Set up and maintain your NIS2 file
The Cyber Security Act applies, with no transition period. Thousands of organisations are only now discovering that they fall under it. And their suppliers notice immediately afterwards: anyone subject to the law must assess their supply chain, so security questionnaires and contractual requirements follow. We establish where you stand and record what you have in place.
Three questions, no account, and no need to hand over your email address first.
Where organisations run into difficulty
"Do I actually fall under this?"
There is no letter. You must establish it yourself and register yourself. Sector and size determine it — but the largest group falls just outside and receives the requirements anyway, via customers who do fall under it.
Do the check →"My customer sent a security questionnaire"
Those questions always come down to the same ten topics, because they are based on the same provision. Only the form differs per customer: sometimes an Excel file, sometimes a portal. That is precisely why the second time round is much less work.
What it contains →"We do it, but it is not documented anywhere"
Back-ups, updates, password policy — almost everyone has them. Where things go wrong is proving it: no owner, no date, and no one who can show when the recovery was last tested. The duty of care demands exactly that.
The ten measures →Why you can check us
Every claim we make has its source: the article from the NIS2 Directive, or the national law that implements it. And the date on which we last checked that position — because the implementation differs per country and is still evolving. For a country where the law is not yet in place, we show no deadlines and no portal. There is nothing to report yet, and an invented portal is worse than none.
We do not report and register never on your behalf. That requires your own login credentials with your own supervisor, and that access should not be in a supplier's hands. What we do is prepare the text with the data from your file filled in; you submit it yourself.
The texts in the knowledge base are written with AI based on those sources, put through a technical review and approved by a person before they go online. We tell you that, on every page. See how we work.
What this is not: a certificate, an audit, a pentest or incident response. There is no NIS2 approval mark — no body issues that, not to us and not to anyone else. What you get is a file with which you can show what you have arranged. Demonstrability, not certification.
Latest articles
Security questionnaire in the metal and manufacturing industry: which questions recur?
Suppliers in the metal and manufacturing industry often receive the same questions about their production environment. This article sets
Read more →Awareness and training in the installation sector: what does the duty of care under NIS2 require?
The duty of care requires that employees in an installation business are regularly made aware of cyber risks; for managers
Read more →What belongs in an information security policy for an installation company?
An overview of what an information security policy for the installation industry should contain, precisely because technicians work on-site
Read more →Start with the question of whether it applies to you
Three questions and you know where you stand — and what is then expected of you. Free, and it stays that way.
Do the NIS2 check