“Real compliance powerhouse”
Kertos quickly and precisely guided us through the GDPR and ISO27001 certification compliance jungle. The Kertos platform was easy to implement and is a real compliance powerhouse due to the high level of automation.
<h1 class="heading-style-h1"><span class="text-color-secondary">NIS2</span> - Prepare now</h1>
Ensure your organization's cybersecurity resilience with Kertos' comprehensive NIS2 framework solutions. Designed to align with European Union standards, our platform simplifies compliance and strengthens your security posture. Achieve seamless integration and robust protection with our user-friendly, automated tools tailored for critical infrastructure sectors.



<h2 class="heading-style-h2">The<span class="text-color-secondary"> all-in-one solution</span> for NIS2</h2>
With Kertos, you put the development of your ISMS on autopilot.
An information security management system (ISMS) in accordance with ISO 27001 already covers up to 70% of the requirements of the NIS2 Directive. With Kertos, you can set up your ISMS quickly and efficiently so that you can easily achieve the required security standards.
Quick and efficient ISMS set-up
Optimized security measures, active risk management
all-in-one platform

Get professional support in setting up and maintaining your ISMS as well as continuous support. Whether before, during or after the audit — we will guide you step by step and ensure that you meet all requirements safely and efficiently.
Experienced ISO 27001 experts at your side
Personal assistance in setting up and maintaining the ISMS
Continuous support for efficient fulfillment of all requirements














.avif)












.avif)


Compliance that convinces: Whether B2C, B2B, startup, or scaleup, Kertos is the right solution for companies looking to grow quickly.
<h2 class="heading-style-h2">Ready to set up your ISMS within a few <span class="text-color-secondary">weeks?</span></h2>

Find useful whitepapers, videos, and practical tools that help you efficiently achieve your compliance goals.
Information about the Kertos compliance platform
Our platform automates up to 60% of the workflows required for ISO 27001 certification. It provides you with tools for creating policies, risk management, and asset discovery, which significantly speeds up and simplifies the certification process.
An ISO 27001-certified ISMS already covers a large part of the NIS2 requirements and provides a solid basis for implementing further specific measures required by the NIS2 Directive.
Article 34 sets floors for national maxima, not EU-wide caps. Member states must provide for a maximum of at least €10 million or 2 % of total worldwide annual turnover for essential entities, and at least €7 million or 1.4 % for important entities, whichever is higher in each case. Turnover is measured at group level for the preceding financial year. Fines are triggered by breaches of Article 21 or Article 23. Because these are minima, national law can go further and can structure the amounts differently: Germany's § 65 BSIG sets fixed amounts, applies the percentage caps only above €500 million group turnover, and caps a breach of the registration duty at €500,000.
The directive entered into force on 16 January 2023 and member states had to transpose it by 17 October 2024. Most missed that deadline, so the date that matters is the national one. In Germany, the NIS2-Umsetzungsgesetz was promulgated on 5 December 2025 and the BSIG has applied since 6 December 2025 with no transition period, which made the registration deadline 6 March 2026. Ireland, Spain, France, and the Netherlands had still not transposed when the Commission referred them to the Court of Justice of the European Union on 8 July 2026.
No. NIS2 creates no certificate of its own. Article 24 only allows member states to require that certain ICT products, ICT services, and ICT processes be certified under European cybersecurity certification schemes adopted pursuant to Article 49 of Regulation (EU) 2019/881. Compliance is demonstrated to the competent authority, not through a certificate. An ISO 27001 certificate is strong evidence for the risk-management measures in Article 21, but it does not replace registration with the national authority, the reporting duties under Article 23, or the governance and training duties on management bodies under Article 20.
Our team is happy to assist you with any questions regarding our platform, different frameworks, and your compliance.