Fifteen deliverables. Not a report that dies in a folder.
1. Discovery
Maturity Baseline — domain-level scoring with evidence coverage per domain, not self-assessment optics. NIS2 Applicability and Country Assessment — entity-by-entity determination (size and sector tests), which obligations attach, on which dates, under your member state's transposition.
2. AI-Run Mapping
NIST CSF 2.0 Profile — target state vs current state by function. ISO/IEC 27001 Readiness Map — Annex A control by control. ISO/IEC 27005 Risk Workflow — threats, vulnerabilities, treatments linked to assets. ISO/IEC 42001 AI Governance Readiness — for the systems you build or deploy. Tooling and Evidence Automation Map — which existing tool evidences which control. Business-Process Integration Map — where governance meets the processes that actually run the business.
3. Human Expert Review
Risk Register — every risk with owner, appetite decision and treatment, agreed in session. Remediation Backlog — prioritized, sequenced against budget and roadmap, each item carrying its regulatory driver.
4. Roadmap & Readout
Board-Ready Accountability Pack — what the board must know, decide and be able to show. Incident Reporting Readiness Pack — who reports what to whom, in which window, under which regime. Policy Modernization Plan — what to rewrite, merge or retire. Automation Roadmap — what to connect next, in what order, with what evidence gain.
5. Adoption Handoff
Platform Adoption Plan — the literal configuration plan that turns everything above into live operation in Community Edition or Resilience Fabric: frameworks as packs, tools as connectors, risks as a live register.
Every deliverable lands inside the platform as structured, versioned data — traceable to its source clause or evidence pull, reusable by the next cycle. Nothing exists only as a slide.