NIS2 Directive Β· Cybersecurity Act 2026

NIS2 β€” be ready before the supervisors arrive.

NIS2 enters into force in 2026. We automate 76% of technical Art.21 requirements and collect the rest via attestations. Total cost: SEK 15,000 instead of SEK 80,000.

Register interest β†’

NIS2 Article 21 β€” ten requirement categories

Art.21.2 lists ten minimum requirements that essential and important entities must implement. Here is how we cover them:

Art.21.2 Requirement Security Guru
a) Risk analysis + security policy βš™ Attestation
b) Incident handling βœ“ Auditd rules, log forwarding, SIEM detection
c) Backup + disaster recovery βœ“ Backup validation (not just existence β€” functionality)
d) Supply chain βœ“ CVE in deps, GitHub Advisory, OSV mapping
e) Network security + procurement βœ“ Segmentation, OT protocols, port exposure
f) Vulnerability management βœ“ CVE matching, KEV, EPSS prioritisation
g) Effectiveness measurement βš™ Attestation (KPI process)
h) Cryptography + authentication βœ“ TLS config, DKIM/SPF, MFA gates, PKI
i) HR security + access rights βœ“ AD RBAC, stale users, privileged accounts
j) MFA + secure communications βœ“ MFA detection per service, S/MIME, end-to-end

Art.20 β€” board responsibility

NIS2 introduces personal liability for management members. The board must:

Our Compliance module collects attestations for Art.20 and can produce a board pack for the next board meeting with the same traceability the auditor will require.

Art.23 β€” incident reporting

In the event of an incident with significant impact you must:

We cannot report on your behalf, but our scan report provides rapid root cause mapping that otherwise takes consultant hours.

Become a beta tester

Fill in the form β€” we'll get back to you within 24 hours.

By submitting you consent to us storing your details in order to contact you. See our privacy policy.