NIS2 β€” Get started

Is your organisation ready for NIS2?

DocLex analyses your documentation and generates a structured NIS2 compliance report with concrete action points β€” based on Danish Act No. 434 of 06/05/2025.

Start analysis

Important and essential entities under NIS2

Important entities

Are you an important entity?

Organisations in critical sectors (energy, transport, health, digital infrastructure, etc.) with 50–249 employees or EUR 10–50 million turnover.

Requirements: NIS2 Β§ 6 security measures + Β§ 12 incident reporting Registration: Β§ 10 β€” with the competent authority Penalty: Up to EUR 7 million or 1.4% of global turnover
Essential entities

Are you an essential entity?

Large organisations with β‰₯250 employees or β‰₯EUR 50 million turnover in critical sectors β€” or providers of certain digital services regardless of size.

Requirements: All NIS2 requirements + proactive supervision Regulation: EU 2024/2690 applies to MSP/cloud providers Penalty: Up to EUR 10 million or 2% of global turnover

Unsure whether you are covered? DocLex automatically assesses your entity classification based on the uploaded documents and identifies which category you belong to.

From documentation to NIS2 report β€” four steps

Upload your documentation and receive a structured compliance report within minutes.

1
Upload your documents

Upload up to 5 files β€” security policies, risk assessments, incident procedures, system documentation, BCP/DR plans, etc. The more documentation you provide, the more precise the report. DocLex analyses all files together.

2
AI analysis of all 13 NIS2 requirement areas Claude (Anthropic)

DocLex systematically reviews all 13 requirement areas in NIS2 Β§Β§ 4–7 and Β§Β§ 10–12 and identifies gaps in your documentation. Critical gaps (scope, registration, incident handling, management responsibility) are highlighted separately.

3
Targeted clarification dialogue

Based on the gap analysis, DocLex asks follow-up questions about requirement areas not covered by your documentation β€” e.g. incident SLAs, MFA exceptions or management approval procedures.

4
Report delivered by email

You receive a complete NIS2 compliance report with status for each requirement area, precise legal section references and concrete action points. The report is suitable as a basis for internal review and board presentation.

All 13 NIS2 requirement areas

Based on Danish Act No. 434 of 06/05/2025 and EU Implementing Regulation 2024/2690.

Scope assessment

Β§ 4–5 β€” Is the organisation subject to NIS2?

Registration obligation

Β§ 10 β€” Registration with competent authority

Risk management policy

Β§ 6 no. 1 β€” Risk management policy and procedures

Incident handling

Β§ 6 no. 2 + Β§ 12 β€” 24h/72h/1-month reporting

Business continuity

Β§ 6 no. 3 β€” BCP, backup and disaster recovery

Supply chain security

Β§ 6 no. 4 β€” Supplier management and security agreements

System security

Β§ 6 no. 5 β€” Network and system security

Effectiveness measurement

Β§ 6 no. 6 β€” Audit, testing and security metrics

Cyber hygiene and training

Β§ 6 no. 7 β€” Awareness programmes and education

Cryptography

Β§ 6 no. 8 β€” Encryption and key management

Access control

Β§ 6 no. 9 β€” IAM and privileged accounts

MFA and secure communications

Β§ 6 no. 10 β€” Multi-factor authentication

Management responsibility

Β§ 7 β€” Board and management accountability

Ready to get started?

Upload your documents and receive a NIS2 compliance report within minutes.

Start analysis
Questions about NIS2? β†’ See FAQ