A personal project about making compliance provable.
NISAware started from a simple question: what would NIS2 and CyberFundamentals compliance
look like if it were worked through in software instead of a folder full of spreadsheets,
where scope, controls, risk and evidence are actually wired together? This page describes
what came out of that.
An independent project. NISAware is built
and maintained by one person, not affiliated with any employer or vendor. It is not
commercially available — no demos, trials or sign-ups.
Built around the NIS2 Directive and CyberFundamentals: Basic, Important, Essential. GDPR-aware throughout.
app.nisaware.com
Compliance ScoreCyFun Basic
Compliant0 / 34
Partial3 / 34
Gap1 / 34
218CyFun controls, Basic → Essential
2.5 → 3.5The maturity bar per assurance level
Art. 23NIS2 reporting deadlines tracked per incident
ISO 27001Annex A shown as a lens over the same work
About this project
Why it exists.
Working through a CyberFundamentals assessment on paper means keeping
a control set, a risk register, an asset inventory, a supplier list and a pile of evidence in
separate files that know nothing about each other. Every link between them is a cell you
typed by hand, and nothing tells you when one of them goes stale. NISAware is my attempt at
modelling those relationships properly and seeing what that changes.
What it does
The parts that turned out to matter.
Most of these started as something I was doing by hand and got built
because doing it by hand kept going wrong.
Guided classification
A guided intake works out whether an entity falls in scope and at which obligation level,
then assigns the matching CyFun profile. Every input that led there is kept as a record, so
the scope decision can be explained afterwards rather than reconstructed.
Maturity scoring on two axes
Documentation and implementation are scored separately per control, against the bar the
assurance level demands. Key measures are tracked individually, because a good average does
not help if one of them falls under the line.
Risk templates
Common scenarios come pre-filled with threat, vulnerability and outcome, and map themselves
to the controls that mitigate them. Risks are written as scenarios rather than as missing
measures, so a treated risk stays on the register instead of disappearing.
Asset and supplier chain
Information asset, supporting asset and supplier are linked as a real chain rather than as
text in three separate lists. Sensitivity flows up from the data, so a business process
inherits its classification instead of being typed in again.
Policy templates
Policies are rendered from templates and link back to the controls they cover, so coverage
maps itself rather than being cross-referenced by hand. Approval stays where it belongs:
with the organisation, not with the tool.
Reviews and separation of duties
Scoring runs through review cycles that close as read-only, point-in-time records. Roles
are enforced rather than suggested: whoever implements a control does not score it, and
whoever runs a review does not approve it.
How it works
From scope to sign-off in three moves.
1
Classify
Run the intake. Scope and assurance level are worked out from sector, size and annex, and
the reasoning behind the outcome is kept alongside it.
2
Assess
Work the controls in a review cycle. Score both axes, attach evidence, record exceptions
where a requirement genuinely cannot be met.
3
Prove
Close the review as an immutable snapshot and export the evidence pack, with the trail from
control to finding to evidence intact.
Status
Where this stands.
NISAware started as an experiment: how far could this go in software,
and how much of the spreadsheet work could actually be streamlined away? It runs on its own
infrastructure with synthetic test data.
It is not a conformity assessment tool. Verification against the
CyberFundamentals framework is carried out by accredited conformity assessment bodies under
national accreditation supervision, and nothing produced here substitutes for that.
Questions about the project are welcome at
info@nisaware.com.
Please note that it is not available commercially, so requests for demos, pricing or access
cannot be taken up.