200+
Companies trust Kopexa
40-60%
less compliance effort
100%
EU-hosted

From 2025, stricter reporting obligations and fines up to EUR 10 million apply

Heavy fines

Up to EUR 10M or 2% of global annual revenue for NIS-2 non-compliance.

Personal liability

Executives are personally liable. NIS-2 makes cybersecurity a board-level issue.

Tight deadlines

BSI registration and first audits from 2026. Those who don't start now risk delay.

What the NIS-2 software specifically covers

Every NIS-2 requirement becomes a structured workflow with automatic evidence collection in Kopexa software.

Art. 23

Reporting obligations

Meet the 24-hour deadline

  • Report incidents to BSI within 24 hours
  • BSI-compliant reporting forms built into the software
  • Escalation workflows with automatic notifications
  • Complete audit trail for every report
Art. 21 (2a-b)

Risk management & incident response

Risk-based approach per ISO standard

  • Automated risk assessment with risk matrix
  • Treatment plans with owners and deadlines
  • Incident response process with playbooks
  • Risk register per ISO 27005, exportable as PDF
Art. 21 (2d)

Supply chain security

Automated vendor assessments

  • Structured questionnaires for vendor evaluation
  • Automatic risk classification per vendor
  • SLA tracking and contract management
  • Continuous monitoring of vendor security
Art. 21 (2c)

Business continuity

Prove resilience

  • Create and version BCM plans
  • Document recovery objectives (RTO/RPO)
  • Schedule and log regular tests
  • Define crisis management workflows
Art. 20

Governance & accountability

Engage executive management

  • Management dashboard with NIS-2 compliance status
  • Role-based access (CISO, DPO, IT lead)
  • Document training records for executives
  • Automatically schedule regular management reviews

The NIS-2 software that automates compliance

Compliance software that reduces your manual effort by 40-60%. Self-service or with partner support.

Kopexa controls overview with gap analysis and compliance status
Gap analysis at the push of a buttonCompliance status in real timeInstantly spot missing evidence

Seamless integration with your existing infrastructure

AWSMicrosoft AzureMicrosoft 365GitHubAtlassianCloudflare

Concrete outputs for audits and management

Kopexa NIS-2 software produces audit-ready documents. No manual copying, no formatting, no hoping.

Automated gap analysis (dashboard + PDF export)
NIS-2 compliance report with traffic light status
Risk register per ISO 27005
Action plan with owners and deadlines
Evidence documentation for BSI audits
Incident response protocols
Supply chain risk assessments
Management summary for executives
Training records and awareness documentation
Complete audit trail of all changes

One tool for all frameworks

NIS-2 is rarely the only requirement. Kopexa software supports cross-framework mapping: one control covers multiple standards simultaneously.

NIS-2

Full

All requirements per Art. 20, 21, 23

ISO 27001:2022

Full

93 Annex A controls with automatic mapping

TISAX

Full

VDA ISA catalog for automotive supply chains

GDPR

Full

ROPA, DPIA, data subject rights, reporting

DORA

Full

ICT risk management for financial institutions

BSI IT-Grundschutz

Mapping

Cross-mapping to BSI modules

Transparent pricing

No hidden costs. No minimum contract. 14-day free trial.

Lite

EUR 249/ month

Perfect for getting started with structured compliance

  • 1 framework (e.g. ISO 27001, NIS-2)
  • Up to 10 users
  • Risk management & policy management
  • Evidence collection
  • Email support
Start for free
Recommended

Pro

EUR 599/ month

NIS-2 compliance with cross-framework mapping

  • Up to 3 frameworks
  • Up to 25 users
  • Everything in Lite
  • Vendor management & asset management
  • Cross-framework mapping
  • Priority support
Start for free

Enterprise

Custom

For organizations with complex requirements

  • Unlimited frameworks
  • Unlimited users
  • SSO / SAML
  • Custom integrations
  • Dedicated success manager
Book a demo

Frequently asked questions about NIS-2 software

What is NIS-2 compliance software?

NIS-2 software digitizes the implementation of the NIS-2 directive. Instead of Excel spreadsheets and Word documents, you work with structured workflows, automatic evidence collection and a complete audit trail. Kopexa software covers all requirements under Art. 20, 21 and 23.

Who needs NIS-2 compliance software?

Any organization that falls under the NIS-2 directive: operators of essential and important entities across 18 sectors, from 50 employees or EUR 10M revenue. Over 160,000 companies are affected in Germany alone.

How quickly can I start NIS-2 implementation?

Immediately. After registration, the software is ready in minutes. The automated gap analysis shows you within an hour where you stand and what needs to happen next.

Can I use the software without a consultant?

Yes. Kopexa is designed for self-service: guided workflows, automatic action plans and built-in templates. If you want additional support, you can bring in one of our certified partner CISOs at any time. The software stays the same.

Which frameworks does the software support?

NIS-2, ISO 27001:2022, TISAX, GDPR, DORA and BSI IT-Grundschutz. Cross-framework mapping shows which controls overlap. One action plan can cover multiple standards simultaneously.

What does NIS-2 compliance software cost?

Kopexa starts at EUR 249/month (Lite). NIS-2 compliance with cross-framework mapping is available from EUR 599/month (Pro). Transparent pricing, no hidden costs. 14-day free trial.

How does software differ from Excel/Word?

Excel has no role-based access, no audit trail and no automatic evidence collection. During a BSI audit, you have to manually compile what the software documents automatically. The effort for Excel-based NIS-2 compliance grows exponentially with each audit.

Does the software meet BSI requirements?

Kopexa software covers all NIS-2 requirements that BSI checks as the responsible authority: risk management, incident response, supply chain security, business continuity and reporting obligations. Evidence is automatically linked and exportable at any time.

Where is my data hosted?

100% in the EU. Kopexa is hosted in European data centers. GDPR-compliant, no data transfer to third countries.

Does the software reduce consulting costs?

Yes. Through automated gap analysis, guided workflows and automatic evidence collection, manual effort drops by 40-60%. That means: fewer consultant hours for implementation, more focus on strategic decisions.

The NIS-2 deadline is running. Software, not panic.