What is the best NIS2 software for mid-sized companies?
Last updated: October 6, 2026. Vendor details verified on the vendors' own public pages: GRASP, otris, and verinice on October 6, 2026, all others on October 5, 2026.
Key Takeaways
- No NIS2 software is the best choice for every mid-sized company. The deciding question is whether someone in-house owns the information security management system (ISMS).
- If an internal information security officer or CISO is in place, an ISMS tool such as GRASP, otris isms, or verinice can be enough.
- That role is often missing: in the Kertos NIS2 Readiness Study 2026, 84% of 51 German companies with 50 to 1,000 employees had neither an in-house nor an external CISO.
- If that role is missing, a platform with experts is usually the realistic route. DataGuard, heyData, Kertos, and Secfix offer this model.
- Under Article 2 of the NIS2 Directive, a company in an Annex I or II sector is in scope from 50 employees, or once both its annual turnover and its balance sheet exceed EUR 10 million.
Which NIS2 software fits a mid-sized company depends less on features than on one question: does someone in-house own the ISMS? If so, a classic ISMS tool can be enough, because the expert work happens inside the company. Typical vendors of this model are GRASP, otris isms, and verinice. If not, a tool alone will not get you to NIS2 compliance. A platform with included experts is then usually the realistic route, as offered by DataGuard, heyData, Kertos, and Secfix. In between sit self-service tools such as secjur and Vanta, where experts are optional or come through partners.
Which mid-sized companies fall under NIS2?
"Mid-sized" is not a legal term in NIS2. The directive borrows the size categories of Commission Recommendation 2003/361/EC and applies to entities in its Annex I or II sectors that are medium-sized or larger (Directive (EU) 2022/2555, Article 2(1)). Article 3 then sorts in-scope entities into essential and important.
| Category | Condition | Mid-sized example |
|---|---|---|
| Important entity (Article 3(2)) | Annex I or II sector, and 50 or more employees, or annual turnover and balance sheet each above EUR 10 million | Machinery manufacturer with 120 employees (manufacturing, Annex II) |
| Essential entity (Article 3(1)(a)) | Annex I sector, and 250 or more employees, or turnover above EUR 50 million and a balance sheet above EUR 43 million | Energy supplier with 300 employees (energy, Annex I) |
| Regardless of size (Article 2(2) to (4)) | Among others: providers of public electronic communications networks or services, trust service providers, top-level domain name registries, DNS service providers, critical entities under Directive (EU) 2022/2557, and domain name registration services | A small DNS service provider |
Annex I covers eleven sectors of high criticality, including energy, transport, banking, health, and digital infrastructure. Annex II covers seven other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research. For many mid-sized companies Annex II is the relevant part, because manufacturing sits there. Article 3(1) also lists further categories of essential entities beyond the size rule.
Under the Recommendation, the figures of partner and linked enterprises generally count towards your headcount and financials, so a subsidiary of a larger group can be in scope. The directive sets a floor, and each member state's transposing law defines the final scope, generally that of the country where you are established. Germany is one example of a national variation: Section 28(4) of the German BSI Act leaves out partner and linked enterprise figures where a company runs its IT systems, components, and processes independently of them.
Germany also shows how far mid-sized companies have got. The Kertos NIS2 Readiness Study 2026 surveyed 51 companies based in Germany with 50 to 1,000 employees in sectors listed in Annex I of the directive, between August 3 and September 4, 2026. 27% reported being registered with the BSI, the German supervisory authority; 49% had not started implementation or were still assessing whether they are in scope. Six companies did not consider themselves in scope, although all respondents operate in sectors the directive covers.
Which type of NIS2 software fits which mid-sized company?
The three provider models differ in who does the expert work: your team, the vendor, or both. The vendors named are examples of each model, not a recommendation for your specific case.
| Your situation | Fitting provider model | Vendors of this model (examples) |
|---|---|---|
| An information security officer or CISO with ISMS experience is appointed in-house and has time for ongoing operation | ISMS or GRC tool for risks, measures, incidents, and evidence, some also on-premises | GRASP, otris isms, verinice |
| No internal security role; IT runs on the side or through a service provider | Platform with experts who carry implementation and evidence, some with an external information security officer or CISO mandate | DataGuard, heyData, Kertos, Secfix |
| Security know-how in-house, support wanted only occasionally | Self-service tool; experts optional (secjur) or audits through a partner network (Vanta) | secjur, Vanta |
The officer question decides because a tool manages risks and evidence but does not assess them. Someone has to lead the risk analysis, prioritize measures, and defend them in front of management and auditors. Without that person, a pure ISMS tool stays empty and the work shifts to external consultants. In the Kertos NIS2 Readiness Study 2026, 84% of the companies surveyed had neither an in-house nor an external CISO. In 63%, NIS2 sat with the head of IT, and in 41% that was the only role named.
The ISMS tools in the first model are available as SaaS or on-premises. GRASP offers a NIS2 module with standard controls, a risk register, action tracking, and incident and supplier risk management. verinice is open source, and its NIS-2 domain maps the 24-hour, 72-hour, and one-month reporting deadlines. According to its vendor page, otris isms starts at EUR 490 per month for the Standard edition (price dated May 8, 2026). Origin, hosting, and frameworks of all vendors are set out in the full NIS2 software comparison.
What does NIS2 software need to do for a mid-sized company?
- The ten measures with owner, status, and evidence: Article 21(2) of the directive lists ten cybersecurity risk-management measures, from risk analysis to multi-factor authentication. The software should assign each measure to an owner, show its implementation status, and store the evidence. In the study, 16% named manual, spreadsheet-based processes as an obstacle, and the same share named keeping evidence audit-ready. A function checklist for all ten measures is in the buyer's guide to NIS2 compliance software.
- The supply chain: Article 21(2)(d) requires supply chain security, including the relationships with direct suppliers and service providers. Regulated customers therefore often pass these requirements on to their suppliers by contract, including mid-sized companies that are not in scope themselves. Software that assesses suppliers and provides your own evidence for customer requests helps here. In the study, supplier and supply chain management was the least-named obstacle, at 6%.
- Management duties: Article 20(1) requires management bodies to approve the risk-management measures and oversee their implementation, and Article 20(2) requires them to follow training. The software should give management a status they can read without security expertise and document the training. In the study, 22% of companies named management as responsible for NIS2, while 63% named the head of IT.
When is Kertos the right choice for mid-sized companies, and when is it not?
Kertos fits mid-sized companies without an internal security role that want to implement NIS2 with a platform and certified experts. The experts are in-house at Kertos and can take on the external CISO mandate, which fills the missing internal role. The platform and the AI agent KAIA are developed and hosted in Europe. Alongside NIS2, Kertos covers ISO 27001, ISO 27701, ISO 42001, GDPR, SOC 2, TISAX, C5, and the EU AI Act from a shared evidence base.
Customers achieve a 100 percent audit pass rate and around 80 percent less manual compliance effort. AskUI achieved ISO 27001 certification with Kertos in 8 to 10 weeks without external consultants. Kertos is rated 4.8 out of 5 on G2 (as of October 2026).
"We also deeply appreciate the strong expert support: German-speaking and structured, with clear guidance milestones and regular check ins." Verified user, medical devices, small business, G2 review, December 2025.
A demo shows what implementation looks like for your scope.
Kertos is not the right choice if an experienced information security officer is already in place and only wants a documentation tool; an ISMS tool from the first model is enough then. The same applies if you must run the software on-premises or use BSI IT-Grundschutz as your leading standard.
Frequently asked questions about NIS2 software for mid-sized companies
From how many employees does NIS2 apply?
From 50 employees, if the company operates in an Annex I or II sector. Alternatively, an annual turnover and a balance sheet each above EUR 10 million are enough (Article 2(1) of the directive with Recommendation 2003/361/EC). Some entities are in scope regardless of size, such as trust service providers, DNS service providers, and top-level domain name registries. The exact thresholds and registration duties depend on the national law of the member state where you are established.
Does NIS2 apply to suppliers?
Not directly. A supplier is in scope only if it meets the sector and size conditions itself. Indirectly, NIS2 also reaches smaller suppliers: their regulated customers must manage supply chain security under Article 21(2)(d) and therefore often ask for evidence, such as completed security questionnaires, contractual commitments, or an ISO 27001 certificate.
What does NIS2 software cost for mid-sized companies?
Most vendors only quote prices on request. Software is only part of the cost anyway. Germany offers one public reference point: the German government estimates the total compliance burden at about EUR 75,000 one-time and EUR 78,000 per year per entity, as an average across roughly 29,500 entities. How these costs break down is set out on the page What does NIS2 cost?
Discover our Resources
Find useful whitepapers, videos, and practical tools to help you efficiently achieve your compliance goals.


