All solutions Solution · NIS2

Implement NIS2 and keep the evidence

From risk analysis through the reporting chain to the supply chain: isidaten maps the due-diligence duties of Article 21 in one place, so the evidence emerges as a by-product of daily work instead of a yearly scramble.

Request a demo
Background

What NIS2 requires

The NIS2 directive extends cybersecurity duties to far more entities, from energy and health through public administration to manufacturers and digital services. At its core, Article 21 requires ten areas of measures, plus short reporting deadlines and personal accountability of management. The real hurdle is rarely the single requirement but the evidence: being able to prove that a measure is not just documented but actually works.

Risk analysis and security policiesIncident handling and reporting channelsBusiness continuity, backup and crisis managementSupply chain securityVulnerability handling and secure developmentAssessing the effectiveness of measuresCyber hygiene and trainingCryptography, access control and asset management
FAQ

Frequently asked questions

Who does NIS2 apply to?

NIS2 covers essential and important entities across 18 sectors, generally from medium size upward. What counts is the national transposition, in Germany the NIS2 implementation act. Whether you are in scope depends on sector, size and role.

Does isidaten make me automatically NIS2-compliant?

No. Software alone does not create compliance. isidaten maps the requirements of Article 21 in a structured way and produces the evidence. Implementation and accountability remain with the entity and its management.

What distinguishes evidence from documentation?

Having a policy does not mean the measure works. NIS2 requires demonstrable effectiveness. isidaten links measure, risk and evidence in one place, so the proof is a state and not a folder assembled after the fact.

Does isidaten also cover the supply chain?

Yes. Suppliers, contracts and processors are the same object across questionnaire, contract and risk register, so third-party risk does not stop at your own firewall.

Ready to simplify your compliance?

Schedule a no-obligation demo and experience isidaten with your own use cases – personally and without commitment.