Implement NIS2 and keep the evidence
From risk analysis through the reporting chain to the supply chain: isidaten maps the due-diligence duties of Article 21 in one place, so the evidence emerges as a by-product of daily work instead of a yearly scramble.
What NIS2 requires
The NIS2 directive extends cybersecurity duties to far more entities, from energy and health through public administration to manufacturers and digital services. At its core, Article 21 requires ten areas of measures, plus short reporting deadlines and personal accountability of management. The real hurdle is rarely the single requirement but the evidence: being able to prove that a measure is not just documented but actually works.
How isidaten maps NIS2
Each requirement meets a module that runs on the same object base as the risk register, so the evidence stays connected instead of copied across tools.
Assess and treat risks
Capture, assess and treat risks and document the decision, instead of losing them in scattered spreadsheets.
View module: Risk RegisterIncidents and reporting deadlines
The reporting chain under § 32 BSIG as a guided flow: early warning in 24 hours, notification in 72, interim and final report, with deadline alerts and a PDF reporting file.
View module: NIS2 ReportingSecure the supply chain
Service providers, contracts and processors in one place, connected to the risk register instead of isolated questionnaires.
View module: Supplier ManagementAttack surface and vulnerabilities
Bring exposed assets, known vulnerabilities and decisions together instead of spread across several tools.
View module: Attack Surface ManagementEmergency and recovery
Emergency plans, recovery and exercises, so availability is not a promise but something you can prove.
View module: Emergency Management (BCM)Effectiveness and evidence
Measure the effectiveness of measures and keep the evidence for audit and authority as a continuous state.
View module: Effectiveness AssessmentFrequently asked questions
Who does NIS2 apply to?
NIS2 covers essential and important entities across 18 sectors, generally from medium size upward. What counts is the national transposition, in Germany the NIS2 implementation act. Whether you are in scope depends on sector, size and role.
Does isidaten make me automatically NIS2-compliant?
No. Software alone does not create compliance. isidaten maps the requirements of Article 21 in a structured way and produces the evidence. Implementation and accountability remain with the entity and its management.
What distinguishes evidence from documentation?
Having a policy does not mean the measure works. NIS2 requires demonstrable effectiveness. isidaten links measure, risk and evidence in one place, so the proof is a state and not a folder assembled after the fact.
Does isidaten also cover the supply chain?
Yes. Suppliers, contracts and processors are the same object across questionnaire, contract and risk register, so third-party risk does not stop at your own firewall.
Ready to simplify your compliance?
Schedule a no-obligation demo and experience isidaten with your own use cases – personally and without commitment.