Guided classification
A guided intake fixes NIS2 scope (Essential or Important), with the matching CyFun level (Basic, Important, Essential) and the rationale logged for the auditor.
Ten clients, twelve spreadsheets, and one assessor who rejects the whole submission because a single key measure came in just under the line. NISAware ends the Excel hell. Classify the entity, hold every control to the maturity bar its CyFun tier demands, and auto-map risks to the controls that fix them - then export evidence the auditor actually accepts.
Purpose-built for the NIS2 Directive and CyberFundamentals: Basic, Important, Essential. GDPR-aware throughout.
From intake to the assessor's sign-off, NISAware keeps scope, controls, risk and evidence wired together, so the posture is always real, never a stale spreadsheet you patch the night before.
A guided intake fixes NIS2 scope (Essential or Important), with the matching CyFun level (Basic, Important, Essential) and the rationale logged for the auditor.
Score documentation and implementation per control. Clear the maturity bar your tier demands (2.5 at Basic, 3.0 at Important, 3.5 at Essential), or it's a Gap, automatically. No optimistic rounding, no "mostly done", no audit-room surprises.
Pick "Ransomware" or "Phishing". NISAware pre-fills the threat, vulnerability and description, and auto-maps the 10+ CyFun controls that actually mitigate it. Get a documented, treated risk in minutes instead of an afternoon.
Track the real chain: Information Asset → Supporting Asset → Supplier. This delivers the exact supply-chain visibility NIS2 Article 21 expects, replacing the spreadsheets most teams quietly fake.
Code-rendered policies that auto-link back to the framework controls they satisfy. Generate one, and the control coverage maps itself. Eliminate orphaned Word docs and manual cross-referencing.
Run review cycles with point-in-time snapshots, then export a clean evidence pack for the board, the client, or the assessor. Available on demand, not after a week of scrambling through shared drives.
Run the intake. NISAware fixes NIS2 scope and the CyFun tier, and logs exactly how it got there, so the scope decision survives the auditor's first question.
Work the assigned controls. Score maturity against your tier's bar, fire risk templates, attach evidence. Every control that misses the bar surfaces as a Gap on the spot.
Watch the posture move live, then export the evidence pack the assessor signs off on. No month-end scramble, no "where did we save that".
One classify-assess-prove engine for client one and client one hundred. Every tenant is fully isolated, with each posture a click away.
Every client in one console, fully isolated. Switch context without ever crossing wires, and onboard the next logo in minutes, not a fresh deployment.
Scope consultants, analysts and client contacts to exactly what they should touch, and nothing they shouldn't. Least privilege, out of the box.
Your logo on the app, the reports and the emails. The client sees your brand on the audit deliverable, not ours. Your relationship stays yours.
Not an MSP? NISAware also runs as a dedicated single-tenant deployment. Corporates and larger mid-market teams managing their own NIS2 / CyFun compliance in-house get the same engine, isolated to a single organisation.
Stop fighting spreadsheets. See NISAware run a real classify → assess → prove cycle on your own roster. Tell us a little about your setup and we'll book a walkthrough.
Prefer email? info@nisaware.com