NIS2 compliance: software for SMEs, auditors & MSPs

"Top security startup" by Mastercard Strive
Lupasafe delivers compliance software for SMEs & organizations, auditors and IT providers to get NIS2 in order. Baseline clear for 12 of the 17 key controls within 60 minutes.
I am interested in NIS2 as
Organization
Your challenge
- Supply chain must be NIS2 compliant, you are part of it
- Management liability for non-compliance
- Incident reporting obligation (report within 24 hours to CSIRT).
- Complex and time-consuming to manage manually
Auditor
Your challenge
- Completing audits within time and budget
- Few staff, lots of work
- Data is everywhere and nowhere
MSP
Your challenge
- Not losing clients
- Lack of time to get clients and organization in order
- Lack of integrations and tools
"Excellent tool"
Insights

For organizations
NIS2 for your organization?
Why start with NIS2 now?
Deadline approaching (Q2 2026)
NIS2 becomes your 'license to operate'
Supply chain responsibility
Heavy penalties for non-compliance
Organizations must start implementation now to comply with customer and legal requirements on time
From baseline check to certificate
In two weeks the baseline is clear 'where do we stand' with Lupasafe
Step 1: Orientation & demo
Step 2: Quote & decision
Step 3: Implementation by IT
Step 4: In operation & insight into the NIS2 baseline
With the baseline check you know what still needs to be done.
Lupasafe solution
All tools ready for NIS2: Awareness, Technical
Continuous insight into progress towards certification
Smart integrations with Microsoft and Google save time and money
Our network of auditors helps you receive the certification quickly and easily.
Trusted by SMEs, healthcare and local governments
Solutions

Marco Wientjes
Zorggroep Solis
How does it work?
Insight into the NIS2 baseline within 60 minutes
Step 1: Onboarding (60 minutes)
Collect data for 12 of the 17 key controls:- Sign up on the platform
- Start AlwaysOn Elearning & Phishing
-
Connect Microsoft EntraID
- Deploy the software manually or automatically
-
Start network scanner
-
Activate 365 cloud audit
Step 2: Immediate value (day 1)
Dashboard shows 12/17 NIS2 controls. You see immediately: 'We have this under control'.
You have access to key control evidence, for example:- 1.6.2 ICT assets inventory
- 2.2 Education of directors and employees
- 2.6 Safe working from home
- 4.4 Malware prevention
Step 3: Continuously compliant
The 12 technical controls are continuously monitored. You see immediately which measures are active and where action is needed.
The team doesn't waste time searching and exporting - everything is continuously collected and updated.
You implement, we support
- Support on process, people and technology for your team
- Documentation and guides
- Advice on targeted phishing and awareness
Why Lupasafe?
Partner of Samen Digitaal Veilig (Dutch national platform). - 1000+ organizations / 60+ MSPs in the Netherlands
- 12/17 controls automated
- 60 minutes work - instead of weeks of manual work, measured by SMEs & MSPs
Mapped to ISO 27001
Samen Digitaal Veilig (Dutch national platform)'s framework is pragmatic and mapped to ISO 27001. Familiar structure, modern execution.
Data stored at Microsoft Azure Amsterdam
From €7.99 per user per month
Features
What does Lupasafe deliver for NIS2?
1. Organizational controls
1.3 Assignment of who is responsible for cybersecurity
1.6.1 Information inventory
1.6.2 ICT assets inventory
1.8 Return of company assets after use
1.14 Management of access rights
Technological controls
4.1 Security and management of user devices
4.4 Combating and preventing malware
4.7 Keep software on company assets up-to-date
4.10 Apply authentication methods
NIS2 Dashboard

Easily share access with team, IT providers and auditors
Autotask, Google & Microsoft integrations
The endpoints directly share data about for example laptop encryption, employee MFA and use of VPN software
2. Personnel controls
2.2 Education of directors and employees on digital security
2.6 Working from home or hybrid in a safe manner
3. Physical measures
3.9 Define access security
Frequently asked questions (FAQ)
What is NIS2?
NIS2 is European cybersecurity legislation that came into force on October 17, 2024. The legislation requires organizations to better manage digital risks and take cybersecurity seriously.Does NIS2 apply to my organization?
Your organization may fall under NIS2 directly or indirectly.NIS2 applies to companies with 50+ employees or €10 million+ revenue in essential sectors such as:
- Healthcare (hospitals, pharmacies, labs)
- Digital infrastructure (hosting, cloud, online platforms)
- Food production and distribution
- Manufacturing (chemicals, pharmaceutical industry)
- Wastewater and waste management
- Public administration
Smaller organizations in critical sectors may also fall under NIS2. Especially when they are suppliers in the above supply chain.
Self-assessment available here:
What does it mean if I fall within a NIS2 supply chain?
NIS2 legislation requires NIS2 entities (approximately 10,000 large organizations and companies) to carefully examine their risks – not only IT and network suppliers, but also suppliers of operational technology and physical systems.Read more at https://samendigitaalveilig.nl/nis2-ketenzorgplicht/
“Increasingly, companies work intensively with suppliers and service providers, both digitally and physically. NIS2 legislation requires NIS2 entities (approximately 10,000 large organizations and companies) to carefully examine their risks – not only IT and network suppliers, but also suppliers of operational technology and physical systems.
This means that 50,000 companies (the suppliers) will be assessed for risk. This will set in motion a large wave of certification requests. After all, it is a requirement of the NIS2 cybersecurity law. Companies will then have to prove to their customers that they have their cybersecurity in order.
To prevent this problem from escalating into requirements for overly heavy and unattainable standards, industry associations have further developed Samen Digitaal Veilig (Dutch national platform) and there is collaboration with the NIS2 certification framework. A very good and especially achievable certification.”
How does Lupasafe help?
Lupasafe offers a complete compliance platform for NIS2 with awareness training, phishing simulations and reports that demonstrate you comply with the law.With Lupasafe you perform the baseline scan yourself or through your auditor or MSP: you then see exactly what is already in order and what is still missing. Your MSP helps to get the technical matters in order, such as safe working from home or backup. Your auditor determines whether you meet the requirements and certifies you according to the certification framework, for example.
What can we provide as evidence for the key controls?
12 of the 17 controls.Lupasafe delivers 12 of the 17 key controls. You must deliver the other 5 yourself or with IT. This includes, for example, the backup procedure or the information security policy.
See the list here: https://lupasafe.com/auditors/
What do we need to set up once for this?
Connect EntraID & endpoint deploymentPeople & Roles:
- Assign which users in the Employee list are management, IT manager and data privacy officer
- Inform client contact person
- Activate AlwaysOn Elearning
- Schedule year-long phishing
Technical:
- Connect EntraID
- Deploy endpoints: install endpoint on workstations via Intune (20 min work)
- Install network scanner per office location (10 minutes per office or care location)
- Start 365 cloud audit (1 minute)
What do we need to maintain monthly for this and how much time does it take?
Management tasks such as checking scanner and handling user questions, renewing EntraID consent - max 15 minutesWhich package do we need from Lupasafe for this?
AWARENESS contains 1 key control 2.2 "Education of directors", PRO contains the 12 controlsSee feature comparison at https://lupasafe.com/nieuws/welk-niveau-van-cyberbeveiligingsmonitoring-heeft-u-nodig/
Leaders choose Lupasafe
What IT leaders and MSPs say
Gert de Fluiter
Partner Schuiteman Accountants and Advisors
F.S.
IT Director Sobell Rhodos
NIS2
Compliant
Evidence
Compliance and monitoring
Ruben Schevers
IT Manager Hendriks Group
Juryry Bouterse
IT Administrator, Total Packaging
Marc Paus
CISO Mobile World Congress
Pieter Willemsen
CEO, Hupra ICT
100%
Recommend Lupasafe
5/5 Gartner rating
Jelle Witteveen
Technical Director, Motivo
Rick van den Hoorn
STH Automatisering
Recent NIS2 articles

NIS2 and Cyber Fundamentals in Ireland: What MSPs and SMEs Need to Do
As Ireland prepares for NIS2 Directive, many SMEs and Managed Service Providers (MSPs) are asking the same question: “Does this affect…
What is DMARC? How to protect your business email from criminals
Last month, a notary office in Birmingham received an angry phone call from a client. The client had transferred €25,000…
Why members of INAA choose a different approach to cybersecurity
INAA (International Network of Accountants and Advisors) is a global alliance of independent accounting and advisory firms. Lupasafe and INAA…
How can dark web scanning help our cyber risk management for our data?
The recent implementation of the NIS2 directive has changed the rules for management boards EU-wide. As a director, you are…
What small businesses can learn from NIS2: cybersecurity as a competitive advantage
As a small business owner, you might think: "NIS2? That's for big enterprises, right?" Technically, yes - the NIS2 directive…
For directors and managers in SMEs and healthcare who must be NIS2 compliant due to chain responsibility
As the director of an SME or healthcare institution, you'll be faced with NIS2 compliance—often not because your organization itself…






