If you get stuck with NIS 2

The platform is free and stays free. So does the course. Most companies get through on their own. If you do not, there are two routes, and both start with the same email.

Send a request

One click and your email address. No account needed.

What is it about?

Free for you. We receive a referral fee from the firm. No commitment, you decide after the first conversation.

Level 1

1. You do it yourself. 0 EUR.

A scope check, every measure required by Article 21 as a single step you can work through, evidence upload, PDF export, an audit trail, and the management course with a certificate of attendance that Article 20 asks you to be able to show.

If you would rather run the platform yourself, the source is on GitHub under AGPL-3.0. Also free. No licence fee, no user limit.

No time limit, no credit card, nobody from sales calling you.

NIS 2 is transposed by each member state, so the wording you are audited against is your national law, not the directive. The platform maps to the directive first and shows the national reference where one exists, for example §30 BSIG in Germany.

Level 2

2. You want to run it yourself. We set it up.

Short technical questions get answered by email, usually within two working days, at no charge. Questions about self-hosting included.

500 EUR net, one-timeper installation, nothing recurring

Self-hosting is free and stays free: the source is under AGPL-3.0 and there is no licence fee. The 500 EUR is our work getting the platform running on your infrastructure: database and migrations, object storage for evidence, transactional email, sign-in, the first deployment, and a handover your own team can keep updating from.

One payment, not a subscription. After the handover the instance is yours, with no account with us and nothing to renew. If you would rather set it up yourself from the documentation, that route stays open and costs nothing.

Level 3

3. It needs a specialist firm. We refer you.

Some of it is not our work, and we would rather say so before you pay us than after. Penetration testing and technical audits, ISO 27001 certification, a standing external security officer, legal advice, incident response, OT and control systems, hands-on implementation on your infrastructure.

For that we keep a list of firms we work with. How it goes:

  1. Send us one line about where you are stuck. Or click “Find a specialist” inside the platform.
  2. We name one to three firms and write down why those ones. Field, region, free capacity.
  3. You decide whether to approach any of them. Nothing about you is passed on until you explicitly say so.
  4. The contract is between you and the firm. We are not in the middle of it and we invoice nothing.

The referral costs you nothing. No markup, no finder's fee, no obligation.

How we earn

Level 2 is the one-time setup fee. On level 3 the firm pays us 15 percent of its net fee if the referral turns into an engagement.

Our partners commit in writing not to raise their fee because of it. We do not recommend by commission, and the order of our list does not depend on it.

If you would rather use your own consultant, that is completely fine, and you keep the platform either way.

Read the referral terms

What we do not do
  • No legal advice. For that you need a law firm.
  • No promise that an authority will accept your implementation. Nobody can honestly give you that.
  • No recommendation we would not also make without a commission.
Prefer email?

contact@nisd2.eu. One line is enough: where you are stuck, how many employees, which sector, which country.

Write to us