A personal project about making compliance provable.

NISAware started from a simple question: what would NIS2 and CyberFundamentals compliance look like if it were worked through in software instead of a folder full of spreadsheets, where scope, controls, risk and evidence are actually wired together? This page describes what came out of that.

An independent project. NISAware is built and maintained by one person, not affiliated with any employer or vendor. It is not commercially available — no demos, trials or sign-ups.

Built around the NIS2 Directive and CyberFundamentals: Basic, Important, Essential. GDPR-aware throughout.

app.nisaware.com
NISAware dashboard showing a customer's compliance overview
Compliance Score CyFun Basic
0% COMPLIANCE
Compliant0 / 34
Partial3 / 34
Gap1 / 34
218CyFun controls, Basic → Essential
2.5 → 3.5The maturity bar per assurance level
Art. 23NIS2 reporting deadlines tracked per incident
ISO 27001Annex A shown as a lens over the same work
About this project

Why it exists.

Working through a CyberFundamentals assessment on paper means keeping a control set, a risk register, an asset inventory, a supplier list and a pile of evidence in separate files that know nothing about each other. Every link between them is a cell you typed by hand, and nothing tells you when one of them goes stale. NISAware is my attempt at modelling those relationships properly and seeing what that changes.

What it does

The parts that turned out to matter.

Most of these started as something I was doing by hand and got built because doing it by hand kept going wrong.

Guided classification

A guided intake works out whether an entity falls in scope and at which obligation level, then assigns the matching CyFun profile. Every input that led there is kept as a record, so the scope decision can be explained afterwards rather than reconstructed.

Maturity scoring on two axes

Documentation and implementation are scored separately per control, against the bar the assurance level demands. Key measures are tracked individually, because a good average does not help if one of them falls under the line.

Risk templates

Common scenarios come pre-filled with threat, vulnerability and outcome, and map themselves to the controls that mitigate them. Risks are written as scenarios rather than as missing measures, so a treated risk stays on the register instead of disappearing.

Asset and supplier chain

Information asset, supporting asset and supplier are linked as a real chain rather than as text in three separate lists. Sensitivity flows up from the data, so a business process inherits its classification instead of being typed in again.

Policy templates

Policies are rendered from templates and link back to the controls they cover, so coverage maps itself rather than being cross-referenced by hand. Approval stays where it belongs: with the organisation, not with the tool.

Reviews and separation of duties

Scoring runs through review cycles that close as read-only, point-in-time records. Roles are enforced rather than suggested: whoever implements a control does not score it, and whoever runs a review does not approve it.

How it works

From scope to sign-off in three moves.

1

Classify

Run the intake. Scope and assurance level are worked out from sector, size and annex, and the reasoning behind the outcome is kept alongside it.

2

Assess

Work the controls in a review cycle. Score both axes, attach evidence, record exceptions where a requirement genuinely cannot be met.

3

Prove

Close the review as an immutable snapshot and export the evidence pack, with the trail from control to finding to evidence intact.

Status

Where this stands.

NISAware started as an experiment: how far could this go in software, and how much of the spreadsheet work could actually be streamlined away? It runs on its own infrastructure with synthetic test data.

It is not a conformity assessment tool. Verification against the CyberFundamentals framework is carried out by accredited conformity assessment bodies under national accreditation supervision, and nothing produced here substitutes for that.

Questions about the project are welcome at info@nisaware.com. Please note that it is not available commercially, so requests for demos, pricing or access cannot be taken up.