NIS2 compliance without spreadsheets — Lupasafe maps your evidence automatically
Lupasafe is a European cybersecurity platform that generates your NIS2 compliance evidence automatically — from phishing simulations, e-learning, vulnerability scanning, Microsoft 365 audit and DMARC reporting. Maps to the key NIS2 controls (Annex I & II of Directive (EU) 2022/2555) and ISO 27001 Annex A. Trusted by 600+ organisations across Europe, from €7.99 per user per month. Take the free NIS2 quick scan at lupasafe.com/en/nis2-scan/ or book a demo at lupasafe.com/en/book-a-demo/.
Trusted by 600+ organisations • Gartner Peer Insights ★★★★★ 5.0
Trusted by 600+ organisations

★★★★★5.0
What is NIS2?
The NIS2 Directive (Network and Information Security Directive) is European legislation that requires organisations to take appropriate measures to secure their network and information systems. It introduces a duty of care, incident reporting obligations and supply chain security requirements.
NIS2 applies to essential and important entities across multiple sectors — including many SMEs that are part of critical supply chains. Compliance requires demonstrable measures across people, technology and processes. Lupasafe automates the evidence collection and reporting.
Key NIS2 controls (Annex I & II): your compliance framework
The key NIS2 controls (Annex I & II of Directive (EU) 2022/2555) provide a structured framework for compliance. They cover the essential security measures organisations must implement — from access control and vulnerability management to incident response and business continuity.
Lupasafe maps its 8 security modules directly to these control areas. Every scan, test and training session generates evidence that feeds into your compliance dashboard — so you can demonstrate compliance without manual effort.
Control areas Lupasafe covers
Security awareness & training
Phishing simulations + e-learning with completion tracking
Access control & authentication
MFA status, admin rights review, leaked credential monitoring
Vulnerability management
Domain scanning, CVE/CVSS/EPSS, endpoint compliance
Network security
Port scanning, SSL/TLS assessment, security headers
Email security
DMARC, DKIM and SPF monitoring and reporting
Endpoint protection
Antivirus active, disk encryption, OS updates, admin rights
Cloud security
Microsoft 365 Secure Score, mailbox rules, admin review
Policy & documentation
BCP, backup policy, remote work policy, incident response plan
Incident response
Breach alerting, dark web monitoring, response documentation
Supply chain security
Shareable compliance reports for clients and partners
“I can continuously monitor the team, the devices and the security.”
IT Director, Sobell Rhodes
Your NIS2 compliance status at a glance
All key NIS2 controls (Annex I & II) in one dashboard. Automatically populated by 8 security modules. Export compliance reports for auditors with one click.

Every scan, test and training session feeds into your compliance dashboard. Share with auditors, management or clients. One source of truth for NIS2 and ISO 27001 Annex A.
Three pillars that feed your compliance dashboard
Every module delivers immediate insight. All results flow automatically into your NIS2 reporting.
People
Know who is vulnerable — and make them more resilient.
40% of employees enter credentials at the first phishing test. Continuous training and testing reduces it measurably over time.
- Phishing simulations — email, QR code, credential harvest
- E-learning — role-specific, NIS2 functions, annual planning
- Dark web monitoring — 20 billion+ leaked records
Technology
Discover vulnerabilities before an attacker does.
Your attack surface changes continuously. Lupasafe scans your domains, endpoints, network and cloud — automatically, weekly.
- Endpoint compliance — Windows, macOS, Linux, CVE matching
- Microsoft 365 audit — Secure Score, MFA status
- Domain scanning — ports, SSL, security headers
- DMARC — prevent email spoofing
Compliance
Prove you comply — without spreadsheets.
All scan and training results flow automatically into your NIS2 compliance dashboard. NIS2 controls (Annex I & II) and ISO 27001 Annex A — in one place.
- NIS2 — key controls (Annex I & II) with evidence
- ISO 27001 — Annex A mapping
- ISO 27001 Annex A — international standard mapping
- Policy documents — BCP, backup, remote work
You are here
Two compliance frameworks, one dashboard
Lupasafe maps your security results to both frameworks simultaneously. Whether your client maps evidence to the key NIS2 controls (Annex I & II of Directive (EU) 2022/2555) or ISO 27001 Annex A — you have the evidence ready.
Key NIS2 controls (Annex I & II)
The compliance framework under Directive (EU) 2022/2555 covering all essential security measures. Lupasafe maps directly to the control areas with automated evidence.
ISO 27001 Annex A
The international information security standard. Lupasafe maps scan and training results to relevant Annex A controls for audit preparation.
Read more
Security Awareness Training
NIS2 requires all employees and directors to receive cybersecurity training. Start building evidence now.
Read more →
Phishing Simulation Testing
40% of employees fail the first test. Measure and reduce your organisation's phishing risk.
Read more →
Domain & IP Scanning
CVE, CVSS 3.0 and EPSS scoring for your domains, ports and email security.
Read more →
Start your NIS2 compliance journey today
Free 30-day evaluation. See which key NIS2 controls (Annex I & II) you already meet — and where the gaps are. No hardware, no installation.
Trusted by 600+ organisations
Frequently asked questions
Does my organisation need to comply with NIS2?
The NIS2 Directive applies to essential and important entities across multiple sectors. Even if your organisation is not directly in scope, you may be required to demonstrate compliance as part of a larger organisation's supply chain. Any SME or organisation working with NIS2-regulated clients should be prepared.
What are the key NIS2 controls Lupasafe maps to?
Lupasafe maps to the key NIS2 controls under Annex I & II of Directive (EU) 2022/2555 and Article 21 risk-management measures. These cover access control, vulnerability management, email security, endpoint protection, security awareness, incident response and business continuity. Lupasafe maps its 8 modules directly to these control areas.
How does Lupasafe help with NIS2 compliance?
Lupasafe automates evidence collection for NIS2 compliance. Every phishing simulation, training session, vulnerability scan and policy check generates compliance evidence that feeds into your dashboard. Export reports for auditors in one click. No spreadsheets, no manual tracking.
How does Lupasafe support ISO 27001 alongside NIS2?
Every scan, training session and policy event is mapped to both the key NIS2 controls (Annex I & II of Directive (EU) 2022/2555) and ISO 27001 Annex A. Auditors get a single dashboard view for both frameworks — one source of truth, two compliance outputs.