Risk Baseline & Gap Assessment
Our experts set the baseline — scope, materiality, and where you actually stand against NIS2. AI assists by mapping your attack surface and flagging drift between reviews; people decide what's material.
Backed by RAS Institute · Vetted through EU procurement
RASDefense is the cybersecurity arm of RAS Institute — vetted through competitive EU procurement to hold three framework contracts with ENISA, the European Union Agency for Cybersecurity. We keep your NIS2 evidence continuously fresh with AI, and put senior experts on every call that carries real liability — turning obligations into audit-ready proof, not assertions.
The cybersecurity arm of RAS InstituteWhy this matters
To hold its three framework contracts with ENISA, the European Union Agency for Cybersecurity, our parent RAS Institute had to clear a competitive, multi-stage EU procurement — a process that tested its methodology, technical rigour, security vetting and data sovereignty against the standards the Union applies to its own cyber agency's suppliers.
Passing that bar is the credential. It isn't an endorsement, and it isn't a claim that ENISA works with us day to day — it is independent, documented proof that our methods withstood EU-grade scrutiny. We took the disciplines behind that vetting and built RASDefense: an agentic-AI platform for NIS2, run under expert oversight.
What we do
We automate the one place where machines genuinely beat an analyst — keeping your compliance evidence continuously fresh — and put senior people on everything that carries real liability. That dividing line is the discipline a regulator wants to see, and a pure-SaaS tool can't credibly claim it.
Our experts set the baseline — scope, materiality, and where you actually stand against NIS2. AI assists by mapping your attack surface and flagging drift between reviews; people decide what's material.
Our automated product. The platform continuously checks your technical controls against the NIS2 control set with deterministic rules — not AI verdicts — and drafts an audit-ready evidence pack. Then an RAS expert reviews the exceptions and counter-signs every cycle. The signature is the product.
When an incident hits, our experts and your team make every call and own every regulatory submission. The software is the timer and checklist — it runs the NIS2 24h / 72h / 30-day clocks and pulls evidence — but a human decides what's reported and signs it.
Penetration testing, operational exercises and the governance controls automation can't attest — delivered by senior specialists, the disciplines for which our team cleared ENISA's procurement vetting. AI supports scheduling and tracking; the rigour is human.
The credential
Won through competitive EU procurement by RAS Institute and its "Consortium Cyber Defence" — a Bulgarian–Romanian expert team — across cybersecurity operations, studies and market monitoring.
Preparedness, penetration testing, operational exercises and an incident-response retainer with stand-by capacity.
Tool-based professional services to design and execute large-scale cybersecurity studies across the EU internal market.
Tool-based professional services to analyse and continuously monitor the EU cybersecurity market — technologies, products and trends.
All three are non-exclusive framework contracts — they make our consortium eligible to provide the services above and to compete for call-offs. Signed in 2026; values shown are framework ceilings, not guaranteed revenue or delivered work. RASDefense states this contractual relationship as fact only and does not imply that ENISA endorses, sponsors or partners with the RASDefense brand.
Why us
NIS2 & equivalent regimes
The NIS2 Directive expands who is in scope and raises the bar on risk management, incident reporting and accountability — with management bodies personally responsible. We apply the same EU-grade rigour to equivalent regimes — including the UK's NIS Regulations 2018 and the incoming Cyber Security and Resilience Bill — making compliance defensible to regulators, customers and your board, wherever you operate.
An expert-led gap assessment sets your NIS2 baseline — the foundation everything else builds on.
AI keeps proof of your technical controls continuously fresh, and an expert counter-signs every cycle.
If an incident hits, your team and our experts make every call; the software runs NIS2's reporting clocks.
Penetration testing, exercises and oversight — senior specialists, the ENISA-vetted disciplines.
About
RAS Institute — the Research, Analysis and Strategy Institute, based in Sofia — is a consultancy with a track record of success in competitive EU procurement. RASDefense is its cybersecurity arm: a way to bring that institutional credibility to organisations facing NIS2 and equivalent regimes — across the EU, the UK and beyond.
Get in touch
Tell us where you are on the journey — we'll show you the fastest credible route to readiness, built on an EU-vetted methodology and agentic AI.
contact@rasdefense.com