senn-techsenn-tech
All references03 · IT

NIS2 compliance platform

Reference client: Logistics and trading group in Tyrol, Austria · ~100 employees · 4 sites

Customer data in copy and images has been neutralised.

55controls
14areas
13recurring duties

Starting point

NIS2 makes cybersecurity a leadership matter — with personal liability for management. The requirements are extensive, and the classic answer is a binder full of documents nobody opens again after the audit.

What was missing was a living overview: which measure is fulfilled, which is in progress, who owns it — and what is overdue?

The hard part

Compliance has a habit of documenting itself to death. The usual route ends in a binder that is complete for the audit and of interest to nobody for the following year. Formally correct, practically worthless. The requirement, after all, is not to prove it once but to be continuously compliant.

The real difficulty is a different one: evidence ages without announcing itself. A restore test from fourteen months ago appears on no list as expired, it appears as done, and nobody ever decided that it had stopped counting. Setting a control to green once is therefore the most comfortable way to deceive yourself.

And any measure without a name against it is nobody's job. A control assigned wholesale to IT gets done by no human being personally. It gets administered.

Solution

A NIS2 status board was built: 55 controls across 14 areas — from risk management through backup to the supply chain — each with an owner and a status, rolled up into a compliance score for management.

Alongside it, a task tracker with 13 recurring duties such as restore tests or access reviews. When something falls overdue, the system reminds automatically — every morning, until it is done.

Node.jsPostgreSQLStatusboardAuto-Reminder

How it is built

The status board maps the controls into functional areas, from risk management through access rights and backup to the supply chain, and each one carries three entries that only together amount to a statement: a named owner, a status, and an evidence date.

The evidence date is the heart of it. Each control has an interval, and when it expires the control drops back to open on its own, without anyone having to remember or make a decision. Nobody can let evidence age quietly.

Alongside it sits a task tracker for the recurring duties: restore tests, access reviews, emergency drills. When something falls overdue, the system sends a reminder every morning, and it keeps doing so until the task is actually done — a one-off reminder goes missing just as reliably as the deadline it was meant to replace. It goes to the owner. Not to a shared mailbox.

Employee training on the directive runs on the same platform. That way the training record is not yet another list in another place.

Day-to-day operation

The day does not start with the compliance score. It starts with the list of overdue evidence, because that is the only number on the whole board which immediately triggers an action.

Technical evidence comes, wherever possible, out of live operation rather than out of a declaration: backup runs, certificate lifetimes and sign-in anomalies are supplied by the in-house SIEM, so the record is created where the fact is created and not in a form beside it. Evidence somebody types in by hand is an assertion. Measured evidence is proof.

When an ownership changes, it changes in one place. That sounds obvious and is still the most common reason compliance lists no longer hold up after a year.

Outcome

Management sees the compliance status at a glance instead of once a year in the audit. Almost a third of the measures are already fully met; the rest have owners and deadlines.

A paper project became a running process — and NIS2 employee training runs on the very same platform.

What we learned

The compliance score was our headline number at first, and that was wrong. A percentage rewards ticking off the easy controls first and says nothing at all about risk: ninety percent complete with backups unresolved is a considerably worse state than sixty percent with a verified restore, and the first number still looks better on every slide. The meaningful one is the more uncomfortable. How much evidence is currently overdue?

A board that is red is uncomfortable and useful for exactly that reason. A green board with no expiry checking is comfortable and worthless. Between those two sentences lies the entire difference between a compliance tool and compliance decoration.

And the experience that appears in no guide: the effort is not in building the list. It is in filling it in honestly the first time — with everything that surfaces uncomfortably in the process and that somebody then has to work through. Once that is done, it costs minutes per week.

Status board with 55 controls, broken down by completion and status

The status board, condensed: 55 controls under Article 21, split into complete, partial, in progress, blocked and open. The figure above is the compliance score. The less comfortable one below it says more.

Similar problem?

Tell us what you're planning — a short call clarifies whether it pays off.