Skip to content
NIS2 · EU essential + important entities

Have your NIS2 evidence ready when your competent authority asks.

NIS2 is transposed across EU Member States. Penalties reach €10 million or 2% of worldwide turnover, and the management body itself can be held personally liable. Have the file ready before they call.

What you get

Three outcomes for a NIS2 assessment.

The NIS2 evidence pack

One PDF and CSV covering every cybersecurity risk-management measure your supervisor expects.

The incident clock

The 24-hour early warning, 72-hour notification and 1-month final-report windows surfaced before they slip.

Board-ready evidence

Management-body sign-off on cyber measures, captured with timestamp and reviewer — the personal-liability defence.

How it works

Connect. Assess. Ship.

1. Connect

Read-only OAuth into your cloud and SaaS.

2. Assess

Each cybersecurity measure mapped to your evidence. Two reviewers sign off.

3. Ship

One-click NIS2 evidence pack with the audit trail attached.

Who it’s for

EU essential and important entities under NIS2.

Banks. Energy. Transport. Water. Digital infrastructure. Public administration. Manufacturing of critical products. Digital providers. The full Annex I and II list.

Deep detail

Articles 20, 21, 23 — in our docs.

The full NIS2 walkthrough — governance, the ten risk-management measures and the incident-notification clock — lives on docs.secruna.com.

Want to see your NIS2 gap?
Talk to us for 30 minutes.

A 30-minute call tells you where your NIS2 evidence pack is empty today.