Legal & Compliance
Check your NIS2 readiness against your own evidence
Upload your checklist and evidence on governance, risk, incidents, suppliers and continuity. You get a workbook and gap list, with country differences noted.
or drop them here
- CSV / XLSX / PDF / DOCX
- Up to 25 evidence files
- 64,000 extracted characters maximum
Topic: Incident handling. Evidence: policy/incident.md. Owner: Security Lead. Supplier-risk evidence is not provided.
- Mapped topic: Incident handling
- Visible gap: Supplier-risk evidence
Requirement-evidence workbook, gap CSV, country notes and source evidence
One clear job, from source to download
- 1
Add the source
Supported formats and limits are visible before the upload.
- 2
Confirm the settings
Review the exact source, options, units and access before processing.
- 3
Inspect and download
Check the preview and warnings, then unlock the complete package.
Mapping your NIS2 evidence to your own checklist
What you bring to the run
You upload your organisation's NIS2 checklist and the evidence behind it. That can cover governance, risk, incidents, suppliers and continuity. Files can be CSV, XLSX, PDF or DOCX, up to 25 evidence files and 64,000 extracted characters per run. A larger set has to be split across runs. You also enter the country of assessment and declare your entity status. This is an AI tool, so it needs an account and credits. The cost is shown before you start.
The workbook and gap list you get back
The download holds a requirement-evidence workbook, a gap CSV, country notes and the source evidence. Each requirement shows which of your files was cited for it. A gap means no supplied evidence was cited for that point. Supplier risk is a common example. It is listed as a gap rather than filled in from a loosely related policy. Check each mapping against the cited file before you pass the workbook on.
Country, entity status and the legal call
NIS2 is written into national law differently in each member state. The country you enter shapes the assumptions in the country notes, and those assumptions stay visible in the package. Entity status can be essential, important or unsure. The tool does not decide whether you fall under NIS2 or give a compliance verdict. Those are legal questions for your own advisers, and the workbook is meant to support their review.
Questions before you run it
Do I have to supply my own NIS2 checklist?
Yes, the organization checklist is a required upload. Evidence is mapped to the requirements you list, not to a generic template written by someone else.
Why does it ask which country the assessment is for?
NIS2 is transposed into national law differently in each member state. The country you enter drives the assumptions recorded in the country notes, and those assumptions stay in the package instead of vanishing into a score.
Will it tell me whether we count as an essential or important entity?
No. Entity status is something you declare, and Unsure is an accepted answer. No scope ruling is made, because that classification is a legal question for your own advisers.
What does a gap in the output actually mean?
It means no supplied evidence was cited for that requirement. A topic with no uploaded document behind it, supplier risk being the common case, is listed as a visible gap rather than inferred from a loosely related policy.
How much evidence can one run cover?
Up to 25 files in CSV, XLSX, PDF or DOCX, with 64,000 extracted characters as the hard ceiling. A larger document set has to be split across runs.