NIS2 Compliance

Meet European cybersecurity regulations and avoid penalties

Why Do I Need NIS2 Compliance?

NIS2 is European law that requires certain businesses to meet cybersecurity standards:

  • Avoid Fines: Non-compliance can result in penalties up to €10 million or 2% of annual revenue
  • Legal Protection: Demonstrate due diligence in case of cyber incidents
  • Business Continuity: Better security means fewer disruptions to your operations
  • Customer Trust: Show clients you take data protection seriously
  • Competitive Advantage: Many contracts now require compliance certification

What is NIS2?

The Network and Information Systems Directive (NIS2) is EU legislation that requires organizations in critical sectors to implement cybersecurity measures and report significant incidents.

Simple Explanation

Think of NIS2 like building codes for cybersecurity. Just as buildings must meet safety standards, businesses that provide essential services must meet cybersecurity standards to protect everyone who depends on them.

Who Needs NIS2 Compliance?

Essential Entities

Medium/Large companies in:

  • Energy (electricity, oil, gas)
  • Transportation (airlines, shipping)
  • Banking and financial services
  • Health sector
  • Drinking water supply
  • Digital infrastructure
Important Entities

Medium/Large companies in:

  • Digital services (cloud, online platforms)
  • Waste management
  • Chemical production
  • Food production and distribution
  • Manufacturing
  • Public administration
Size Thresholds

Medium enterprise: 50-249 employees OR €10-50 million annual revenue
Large enterprise: 250+ employees OR €50+ million annual revenue

Key Features

Guided Assessments

Step-by-step questionnaires that check your compliance with all NIS2 requirements.

Compliance Dashboard

Visual overview of your compliance status with clear indicators of what needs attention.

Gap Analysis

Automatic identification of compliance gaps with prioritized action items.

Compliance Reports

Professional reports you can share with auditors, regulators, or leadership.

Assessment Types

Step 1: Relevance Assessment

Time: 5-10 minutes

Determine if your organisation falls under NIS2 scope based on sector, size, and criticality. Start here.

Step 2: Comprehensive Assessment

Time: 2-3 hours

Full evaluation covering all NIS2 Article 21 requirements with gap analysis, remediation items, and Jira ticket creation for each gap.

Getting Started

Quick Start Guide
  1. Check Relevance: Start with the Relevance Assessment to see if NIS2 applies to you
  2. Get Overview: Run the Quick Assessment to understand your current compliance level
  3. Dive Deeper: Use the Comprehensive Assessment for detailed compliance analysis
  4. Address Gaps: Work through identified compliance gaps systematically
  5. Monitor Progress: Regular re-assessments to maintain compliance over time
Important Deadlines

NIS2 became effective in January 2023, with Member States required to transpose it into national law by October 2024. Germany's implementing legislation (NIS2UmsuCG) entered into force in March 2025. Organisations in scope must demonstrate compliance now — enforcement is active.

Integration with Other Modules

NIS2 assessments automatically reference your assets from Asset Management and can generate risk entries in Risk Management for identified compliance gaps. This ensures your compliance efforts are integrated with your broader cybersecurity strategy.