OSINT-Based · AI-Powered · Delivered in 48h

NIS2 Security
Assessments

From applicability check to full attack surface analysis — AI-powered reports that translate technical findings into business risks and NIS2 compliance requirements.

100% passive — no active scanning OSINT-based, fully legal Reports within 48 hours

Two Reports, One Platform

Whether you need to check if NIS2 applies or want a deep security analysis — start with your company email and get results within 48 hours.

Free

NIS2 Applicability Report

Does NIS2 apply to your organization? Get a definitive answer — sector classification, entity size, and specific obligations under the BSIG.

  • Sector & subsector analysis (Annex I/II)
  • Essential vs. important classification
  • Country-specific obligation mapping
  • BSI registration guidance
Start Free Assessment
from €49

Attack Surface Assessment

A 30–50 page professional security report mapping your external attack surface to NIS2 compliance requirements. For CISOs, IT managers, and executive leadership.

  • Full external attack surface map
  • AI-modeled attack path analysis
  • NIS2 § 30 compliance mapping
  • Prioritized remediation roadmap
Start Assessment

NIS2 Applicability Report — Free

The first question every organization faces: Does NIS2 apply to us? Our free report answers this definitively — analyzing your sector, entity size, and jurisdiction against the NIS2 Directive and the German BSIG transposition.

🏭
Sector Classification

Identification of your NACE sector and subsector, mapped to Annex I (essential) and Annex II (important) of the NIS2 Directive.

📊
Entity Sizing

Essential vs. important entity classification based on employee count and revenue thresholds (50+ employees or €10M+ revenue).

📋
Obligation Mapping

Specific requirements under § 30 (measures), § 32 (reporting), and § 38 BSIG (management liability) — with deadlines and registration guidance.

🇪🇺
27 EU Countries

Transposition status tracking across all EU member states. We monitor legislative updates continuously so your report reflects current law.

Get Your Free Report

No credit card · Business email required · Delivered in 48h

Attack Surface Assessment — from €49

A comprehensive 30–50 page professional security report. AI-powered analysis of your external attack surface — DNS, SSL, headers, exposed services — translated into business risks and executive-ready language, mapped to NIS2 compliance requirements.

🌐
External Attack Surface Map

Complete inventory of domains, subdomains, IPs, open ports, SSL configurations, and exposed services.

⚔️
Attack Path Analysis

AI-modeled attack chains showing how an adversary could exploit your infrastructure, step by step.

📊
NIS2 Compliance Mapping

Every finding mapped to the 10 measures of § 30 BSIG. Color-coded status per requirement.

👔
Executive Summary

Business-language risk summary with quantified impact scenarios. Board-ready documentation.

🗺️
Remediation Roadmap

Prioritized action plan ranked by risk reduction. Quick wins highlighted for immediate action.

🔍
Evidence-Based

Every claim backed by OSINT evidence and source citations. Validated findings, no guesswork.

Start Your Assessment

Free applicability report included · Upgrade to attack surface after results

How It Works

Our AI agents collect publicly available threat intelligence and network data, then generate comprehensive NIS2 and Attack Surface reports — automatically connected and correlated for complete clarity.

🔍

Threat Intelligence

CVE databases, threat feeds, industry reports

🌐

Public Company Data

Registry records, financial data, sector info

📡

Public Open-Source Intelligence (OSINT)

DNS, subdomains, exposed services

NIS2Have - AI-Powered Security Assessment Platform

Analysis & Correlation Engine

📋

NIS2 Report

Applicability, obligations, deadlines

Free
🎯

Attack Surface Report

Vulnerabilities, risk scores, NIS2 mapping

📡

Passive Data Collection

AI agents gather publicly available company information and threat intelligence — the same data any threat actor could easily access. No active scanning, no system access required.

🧠

AI Analysis

Our AI processes the data, determines NIS2 applicability based on public company records, identifies external attack surface exposures, and correlates findings with regulatory requirements.

📋

Integrated Reports

Receive two connected reports: NIS2 Applicability Assessment and Attack Surface Analysis — showing exactly how your technical exposure translates into compliance risk.

🛡️
100% Passive & Non-Intrusive We never touch your digital infrastructure or perform active scanning. Our analysis uses only publicly available information — the same data that threat actors can easily access to plan attacks against your organization.

Ready for Clarity?

Start with your free NIS2 Applicability Report. Understand your obligations in minutes, not months — and focus on what matters: your business.

Frequently Asked Questions

What data do you collect about my company?

We only analyze publicly available information (OSINT) — DNS records, SSL certificates, HTTP response headers, WHOIS data, and publicly exposed services. We never perform active vulnerability scanning or penetration testing.

Is the assessment legal?

Yes, 100%. Our methodology is entirely passive — we only look at data that is already publicly available on the internet. This is the same information any potential threat actor could access. No systems are probed, tested, or attacked.

How long does it take to get my report?

Both the free NIS2 Applicability Report and the Attack Surface Assessment are typically delivered within 48 hours. Complex assessments with many subdomains may take slightly longer.

What's the difference between the two reports?

The free NIS2 Applicability Report answers "Does NIS2 apply to us?" — it covers sector classification, entity sizing, and specific obligations. The paid Attack Surface Assessment goes deeper with a 30–50 page technical security analysis of your external infrastructure, mapped to NIS2 compliance requirements.

Do I need to prepare anything?

Just your company email address. We identify your organization from the email domain and start analysis automatically. No documents, no questionnaires, no preparation needed.