NIS2 compliance you can prove

Do the work once and demonstrate compliance across multiple standards at the same time.
ISOPlanner™ turns the four NIS2 obligations into tasks, owners and evidence.
All inside your own Microsoft 365 environment
✓ Risk assessment and controls in one place
✓ Work on NIS2 together, in your own environment
✓ Structure evidence and reporting as one thing
✓ Groundwork for ISO 27001 and multi-framework compliance

See exactly how ISOPlanner™ helps you comply with NIS2.

Schedule a demo and see ISOPlanner™ in action for your organisation, or try it out yourself directly for 30 days for free. No obligation. No credit card needed.

How ISOPlanner™ Supports NIS2

How to Turn the NIS2 Obigations into Control

NIS2 is a European directive and does not apply directly. Each member state transposes it into national law, and that national law is what your organisation is held to. It imposes four obligations.

Duty of care

What the law asks
You assess the risks to your network and information systems and take appropriate measures. The list of measures in the law is a minimum, not a complete enumeration: what counts as appropriate depends on your risk profile.

How ISOPlanner™ helps
The risk assessment and the controls sit in one place, each with an owner and a status. Because "appropriate" depends on your own risk profile, you record for each control why you made that choice and why another control was not needed. That justification is exactly what a supervisory authority asks for, and it is already there. All inside your own Microsoft 365 environment, under your own access control.

1
Embedded ML
API Calling ML
2

Registration duty

What the law asks
Organisations that fall under the law register with the government, through the portal their member state provides.

How ISOPlanner™ helps
You register yourself, with your national authority. ISOPlanner™ does not take that over, and it should not. What the software does do is hold the justification: which sector list you land on, which threshold you test against, who established that and on what date. If something changes in your organisation that means the registration must be updated, that obligation sits as a task with a deadline in the same system, instead of in someone's head.

Reporting duty

What the law asks
You report a significant incident within 24 hours as an early warning, followed by a fuller notification within 72 hours and a final report after that.

How ISOPlanner™ helps
The deadlines are built into the incident register. From the moment you record an incident, the clock runs visibly and you can see which notification is due when. Who filed the notification and what was reported sits with the incident itself. That means you write the final report from what was kept during the incident, instead of reconstructing it afterwards from mailboxes and chat messages.

3
ML Platform
API Calling ML
4

Management liability

What the law asks
This is the part that is most often underestimated. The Dutch supervisory authority puts it this way: "The board bears ultimate responsibility for governance and risk management." The law makes it possible to fine directors personally or to impose a penalty payment order. Compliance is therefore not a subject that can be left entirely to IT.

How ISOPlanner™ helps
A board can only take responsibility for what it can see. The reporting is built to be shown to the board without anyone assembling it first: which risks are open, which controls are behind, who owns them and what has changed since the last report. And because the evidence is recorded at the moment the work happens, that report reflects how things actually stand rather than a snapshot put together for the meeting.

The four NIS2 obligations

From Obligation to Control

An obligation tells you what to do. Control tells you whether it is still being done. Below, each NIS2 obligation sits beside the mechanism that keeps it running: an owner, a status, and evidence that builds as the work happens, inside your own Microsoft 365.

Obligation

How ISOPlanner™ helps

Duty of care

Risk assessment and controls recorded in one place, with an owner and a status.

Reporting duty

Incident registration with the deadlines built in, so the clock is not tracked by hand.

Management liability

Reporting that can be shown to the board without anyone assembling it first.

Supervision

Evidence gathered at the moment the work happens, not afterwards.

None of the four is wasted work. The register, the owners and the evidence NIS2 asks for are what ISO 27001 asks for too, so the work you do for the law becomes the groundwork for certification rather than a detour from it.
Hosted in EU Icon
100% Hosted in the eu

Our Compliance Customers

We are happy with ISOPlanner: it maps out what you do, how you monitor and execute it. For us it is the Ferrari of information security management systems!”
Profile Tanja de Haan
Tanja de Haan
Informatiebeveiliging
Level Software
The auditor was very impressed by the product and how it ties everything together, an auditor’s dream.”
Profile Tracy Usher
Tracy Usher
Credit Collection Services Group
We chose a quick implementation where a lot of preliminary work had already been done. And that matched our security requirements such as single sign-on.”
Profile Jimmy Voskuil
Jimmy Voskuil
CISO
Waterland
Little preparation was required for this audit because everything was properly recorded so employees were able to adequately answer questions from the auditor.”
Profile Wendy Rockx
Wendy Rockx
FinData
The tasks of both ISO 14001 and ISO 9001 are now in the ISOPlanner and they now run synchronously.”
Profile Govert van Bodegem
Govert van Bodegom
QA Manager
Hordijk Group
We have SME, SME-plus and even enterprise clients, all of whom have different needs. There is a lot on the market, but ISOPlanner is in a league of its own when it comes to functionality and pricing.”
Profile Tamara Krijbolder
Tamara Krijbolder
Managing partner
Collence
ISOPlanner provided the right mindset and assistance in conducting the audit preparation. The process went quickly, thanks to the guidance that the tool offers.”
Profile Andre Wiersma
Andre Wiersma
SalesManager Software
An auditor is blown away when he sees our ISMS. Surely ISOPlanner is the cream of the crop.”
Profile Robert Kerssies
Robert Kerssies
DHD
Compliance should not be an annual sprint, but a logical part of a daily practice. ISOPlanner makes that possible.”
Marco van der Steijle
Business Development
TeamValueGroup
New laws and regulations are coming up that will have far-reaching consequences for our organization.”
Profile Leon van der Valk
Leon van der Valk
SPIE Nederland
In retrospect, I should have done it earlier with the knowledge I now have about the added value of the system.”
Profile Alex Beckers
Alex Beckers
EerstelijnsZorg Zoetermeer
Answered

Frequently Asked Questions

01.

What is the difference between essential and important entities under NIS2?

NIS2 Article 3 divides in-scope organisations into two categories. Essential entities operate in critical sectors such as energy, transport, banking, health, and digital infrastructure. Important entities cover a broader set including postal services, waste management, food production, and digital providers. Essential entities face stricter supervision and higher maximum fines (up to €10M or 2% of global turnover). Important entities are subject to reactive supervision and lower maximum fines (€7M or 1.4%). ISOPlanner™ helps document the classification and governance obligations for either category.

02.

What security measures does NIS2 Article 21 require?

Article 21 requires appropriate and proportionate technical, operational, and organisational measures to manage cybersecurity risks. These include policies on risk analysis, incident handling, business continuity, supply chain security, secure development practices, cybersecurity training, and multi-factor authentication. ISOPlanner™ maps each Article 21 requirement to your risk register and control framework so every measure is tracked and evidenced.

03.

What are the NIS2 incident reporting timelines?

NIS2 Article 23 introduces a three-stage reporting timeline. An early warning must reach the national CSIRT or competent authority within 24 hours of detecting a significant incident. A full incident notification with initial assessment follows within 72 hours. A final report with root cause analysis, impact, and applied mitigations is due within one month. ISOPlanner™ includes an incident response workflow that tracks each stage and generates the required notification records.

04.

How does NIS2 address supply chain security?

Article 21 explicitly requires organisations to assess and manage cybersecurity risks from their supply chain and supplier relationships. This includes evaluating the security practices of direct suppliers and service providers, and considering how vulnerabilities in third-party products or services could affect your own security posture. ISOPlanner™ provides a supplier register and assessment template to document and monitor third-party security obligations under NIS2.

05.

What are the penalties for NIS2 non-compliance?

NIS2 imposes significant administrative fines. Essential entities can be fined up to €10 million or 2% of total global annual turnover, whichever is higher. Important entities face maximum fines of €7 million or 1.4% of global turnover. Beyond financial penalties, NIS2 also introduces personal liability for senior management who fail to implement required security measures. ISOPlanner™ helps document governance accountability to reduce management exposure.

06.

How does NIS2 relate to ISO 27001?

ISO 27001 and NIS2 are highly complementary. The security measures required by NIS2 Article 21 closely mirror the technical and organisational controls in ISO 27001 Annex A. Organisations with a certified ISO 27001 management system are well-positioned to meet NIS2 obligations, since ISO 27001 audit evidence can directly support NIS2 compliance demonstrations. ISOPlanner™ cross-maps NIS2 Article 21 requirements to ISO 27001 Annex A controls so a single evidence base serves both frameworks.

07.

Which sectors fall within NIS2 scope?

NIS2 covers a much broader set of sectors than its predecessor. Highly critical sectors include energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure (cloud, data centres, DNS, trust services), public administration, and space. Additional critical sectors include postal services, waste management, chemicals, food production, medical device manufacturing, and digital providers such as online marketplaces, search engines, and social networks.