This talk will provide a brief introduction to the NIS Directive, its scope and why it matters. We will also describe CGI's approach to implementing the Cyber Assessment Framework (CAF). The CAF is a systematic method developed by the NCSC that can be used to assess the extent to which an organisation is adequately managing cyber security risks in relation to Operators of Essential Services.