Community
Free
Self-hosted. No user limit, no time limit.
DownloadArticle 21 is the to-do list of the directive: ten security measures you must have in place. Most organisations already do six or seven of them and cannot prove it. Proving it is the work.
Two questions decide it: what you do, and how big you are. The sector list is set by the directive; the size gate is the same for both tiers.
The size gate. A medium or large enterprise - 50 or more employees, or €10M or more annual turnover - operating in a listed sector is in. A five-person shop is generally out, unless the state decides you are critical anyway.
Proactive supervision - audits without an incident
Authorities can run planned audits and on-site inspections even when nothing has gone wrong.
Reactive supervision - audited on cause
Supervision usually follows a reasonable indication of non-compliance: a breach, or a third-party report.
The exact wording of Article 21(2), and the eramba module that carries the evidence for it. Two measures are marked partial on purpose.
Article 21(4) adds that an entity finding itself non-compliant must take corrective measures without undue delay. In eramba that is a project with an owner and a deadline, linked to the requirement it closes.
NIS2 entered into force in January 2023. Member states had to transpose it into national law by 17 October 2024, and did so in twenty-seven different ways - several of them late. Implementation and enforcement timelines still vary.
eramba holds the same evidence either way: policies with approvals, controls with test results, incidents with timelines, suppliers with assessments.
Strict split between essential and important. Important entities face no direct oversight without cause.
The BSI is the central auditor and folds NIS2 into the existing KRITIS framework, with high-detail evidence.
The CCB requires proactive registration and collects evidence through a portal.
ANSSI streamlines the process alongside DORA for finance, to avoid audit fatigue.
Download the NIS2 package as a CSV - the full directive, Chapter IV, or Article 21 on its own - and import it into the free Community edition. Nothing to unlock, no per-framework fee.
ICT risk, incident reporting and third-party registers for finance.
See the pageFramework pageThe management system most NIS2 programmes are built on.
See the pageUse caseThe classification method behind measure (a) and (c).
See the pageUse caseThe six steps that apply to every framework you import.
See the pageFlat annual price. Unlimited users, unlimited frameworks, every module included. Your bill does not grow with your team.
Flat annual price. Unlimited users, unlimited data, every module included. Your bill does not grow with your team.
Free
Self-hosted. No user limit, no time limit.
Downloadfrom 2500€/year
Runs on your infrastructure, with support and updates.
See pricingfrom 5000€/year
Hosted and operated by eramba, in the EU.
See pricingA practitioner answers, not a sales sequence.