1. Thesis

The Belgium NIS2 Conformity Evidence Desk sells Belgian essential and important entities a done-for-you, auditor-facing evidence packet that maps current controls, policies, incident-response records, supplier files, management-body oversight, and remediation exceptions to the Belgian NIS2/CyberFundamentals or ISO pathway. The buyer is not asked to operate an AI compliance tool; a human cybersecurity/compliance lead receives, reviews, and submits a source-linked workpaper set prepared by an internal AI evidence engine and approved at explicit expert chokepoints.

Outcome sold: CAB/CCB-ready NIS2 evidence binder, exception register, remediation backlog, incident-reporting drill artifacts, and board-ready signoff memo for one entity and one selected compliance pathway.

2. Discovery rationale

The run scanned cybersecurity regulation, AI governance, securities filing access, climate disclosure, consumer subscription rules, and medical-device laboratory deadlines. NIS2 Belgium won because it combined official, current regulatory timing with concrete evidence pathways, cross-sector buyer urgency, and a workflow that is heavily document-based but still requires human cyber judgment. Click-to-cancel and LDT were rejected because current court or FDA actions weakened the regulatory trigger; SB 261 was weakened by enforcement uncertainty; EDGAR Next was credible but narrower and less repeatable.

3. Candidate comparison

CandidateBuyerOutcomeScoreEvidenceDynasty typeDecision
Belgium NIS2 Conformity Evidence DeskBelgian essential and important entitiesCAB/CCB-ready CyFun or ISO evidence pack86/90HighDynasty vertical blueprintSelected: official April 18, 2026 milestone, concrete evidence pathways, broad cyber evidence pain, and bounded pilot.
EU AI Act High-Risk Deployer File DeskEnterprises deploying high-risk AI in employment, credit, education, public servicesArticle 26/27 deployer file and FRIA workpaper78/90MediumDynasty vertical blueprintRejected this hour: strong 2026 signal, but current omnibus timing uncertainty weakens urgency.
EDGAR Next Lockout Recovery DeskSEC filers, funds, issuers, filing agentsRecovered EDGAR access and account governance packet70/90HighDynasty module bundleRejected: verified access pain, but narrower one-time remediation window and lower recurring service surface.
California SB 261 Climate Risk Report DeskLarge companies doing business in CaliforniaPublic climate-related financial risk report and docket packet61/90MediumStandalone businessRejected: statutory need exists, but enforcement was reportedly paused by litigation; overlaps prior climate disclosure work.
FTC Click-to-Cancel Remediation DeskSubscription businessesNegative-option consent/cancellation compliance packet40/90LowNo fitRejected: federal rule was vacated, so the core regulatory trigger failed.
FDA LDT Phaseout Readiness DeskClinical laboratoriesLDT registration/listing and quality file35/90LowNo fitRejected: FDA rule was vacated and reverted; current demand trigger collapsed.

4. Hard disqualifier check

DisqualifierStatusReason
Customer-facing co-pilot/SaaSPassThe offer is a done-for-you evidence production and remediation service; the buyer receives an auditor-ready packet.
Physical labor/site crewsPassWork is remote document, control, log, policy, incident, supplier, and evidence normalization.
Hourly billing dependencyPassPrimary model is per-entity readiness packet plus per-control remediation bundle and renewal refresh.
Cannot reach 50%+ marginPassPlausible after intake normalization and evidence reuse; initial pilots will be lower margin.
Unclear buyerPassCISO, compliance lead, risk owner, general counsel, and management body sponsor at Belgian essential/important entities.
Non-repeatable workflowPassCyFun/ISO pathway maps naturally to controls, evidence requests, exceptions, reviewer approvals, and submission artifacts.
Automates regulated judgment without reviewPassCybersecurity lead and accredited/auditor-facing reviewer remain chokepoints; the service does not certify compliance.
Duplicative of prior blueprintPassAdjacent to DORA/NYDFS cybersecurity but uses Belgian NIS2/CyFun entity pathways and cross-sector evidence objects.
Duplicative of Dynasty Launcher/HVACPassThis is regulated cyber evidence production, not service-business automation or a local-service module ladder.
Illegal/licensing impossiblePassThe company prepares evidence and remediation packets; formal conformity assessment stays with CCB/CAB or ISO bodies.
Core demand claim unverifiedPassOfficial CCB deadline and NIS2 risk-management/reporting obligations are verified.
Model progress commoditizes serviceUnclearGeneric AI will draft evidence faster, but governed evidence chains, reviewer trust, and national framework mapping remain defensible.
Cannot be pilotedPassPilot can cover one entity, one assurance path, and 30-40 controls before scaling.
Customer must operate AIPassCustomer supplies evidence and approves findings; internal AI performs extraction and mapping.

5. Rubric scorecard

GateScoreExplanation
Low trust burden4Cybersecurity compliance and audit preparation are already commonly outsourced, but sensitive evidence raises onboarding trust.
Low task-level judgment4Most work is extraction, mapping, completeness checking, and exception routing; true judgment sits at control adequacy and claim boundary.
High intelligence threshold4The work requires synthesis across controls, logs, policies, supplier files, incident plans, and national framework guidance.
Regulation as moat5NIS2, national transposition, CyFun/ISO pathways, and auditor handoffs create defensible process complexity.
No physical labor5Delivery is remote and evidence-based.
Sam Altman test4Better models improve mapping, extraction, and draft remediation, but generic AI may compress undifferentiated policy drafting.

6. Opportunity

Apr 18 2026Verified Belgian essential-entity milestone from CCB.
24h / 72h / 1 moVerified NIS2 incident-reporting cadence.
CyFun + ISOVerified recognized compliance pathways in Belgium.
55-65%Inferred mature gross-margin target after control reuse.

The wedge is not broad cyber consulting. It is turning scattered operational proof into a packet that a management body, CISO, and assessor can inspect without manually rebuilding the evidence chain.

7. Evidence quality and source-claim matrix

ClaimLabelSource/BasisConfidenceBusiness impact
NIS2 establishes cybersecurity risk-management and reporting obligations for covered sectors.VerifiedEUR-Lex NIS2 Directive textHighCreates the compliance substrate for a managed evidence service.
Belgian essential entities had an April 18, 2026 milestone to demonstrate implementation and a recognized compliance pathway.VerifiedCCB April 18, 2026 deadline pageHighCreates post-deadline remediation urgency and auditor-facing packet demand.
Belgian entities had to register after the NIS2 law entered into force; registration details and timing are described by Safeonweb.VerifiedSafeonweb NIS2 law pageHighDefines intake data and buyer identity checks.
CyberFundamentals is Belgium's official step-by-step framework and references NIST CSF, ISO 27001/27002, IEC 62443, and CIS Controls.VerifiedSafeonweb CyberFundamentals FrameworkHighGives the service a deterministic control/evidence mapping backbone.
Belgian organizations face sustained 2026 pressure from ransomware, DDoS, account compromise, supply-chain attacks, and AI-enabled cyber operations.VerifiedCCB 2026 cyber threat landscape PDFMediumSupports why management bodies will care about current evidence, not static policy binders.
Ireland has joined CyFun as a co-owner, suggesting the framework may be reusable beyond Belgium.VerifiedIreland NCSC CyFun pageMediumExpands strategic option beyond one country while keeping the launch wedge narrow.
Accredited CyFun verification providers exist in Belgium.VerifiedBrand Compliance CyFun accreditationMediumShows vendor/auditor ecosystem precedent and partner path.
NIS2 readiness services already sell governance, risk-management, incident response, and audit-ready evidence support.VerifiedElevate Consult and Hyperproof pagesMediumShows outsourcing/vendor precedent but not direct willingness to pay for this exact desk.
A focused evidence desk can reach 55-65% mature gross margin.InferredBased on repeatable control mapping, fixed-fee packets, and reviewer exception modelMediumKey economic hypothesis to test in pilots.
Belgian essential entities that missed or underprepared for April 18 will buy remediation packets quickly.InferredOfficial deadline plus vendor precedent; no direct buyer interviews in this runMediumPrimary early-demand assumption.
The service should avoid claiming certification, legal advice, or guaranteed regulatory acceptance.VerifiedCCB/CAB pathway and general compliance-service boundaryHighSets the claim boundary and reduces legal risk.
Dynasty can model this as a vertical blueprint with guided activation and control-evidence objects.InferredDynasty reference used only for buildability, not market proofMediumDetermines internal build path.

8. Why now

Verified

Belgium's CCB identified April 18, 2026 as a critical milestone for essential entities to demonstrate implementation and a recognized pathway. NIS2 requires risk-management and incident-reporting obligations across covered sectors. CCB's 2026 threat landscape says Belgian organizations remain under sustained pressure from ransomware, DDoS, account compromise, supply-chain attacks, and AI-enabled cyber operations.

Inferred

Post-deadline entities that have partial documentation will need remediation and evidence normalization more than generic policy templates. Ireland's CyFun adoption suggests the Belgian control-evidence architecture may become more reusable.

Unverified

No buyer interviews were conducted in this run, so willingness to pay for a specialized packet desk remains unverified until pilots.

9. Customer & PMF

RoleDetails
ICPBelgian essential or important entity in energy, health, transport, digital infrastructure, water, food, manufacturing, public administration, or managed ICT services.
Economic decision-makerCFO, CISO, general counsel, risk committee, or management body sponsor.
UserSecurity operations lead, GRC manager, compliance analyst, IT director, supplier-risk owner.
Urgent triggerMissed/partial April 18 milestone, upcoming assessor request, incident-reporting drill failure, supplier audit, board review, insurance renewal.
AlternativesLarge consultancy, GRC software, internal spreadsheet, ISO consultant, MSP/MSSP evidence export.
Jobs-to-be-DoneProve what is implemented, locate gaps, make evidence reviewable, and reduce assessor back-and-forth.

10. The outcome we sell

Deliverable: a source-linked NIS2/CyFun or ISO evidence packet for one legal entity, with control map, evidence index, missing-proof register, remediation tasks, incident-reporting drill output, supplier-risk appendix, and management-body signoff memo.

Acceptance criteria: every claimed control status has linked evidence, owner, date, framework reference, reviewer decision, and exception path. Exclusions: formal certification, legal advice, penetration testing, and implementation of technical controls unless separately scoped. Rework policy: one assessor-feedback revision is included when the customer supplies the requested source evidence within ten business days.

11. Internal AI engine architecture

IntakePolicies, asset lists, SOC logs, tickets, supplier files, board minutes, incident plans, ISO artifacts, CyFun exports.
NormalizationDeduplicate, classify, version, redact, and attach entity/control metadata.
KnowledgeNIS2 articles, Belgian FAQ, CyFun controls, ISO 27001 SoA patterns, incident-reporting timers, assessor notes.
WorkbenchExtract evidence, map controls, draft exceptions, compare artifacts, summarize gaps, generate packet sections.
RulesNo control can be green without dated source proof, owner, reviewer approval, and framework version.
Human chokepointCyber lead validates control status and remediation feasibility.
Licensed/assessor boundaryCAB/CCB/ISO bodies assess; counsel reviews claim language where needed.
QASource-link checks, contradiction scan, stale-evidence flags, incident-timer simulation.
DeliverySecure packet room, PDF binder, spreadsheet control map, board memo, assessor handoff checklist.
Learning loopAssessor feedback and remediation outcomes update templates and exception classifiers.

12. AI-vs-human operations pipeline

StepOwnerOutput
Entity scoping and pathway selectionOperator + reviewerEssential/important classification and CyFun or ISO route.
Evidence request generationAI + rulesControl-specific request list.
Evidence ingestion and classificationAI-ownedTagged source library.
Control status mappingAI draft, reviewer approvalGreen/amber/red control table.
Incident reporting drillRules + operator24h/72h/one-month simulation artifacts.
Exception and remediation registerAI draft, cyber expert approvalPrioritized gap backlog.
Board/management memoAI draft, human leadPlain-language accountability packet.
Assessor handoffCustomer-facing expertSecure packet and review meeting.

13. Operations as product

Variance is eliminated through a fixed kickoff questionnaire, framework-version lock, required evidence checklist, evidence freshness rules, confidence scoring, reviewer assignment by control domain, exception queues, source-link audits, and postmortems after every assessor comment. The operation becomes a factory for control evidence, not a bespoke consulting essay.

14. No-holes quality engine

  • No hallucinated citations: every control assertion links to a customer source file or official framework source.
  • No silent green statuses: green requires source, owner, effective date, reviewer, and test result where applicable.
  • No stale evidence: policies, tests, incidents, suppliers, and board approvals get freshness thresholds.
  • No certification claims: the service says readiness packet, not certified compliant.
  • No hidden remediation: gaps become priced remediation tasks or exclusions.

15. Pricing, pricing legality, and unit economics

Primary pricing: fixed per-entity packet, starting at EUR 12k-25k for a 30-40 control pilot, EUR 35k-85k for full Important/Essential readiness depending on scope, plus EUR 2k-6k monthly refresh. These are inferred price hypotheses from compliance-consulting precedent and must be tested.

Why not hourly: hourly billing rewards slow evidence collection and prevents operating leverage. Pricing legality: avoid contingency based on regulatory outcomes; charge for packet production and remediation deliverables. Unit economics: pilot COGS EUR 7k-12k; mature COGS EUR 14k-25k on a EUR 45k packet; model cost under EUR 200; reviewer time target 6-12 hours per packet; mature gross margin target 55-65%.

16. Nonlinear scaling plan

Start with a 34-control pilot pack, then reuse control evidence schemas, request templates, source parsers, and assessor-feedback libraries. Target 70% automated evidence classification, 50% automated first-pass gap narratives, under 20% escalation rate, and two packets per reviewer per week once intake quality stabilizes.

17. Moat & Sam Altman test

Better models improve extraction from messy policies, SOC tickets, vendor questionnaires, and board minutes, which expands throughput and lowers reviewer time. The moat is not generic drafting; it is the versioned Belgian NIS2/CyFun evidence ontology, assessor-feedback corpus, secure chain-of-custody, partner network, and disciplined claim boundary. The strongest commoditization threat is GRC platforms adding good NIS2 evidence mapping; the counter is faster done-for-you packet delivery and CAB-ready remediation workflows.

18. Buyer-specific go-to-market

Selected GTM: founder-led outbound plus CAB, ISO consultant, MSSP, and cyber-insurance channel partnerships. First 50 prospects: Belgian mid-market essential/important entities with public NIS2 exposure, recent cyber incidents, supplier-risk intensity, or visible ISO/CyFun activity. Trigger events: missed April milestone, assessor scheduling, board cyber review, cyber-insurance renewal, incident tabletop failure. Outreach wedge: "we turn your existing evidence into a CCB/CAB-ready packet in 21 days and show the exact gaps you should not claim."

Conversion path: free 10-control evidence sanity check, paid 34-control pilot, full readiness packet, quarterly refresh. Expected sales cycle: 3-8 weeks. Proof before scaling: two paid pilots, assessor feedback accepted, reviewer time under target, and less than 15% quality rework.

19. Pilot design and early-demand trap mitigation

Run a capped pilot with three entities, one pathway, and 30-40 controls. Success means 95% source-linked claims, a board-ready memo accepted by the sponsor, assessor/cyber reviewer feedback with fewer than five major packet defects, and a repeatable evidence request list. Kill if buyers only want cheap template libraries, refuse secure evidence access, or require broad implementation labor before valuing the packet.

20. Competitive landscape

Incumbents: big-four cyber practices, ISO consultants, Belgian CAB ecosystem, MSSPs, GRC platforms. AI-native competitors: compliance automation vendors adding AI evidence mapping. Services firms: NIS2 readiness advisors, incident-response firms, supplier-risk consultants. Internal teams: CISO/GRC teams using spreadsheets and SharePoint evidence rooms. Do nothing: wait for assessor or regulator requests and respond reactively.

21. Regulation, compliance, and licensing boundary

NIS2 creates the risk-management and reporting basis; Belgium's CCB and CyberFundamentals materials define the local evidence pathway. The desk must not present itself as a CAB, ISO certification body, law firm, or regulator. Counsel-approved disclaimers should say the service prepares evidence and remediation workpapers, while formal assessments, certifications, regulatory decisions, and legal opinions remain with authorized professionals and authorities. Privacy controls include EU hosting, encryption, redaction, least-privilege reviewer access, retention limits, and immutable audit logs.

22. Compact founding team and expert map

RoleWhy neededFT/fractionalTiming
Domain cyber/NIS2 expertMaps framework and reviews control claims.Fractional then FTDay 1
Operations leadRuns packet factory and exception queues.FTDay 1
AI automation engineerBuilds parsers, classifiers, evidence graph, packet renderer.FTDay 1
Compliance/legal reviewerApproves claim boundaries and engagement language.FractionalBefore pilots
Channel sales leadBuilds CAB/MSSP/ISO consultant partnerships.Fractional then FTAfter first 2 pilots
QA ownerOwns source-link and contradiction checks.Operator at firstBefore full launch

23. Exhaustive risk register

Deadline urgency may already have peaked Medium likelihood / High impact

Evidence label: Verified/Inferred. Mitigation: Target missed-deadline remediation, audit follow-up, and 2027 Essential-level progression rather than only pre-April prep. Owner: Sales lead. Leading indicator: Prospects say April work is complete and budget is gone.

Buyer treats NIS2 as generic consulting Medium likelihood / Medium impact

Evidence label: Inferred. Mitigation: Sell the packet acceptance criteria: evidence map, exception log, management-body proof, incident reporting drill, and CAB handoff. Owner: Founder. Leading indicator: Deals ask for broad security program delivery.

Formal certification boundary is misunderstood Low likelihood / High impact

Evidence label: Verified. Mitigation: Engagement letter says the desk prepares evidence and remediation workpapers; CAB/CCB/ISO bodies perform certification or assessment. Owner: Compliance reviewer. Leading indicator: Prospect asks for guaranteed CyFun label.

Sensitive security evidence creates trust friction Medium likelihood / High impact

Evidence label: Inferred. Mitigation: Use EU-hosted encrypted intake, least-privilege rooms, redaction, audit logs, and optional on-prem evidence index. Owner: Security owner. Leading indicator: InfoSec questionnaire blocks pilot.

Controls require actual implementation, not paperwork High likelihood / High impact

Evidence label: Verified. Mitigation: Separate evidence-ready controls from remediation gaps; price remediation packs by control cluster and partner for technical fixes. Owner: Operations lead. Leading indicator: Exception rate exceeds 40%.

Framework versions or national guidance shift Medium likelihood / Medium impact

Evidence label: Verified. Mitigation: Maintain versioned control library and update every packet with framework version and source date. Owner: Regulatory analyst. Leading indicator: CCB updates FAQ or CyFun control set.

Large consultancies bundle the same output Medium likelihood / Medium impact

Evidence label: Verified. Mitigation: Focus on fast packet production for mid-market entities and partner with consultancies that lack evidence normalization capacity. Owner: GTM lead. Leading indicator: Big-four proposal appears in first 10 deals.

AI extraction mistakes create false readiness Medium likelihood / High impact

Evidence label: Inferred. Mitigation: Require source-linked evidence, deterministic completeness checks, reviewer signoff, and no green status without cited proof. Owner: QA owner. Leading indicator: Reviewer overturn rate above 8%.

Incident-reporting artifacts become stale Medium likelihood / Medium impact

Evidence label: Verified. Mitigation: Include tabletop drill and monthly incident-log refresh; do not treat the packet as a one-time binder. Owner: Service owner. Leading indicator: Drill fails 24h/72h evidence simulation.

Cross-border expansion dilutes Belgian wedge Medium likelihood / Medium impact

Evidence label: Inferred. Mitigation: Do Belgium first, then Ireland CyFun alignment, then country-specific NIS2 packs only after partner validation. Owner: Strategy owner. Leading indicator: Roadmap includes three countries before two paid Belgian pilots.

Margins miss target due to remediation labor Medium likelihood / High impact

Evidence label: Inferred. Mitigation: Cap fixed scope, separate implementation work, track minutes per control, and automate evidence mapping before scaling. Owner: Finance owner. Leading indicator: Reviewer plus engineer time exceeds 8 hours per 34 controls.

Management-body accountability requires senior trust Medium likelihood / High impact

Evidence label: Verified/Inferred. Mitigation: Use named domain expert, counsel-reviewed claim boundaries, and board-ready acceptance memo. Owner: Domain expert. Leading indicator: CFO/board sponsor does not attend kickoff.

24. Tech stack & build plan

Stack: secure document intake, Postgres evidence graph, object storage with per-file hash, queue-based extraction workers, OCR for PDFs, LLM extraction/classification with schema validation, deterministic control rules, reviewer UI, packet renderer, and audit-log stream. Build sequence: framework library, evidence schema, intake checklist, control map renderer, reviewer queue, packet PDF/HTML export, incident-drill module, supplier appendix, and assessor feedback loop.

25. Dynasty translation layer

Classification: Dynasty vertical blueprint. Fit: clear buyer, paid outcome, repeatable inputs, deterministic controls, guided activation path, and strong evidence objects. Modules: entity scoping, pathway selection, secure evidence intake, CyFun/ISO control mapper, incident-reporting drill, supplier-risk appendix, exception queue, reviewer approval, packet renderer, refresh monitor. Tenant objects: entity, site, service, control, evidence item, supplier, incident drill, reviewer decision, exception, remediation task, framework version, board memo.

Activation path: guided; instant activation would be unsafe until evidence access, security review, and reviewer assignment are complete. Warranted claims: packet production, evidence mapping, gap register, and readiness workpaper. Unwarranted claims: certification, guaranteed compliance, legal advice, or regulator acceptance. Deployability guess: spec. Anti-duplication: unlike Dynasty's generic service-business automation/HVAC module ladder, this is a regulated Belgian cybersecurity evidence workflow with CAB-facing artifacts. Recommendation: pilot.

26. Metrics & KPIs

MetricPilot targetMature target
Packet cycle time21 business days10 business days
Evidence completeness90% on supplied documents97%
Reviewer overturn rate<12%<5%
Quality failure rate<5 major defects per packet<1 major defect
Gross margin25-40%55-65%
COGS per full packetEUR 20k-35kEUR 14k-25k
Revenue per FTEEUR 250k run-rateEUR 500k+ run-rate
Escalation rate<35% controls<20% controls
Automation rate40-50% first-pass mapping70%+ classification
Customer acceptance2 of 3 pilots expand70%+ convert to refresh
Deployability progressSpecValidated after 3 pilots

27. What could kill this

The business fails if Belgian entities believe NIS2 is already solved, if the team cannot safely access sensitive evidence, if buyers demand broad cyber implementation rather than packet production, if assessors reject the packet format, if GRC tools produce equivalent evidence rooms, or if human review time stays too high for fixed pricing.

28. 90-day validation and launch plan

Weeks 1-2: interview CAB/ISO/MSSP partners, lock engagement boundary, build 34-control evidence checklist. Weeks 3-4: recruit three Belgian pilot entities and run free 10-control sanity checks. Weeks 5-7: deliver paid pilot packets, track minutes per control, reviewer overturns, and missing evidence causes. Weeks 8-10: incorporate assessor feedback, package remediation bundles, and publish anonymized sample packet. Weeks 11-13: close first quarterly refresh contracts and decide whether to expand to Ireland CyFun or stay Belgium-only. Kill if no paid pilot signs by week 6 or if packet COGS cannot fall below 55% by the third pilot.

29. Sources

Machine-checkable validation

  • Exactly one hour-01 output produced: this HTML plus matching PDF.
  • Manifest updated at root override path.
  • All 29 required sections present.
  • At least five candidates considered.
  • Source-claim matrix present.
  • At least 10 risk details included.
  • Dynasty reference and addendum found and read.
  • No remote scripts, remote fonts, external frameworks, or CSS nesting used.

Judgment validation

The business is a done-for-you outcome service, not a customer-operated co-pilot. It is adjacent to prior DORA and NYDFS cybersecurity blueprints, but it is not duplicative because it uses Belgian NIS2/CyFun control evidence, national assessment pathways, cross-sector entity scope, and CAB/CCB-ready packet delivery. The biggest uncertainty is direct willingness to pay after the April 18 milestone; the first 90 days must test that before scaling.

Top