Important and essential entities under NIS2
Are you an important entity?
Organisations in critical sectors (energy, transport, health, digital infrastructure, etc.) with 50β249 employees or EUR 10β50 million turnover.
Are you an essential entity?
Large organisations with β₯250 employees or β₯EUR 50 million turnover in critical sectors β or providers of certain digital services regardless of size.
Unsure whether you are covered? DocLex automatically assesses your entity classification based on the uploaded documents and identifies which category you belong to.
From documentation to NIS2 report β four steps
Upload your documentation and receive a structured compliance report within minutes.
Upload up to 5 files β security policies, risk assessments, incident procedures, system documentation, BCP/DR plans, etc. The more documentation you provide, the more precise the report. DocLex analyses all files together.
DocLex systematically reviews all 13 requirement areas in NIS2 Β§Β§ 4β7 and Β§Β§ 10β12 and identifies gaps in your documentation. Critical gaps (scope, registration, incident handling, management responsibility) are highlighted separately.
Based on the gap analysis, DocLex asks follow-up questions about requirement areas not covered by your documentation β e.g. incident SLAs, MFA exceptions or management approval procedures.
You receive a complete NIS2 compliance report with status for each requirement area, precise legal section references and concrete action points. The report is suitable as a basis for internal review and board presentation.
All 13 NIS2 requirement areas
Based on Danish Act No. 434 of 06/05/2025 and EU Implementing Regulation 2024/2690.
Scope assessment
Β§ 4β5 β Is the organisation subject to NIS2?
Registration obligation
Β§ 10 β Registration with competent authority
Risk management policy
Β§ 6 no. 1 β Risk management policy and procedures
Incident handling
Β§ 6 no. 2 + Β§ 12 β 24h/72h/1-month reporting
Business continuity
Β§ 6 no. 3 β BCP, backup and disaster recovery
Supply chain security
Β§ 6 no. 4 β Supplier management and security agreements
System security
Β§ 6 no. 5 β Network and system security
Effectiveness measurement
Β§ 6 no. 6 β Audit, testing and security metrics
Cyber hygiene and training
Β§ 6 no. 7 β Awareness programmes and education
Cryptography
Β§ 6 no. 8 β Encryption and key management
Access control
Β§ 6 no. 9 β IAM and privileged accounts
MFA and secure communications
Β§ 6 no. 10 β Multi-factor authentication
Management responsibility
Β§ 7 β Board and management accountability
Ready to get started?
Upload your documents and receive a NIS2 compliance report within minutes.
Start analysis