About Us Solutions How We Work Contact Blog
Book a Demo
NIS 2 — EU Directive 2022/2555

NIS 2 Compliance for Startups — Done For You.

In scope for the EU's NIS 2 Directive? Folksoft implements the required cybersecurity risk-management measures, sets up incident reporting, and keeps evidence audit-ready — so you meet your obligations without a security team.

In-scope and ready in weeks — no security hires needed.
24h early warning 72h notification Article 21 measures Continuous
2022/2555
The EU directive, covered
24h/72h
Incident reporting handled
Continuous
Risk management & monitoring
30-day
Money-back guarantee
The platform

What Folksoft does for your NIS 2 obligations

From working out whether you're in scope to handing a regulator a complete incident file, Folksoft runs the programme for you.

Scope & applicability assessment

We determine whether you're an "essential" or "important" entity and what NIS 2 requires of you.

Risk-management measures, implemented

The Article 21 measures — policies, incident handling, business continuity, supply-chain security, encryption, access control — set up for you.

Risk policies Incident handling Business continuity Supply chain Encryption Access control

Incident reporting, wired up

Early-warning (24h) and full-notification (72h) workflows to the relevant CSIRT or competent authority.

24h 72h Final report

Continuous monitoring of your stack

Folksoft watches your AWS, Azure, GCP, GitHub, GitLab, and Okta environments around the clock — so drift is surfaced immediately.

Policies & evidence, written for you

Documentation is drafted and kept current; evidence is collected continuously — so you can show a regulator what you actually do.

Collected automatically
No screenshotsNo spreadsheets
Essential vs Important

Which category are you in?

NIS 2 splits in-scope organisations into two categories. Both carry the same core obligations — what changes is how closely you're supervised.

Essential entities

Larger organisations in critical sectors

Energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure and similar sectors — generally above the large-enterprise thresholds. Some entities, such as DNS providers and trust service providers, qualify regardless of size.

SupervisionOngoing
Proactive supervision — audits and inspections can happen at any time
Higher maximum penalties — expect to be asked to prove it
Important entities

The other in-scope sectors

Postal and courier services, waste management, chemicals, food, manufacturing, research — plus many digital providers such as online marketplaces, search engines and social platforms.

SupervisionAfter the fact
Reactive supervision — triggered by an incident or evidence of non-compliance
Same measures required — lower maximum penalties

In short: both categories must implement the same core risk-management measures and report incidents; the difference is supervision intensity and penalties. Folksoft determines your category and gets you compliant.

Read the full text of Directive (EU) 2022/2555
Who needs it

Who needs NIS 2?

If any of these sound like you, NIS 2 is likely on your critical path.

Digital & ICT service providers

Cloud providers, managed service providers, data centres, and online marketplaces operating in or selling into the EU.

Companies in NIS 2 sectors

Energy, transport, health, finance, manufacturing, and the other sectors named in the directive's annexes.

Vendors in an in-scope supply chain

Suppliers whose EU customers are in scope and now push NIS 2 requirements down the supply chain contractually.

Startups with EU operations

Fast-growing companies with EU entities or customers that meet the size and sector thresholds.

FAQ

NIS 2 questions, answered

Everything founders ask us before starting their NIS 2 programme.

Still have questions?

01 Does NIS 2 apply to my company?

It depends on your sector and size and whether you operate in the EU. Many digital and ICT providers are now "important entities". Even if you're out of scope, in-scope EU customers may require NIS 2-aligned controls contractually. Folksoft confirms your status.

02 NIS 2 is a directive — how does it apply to me?

Member states transpose it into national law, so your obligations apply through each country's implementing legislation rather than the directive directly. We map you to the relevant national requirements.

03 How much does NIS 2 compliance cost?

It depends on your scope and category. Contact us for a tailored quote.

04 Can I do this without a security team?

Yes. Folksoft runs the programme and pairs you with a real GRC analyst.

Get started

Get NIS 2 ready in weeks.

Book a demo and we'll confirm your scope, then map your fastest path to meeting the directive's requirements.

30-day money-back guarantee. No security hires needed.