NIS2 · Readiness & Evidence
Determine scope, continuously demonstrate Art. 21 measures, meet reporting deadlines.
Scope is the wrong first question — the right one is: can you prove it?
"I can claim it — but I can't prove it. The BSI audit could come at any time." That is how CISOs under audit pressure describe their situation — and NIS2 makes it personal: the board must implement the ten risk-management measures under Art. 21(2) themselves, oversee their implementation, and attend training regularly (Art. 20 NIS2 · § 38 BSIG · § 31 NISG 2026). As a last resort, the regulator can temporarily prohibit board members from performing their function.
Before any control framework makes sense, there is a different question: is your organization in Annex I or Annex II — essential or important entity? This classification determines reporting obligations, supervisory intensity, and fine bands, and it depends on your sector, not your headcount. If you do not clarify this carefully, you build on a false assumption.
And when a breach occurs, what matters is not intent, but the clock: 24 hours for the early warning, 72 hours for the complete report, 30 days for the closure report. Without an automatic deadline tracker, you rely on calendar reminders — precisely where a missed deadline is most expensive.
Four pillars that turn claims into proof.
Deterministic scope assessment
Four questions about your sector, size, and activities map you to Annex I or Annex II — traceable and without needing legal advice to take the first step. The result automatically determines which reporting and registration deadlines apply to you.
Scope assessment in workspace.reportact.com
Automated control assessment from evidence
The ten risk-management measures under Art. 21(2) and the CIR 2024/2690 controls are automatically assessed from evidence you have already captured — one control counts toward both ISO 27001 and the AI Act at once, instead of being maintained separately three times. Supply chain security (Art. 21(2)(d)) is continuously assessed from your vendor register and sealed as its own evidence record.

Incident register with 24-hour countdown
Log an incident, and the countdown for early warning (24 h), complete report (72 h), and closure report (30 days) runs visibly — including a signed reporting pipeline with pre-check so nothing incomplete is sent.

Registration deadline tracking
Your country's NISG registration deadline is tracked and escalated on time — instead of being lost in an email or calendar entry that no one finds when it matters.

More on NIS2 and the engine behind it.
Deadlines, Annex I/II classification, fine bands, and primary sources in detail.
Regulation details →How control assessment works and how it covers NIS2, DORA, ISO 27001, and the AI Act simultaneously.
Feature details →What Art. 21(2)(d) requires for assessing suppliers and service providers.
NIS2 & supply chain — what Art. 21 requires →Your first sealed NIS2 evidence — today.
In 30 minutes we show you what ReportAct delivers for this use case – no obligation.