From applicability check to full attack surface analysis — AI-powered reports that translate technical findings into business risks and NIS2 compliance requirements.
Whether you need to check if NIS2 applies or want a deep security analysis — start with your company email and get results within 48 hours.
Does NIS2 apply to your organization? Get a definitive answer — sector classification, entity size, and specific obligations under the BSIG.
A 30–50 page professional security report mapping your external attack surface to NIS2 compliance requirements. For CISOs, IT managers, and executive leadership.
The first question every organization faces: Does NIS2 apply to us? Our free report answers this definitively — analyzing your sector, entity size, and jurisdiction against the NIS2 Directive and the German BSIG transposition.
Identification of your NACE sector and subsector, mapped to Annex I (essential) and Annex II (important) of the NIS2 Directive.
Essential vs. important entity classification based on employee count and revenue thresholds (50+ employees or €10M+ revenue).
Specific requirements under § 30 (measures), § 32 (reporting), and § 38 BSIG (management liability) — with deadlines and registration guidance.
Transposition status tracking across all EU member states. We monitor legislative updates continuously so your report reflects current law.
No credit card · Business email required · Delivered in 48h
A comprehensive 30–50 page professional security report. AI-powered analysis of your external attack surface — DNS, SSL, headers, exposed services — translated into business risks and executive-ready language, mapped to NIS2 compliance requirements.
Complete inventory of domains, subdomains, IPs, open ports, SSL configurations, and exposed services.
AI-modeled attack chains showing how an adversary could exploit your infrastructure, step by step.
Every finding mapped to the 10 measures of § 30 BSIG. Color-coded status per requirement.
Business-language risk summary with quantified impact scenarios. Board-ready documentation.
Prioritized action plan ranked by risk reduction. Quick wins highlighted for immediate action.
Every claim backed by OSINT evidence and source citations. Validated findings, no guesswork.
Free applicability report included · Upgrade to attack surface after results
Our AI agents collect publicly available threat intelligence and network data, then generate comprehensive NIS2 and Attack Surface reports — automatically connected and correlated for complete clarity.
CVE databases, threat feeds, industry reports
Registry records, financial data, sector info
DNS, subdomains, exposed services
Analysis & Correlation Engine
Applicability, obligations, deadlines
Vulnerabilities, risk scores, NIS2 mapping
AI agents gather publicly available company information and threat intelligence — the same data any threat actor could easily access. No active scanning, no system access required.
Our AI processes the data, determines NIS2 applicability based on public company records, identifies external attack surface exposures, and correlates findings with regulatory requirements.
Receive two connected reports: NIS2 Applicability Assessment and Attack Surface Analysis — showing exactly how your technical exposure translates into compliance risk.
Start with your free NIS2 Applicability Report. Understand your obligations in minutes, not months — and focus on what matters: your business.
We only analyze publicly available information (OSINT) — DNS records, SSL certificates, HTTP response headers, WHOIS data, and publicly exposed services. We never perform active vulnerability scanning or penetration testing.
Yes, 100%. Our methodology is entirely passive — we only look at data that is already publicly available on the internet. This is the same information any potential threat actor could access. No systems are probed, tested, or attacked.
Both the free NIS2 Applicability Report and the Attack Surface Assessment are typically delivered within 48 hours. Complex assessments with many subdomains may take slightly longer.
The free NIS2 Applicability Report answers "Does NIS2 apply to us?" — it covers sector classification, entity sizing, and specific obligations. The paid Attack Surface Assessment goes deeper with a 30–50 page technical security analysis of your external infrastructure, mapped to NIS2 compliance requirements.
Just your company email address. We identify your organization from the email domain and start analysis automatically. No documents, no questionnaires, no preparation needed.