FAQ NIS2 Belgium PDF
- CCB 2026 Belgian cyber threat landscape
- Ireland NCSC CyFun page
- Brand Compliance CyFun accreditation
- Elevate Consult NIS2 readiness service
- Hyperproof NIS2 requirements overview
- DORA register prior blueprint anti-duplication
Machine-checkable validation
- Exactly one hour-01 output produced: this HTML plus matching PDF.
- Manifest updated at root override path.
- All 29 required sections present.
- At least five candidates considered.
- Source-claim matrix present.
- At least 10 risk details included.
- Dynasty reference and addendum found and read.
- No remote scripts, remote fonts, external frameworks, or CSS nesting used.
Judgment validation
The business is a done-for-you outcome service, not a customer-operated co-pilot. It is adjacent to prior DORA and NYDFS cybersecurity blueprints, but it is not duplicative because it uses Belgian NIS2/CyFun control evidence, national assessment pathways, cross-sector entity scope, and CAB/CCB-ready packet delivery. The biggest uncertainty is direct willingness to pay after the April 18 milestone; the first 90 days must test that before scaling.