In scope for the EU's NIS 2 Directive? Folksoft implements the required cybersecurity risk-management measures, sets up incident reporting, and keeps evidence audit-ready — so you meet your obligations without a security team.
From working out whether you're in scope to handing a regulator a complete incident file, Folksoft runs the programme for you.
We determine whether you're an "essential" or "important" entity and what NIS 2 requires of you.
The Article 21 measures — policies, incident handling, business continuity, supply-chain security, encryption, access control — set up for you.
Early-warning (24h) and full-notification (72h) workflows to the relevant CSIRT or competent authority.
Folksoft watches your AWS, Azure, GCP, GitHub, GitLab, and Okta environments around the clock — so drift is surfaced immediately.
Documentation is drafted and kept current; evidence is collected continuously — so you can show a regulator what you actually do.
NIS 2 splits in-scope organisations into two categories. Both carry the same core obligations — what changes is how closely you're supervised.
Energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure and similar sectors — generally above the large-enterprise thresholds. Some entities, such as DNS providers and trust service providers, qualify regardless of size.
Postal and courier services, waste management, chemicals, food, manufacturing, research — plus many digital providers such as online marketplaces, search engines and social platforms.
In short: both categories must implement the same core risk-management measures and report incidents; the difference is supervision intensity and penalties. Folksoft determines your category and gets you compliant.
If any of these sound like you, NIS 2 is likely on your critical path.
Cloud providers, managed service providers, data centres, and online marketplaces operating in or selling into the EU.
Energy, transport, health, finance, manufacturing, and the other sectors named in the directive's annexes.
Suppliers whose EU customers are in scope and now push NIS 2 requirements down the supply chain contractually.
Fast-growing companies with EU entities or customers that meet the size and sector thresholds.
Everything founders ask us before starting their NIS 2 programme.
Still have questions?It depends on your sector and size and whether you operate in the EU. Many digital and ICT providers are now "important entities". Even if you're out of scope, in-scope EU customers may require NIS 2-aligned controls contractually. Folksoft confirms your status.
Member states transpose it into national law, so your obligations apply through each country's implementing legislation rather than the directive directly. We map you to the relevant national requirements.
It depends on your scope and category. Contact us for a tailored quote.
Yes. Folksoft runs the programme and pairs you with a real GRC analyst.
Book a demo and we'll confirm your scope, then map your fastest path to meeting the directive's requirements.