NIS2 readiness Get NIS2-ready without starting from scratch

Most teams already do the security work for ISO 27001. Switch NIS2 on in .legal and see how much of it you've already done, then close the gap on the rules that actually apply to your sector.

Unlimited users  •  Free onboarding and support  •  No commitment

Illustration of a completed security document on a violet platform, with a rail sweeping up to a progress column filled about two thirds of the way and two empty columns waiting behind it
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell
The NIS2 – Energy (BEK 260/2025) framework in .legal, showing 46 of 50 tasks completed at 92% progress, above a control list with each control's coordinator and status

NIS2 readiness Meridian was 80% of the way to NIS2 before they'd touched it

Anders Krogh is CISO at Meridian Nordic. As an energy company they're an NIS2 essential entity, and they already run an ISO 27001-certified ISMS in .legal with good progress behind them. When NIS2 landed, Anders didn't start a new project. He switched on the NIS2 framework for energy, and .legal showed him he was already about 80% of the way there, purely from the evidence the ISO work had produced. From there it was a matter of seeing the gap and closing it, not building everything again.

  • Turning NIS2 on showed a ~80% head start, straight from the ISO 27001 evidence.
  • One clear view of what NIS2 asks of an energy company, and what's still open.
  • Assets, vendors, risks and policies live in the same platform as the controls.
  • A real status to give the board, in a click, instead of a guess.

  • A running head start

    Switch NIS2 on and the ISO 27001 evidence you've already collected counts straight away.

  • The directive plus your sector

    A base NIS2 package, plus the national and sector rules that actually apply to you.

  • One place for the work

    Assets, vendors, risks, policies and controls sit in a single platform, not five tools.

  • A status you can show

    Live progress per framework, so you give the board a real answer instead of a guess.

NIS2 isn't a fresh mountain to climb. For most teams it's mostly the security work you're already doing, seen through the lens of a new set of rules.

The framework library in .legal, where CER, DORA, NIS2-loven, the telecoms security act and the energy sector orders each show a simulated readiness percentage before the framework has been added

NIS2 readiness Start from ISO 27001, see the NIS2 head start

This is how most teams actually work, so it's how .legal works too. The base NIS2 package is built on the Article 21 measures, which line up closely with ISO 27001. Do the security work once, and the platform shows you the NIS2 payoff as you go.

  • NIS2's base controls sit on the same ground as your ISO 27001 controls.
  • A simulated score shows your NIS2 readiness before you even switch it on.
  • The evidence you've already collected for ISO counts towards NIS2 straight away.
The Choose framework dialogue in .legal filtered to NIS2, with the NIS2 Directive alongside NIS2-loven, the telecoms security act and NIS2 – Energy (BEK 260/2025), each ready to add

NIS2 readiness The directive, plus the rules for your sector

The EU directive is only half the picture. What you actually have to meet is the national and sector rules on top of it, and that's exactly where teams lose the overview.

  • A base package mirrors the NIS2 directive, so it fits broadly across the EU.
  • Activate the rules that apply to you: NIS2-loven, the energy order (bek. 260), CER, telecoms security.
  • See the gap between the directive and the specific requirements for your sector.
The NIS2 Directive control list in .legal, with each article-level control, its category, task count and control coordinator

NIS2 readiness A clear plan, not just an obligation

Knowing you "have to do NIS2" isn't the same as knowing what to do. The controls give you both the plan and the overview, so the work stops being a vague worry.

  • Every control comes predefined, 1:1 with the standard, so you start from real requirements.
  • Controls drive the plan and the overview: what's done, what's owed, and by whom.
  • No more guessing whether "risk-management measures" means you're actually finished.
Illustration of a central violet control tile linked out to a cluster of asset blocks, a group of supplier figures and a row of risk chips, all mapped into one place

NIS2 readiness Map the assets, vendors and risks NIS2 cares about

A big organisation means a lot to keep track of: many assets, many suppliers, a lot of moving parts. NIS2 wants them mapped and assessed, and in .legal that happens next to the controls, not in a separate spreadsheet.

  • Map the critical assets and the suppliers NIS2 brings into scope.
  • Assess the risk of assets, processes and vendors in an actual NIS2 context.
  • Supply-chain security sits beside the controls it feeds, not off in another tool.
Illustration of a status panel showing a circular progress dial and three summary rows, connected by a line to a single figure standing beside it

NIS2 readiness Give the board a straight answer

Management gets asked about NIS2 too, and they can be held accountable, so the pressure lands on you. It's a lot easier when the status is real and always to hand.

  • Live progress per framework, so "how far are we?" has an actual answer.
  • Show what's done, what's outstanding and who owns it, without a scramble.
  • The same view works for the board and for an auditor.
Illustration of two empty rails with a violet guide stripe, one card already marked with a check and a figure placing the next card onto the track

NIS2 readiness Rails, not the roadmap

.legal stands up the frameworks, the controls and the tools so the whole picture is easy to see and act on. It doesn't decide your compliance for you.

  • You choose whether you're in scope and which rules apply, we don't read the law for you.
  • You map, assess and document; we give the work somewhere to live and a way to reuse it.
  • The score comes from the evidence you actually collect, nothing is compliant by magic.
.legal in practice

Features for NIS2 readiness

Predefined NIS2 framework, in layers

A base package built on the Article 21 measures, with NIS2-loven, the energy order (bek. 260), CER and telecoms security activated alongside for the rules that apply to you.

Simulated NIS2 readiness from ISO work

Activate NIS2 and a simulated score shows how far your ISO 27001 evidence already takes you, before you do anything new.

Asset and supplier mapping

Map the critical assets and the suppliers NIS2 puts in scope, in the same place as the controls they feed.

Risk assessment in a NIS2 context

Assess assets, processes and vendors against NIS2's expectations, starting from what you've mapped rather than a blank template.

Policies and an incident register

Hold your IT-security and cyber policies, and log incidents, against the controls that require them.

Awareness on the same rails

Reach every colleague with training and knowledge checks on the audit engine, and prove they completed it.

NIS2 readiness Frameworks this covers

The directive, the national rules, and the ISO work they build on.

  • icon-framework-NIS2

    NIS2

    A base package on the directive's Article 21 measures, with the Danish national and sector rules (NIS2-loven, the energy order, CER, telecoms security) activated alongside.

    Learn about NIS2
  • icon-framework-ISO

    ISO 27001

    The Annex A controls the base NIS2 package builds on, predefined and mapped to the same evidence, so the ISO work you've done shows up as NIS2 readiness.

    Learn about ISO 27001
.legal compliance platform

Get NIS2-ready with...

Do you need to get NIS2-ready? We recommend the following modules and addons for that task.

Vendor Management

Map and assess the suppliers NIS2 puts in scope, and run awareness training on the audit engine.

Explore Vendor Management

Frameworks

Run several frameworks side by side — the NIS2 directive, ISO 27001 and NIS2 – Energy — each keeping its own structure over one shared set of evidence.

Explore Frameworks

Our Customers

+400

companies

+10.000

users

+79.000

contracts

+14.000

processing activities

Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
Bech Bruun

Bech-Bruun

Mikkel Friis Rossa (Partner)

.legal's team has consistently demonstrated a commitment to innovation while being responsive to the needs of our mutual clients.

Rasmus-boutrup-fenerum

Fenerum

Rasmus Boutrup (Financial Controller)

Case Study
With .legal, we've gained a simpler and more manageable solution that better suits our needs
Michael Berner 1

Lægeforeningen

Michael Berner (Lawyer)

.legal has been the right choice for us. .legal are professional and welcoming with skilled employees.
Nanna Rodian Christensen

Molecule Consultancy

Nanna Rodian Christensen (HR & Operational Manager)

Case Study
Firstly, it means that not all the work is in one place (me), and secondly, that the understanding of GDPR is implemented throughout the organisation.
ulrikdueholmbeckmann

Plum Safety

Ulrik Dueholm Beckmann (QC, CM og ESG Lead)

Case Study
From .legal, we experience an incredibly high degree of flexibility and willingness to adapt features to our local needs.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.
julie-oxenvad-novicell

Novicell

Julie Oxenvad (Legal Consultant)

Case Study
We are satisfied with the switch to .legal – it has strengthened our compliance work, made processes easier to manage and more transparent, and improved cross-team collaboration
Tinna Schultz

Min By Media

Tinna Schultz (HR Manager)

Case Study
It just works! It is so easy and user-friendly, and the overview of processing activities is brilliant.
ansat_Kaspar_Rochholz_005

DMJX

Kaspar Rochholz (GDPR Coordinator)

Case Study
.legal has really understood what it means to create a user-friendly and efficient solution. Privacy is an attractive product compared to price and functionality.
Profile-picture1

Axel Kaufmann ApS

Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)

Case Study
.legal continuously update the platform to ensure their customers always remain compliant. In our view, any other choice would be a downgrade.

NRGi

Mette Mühlendorph (Compliance Specialist)

Case Study
The implementation of .legal has made a difference in the way we handle compliance. The system has created structure and overview, which has had concrete benefits.

Frequently Asked Questions about NIS2 readiness

We already work with ISO 27001. Does that help with NIS2?

Yes, a lot. The base NIS2 package is built on the Article 21 measures, which overlap heavily with ISO 27001. Switch NIS2 on and a simulated score shows how far your ISO evidence already gets you, before you do anything new.

What ISO 27001 certification involves

Does .legal cover the Danish NIS2 rules, not just the EU directive?

Yes. A base package mirrors the directive for broad EU coverage, and you activate the Danish frameworks alongside it: NIS2-loven, the energy executive order (bekendtgørelse 260), CER and the telecoms security act. Other national frameworks can be added on request.

What the CER directive covers

How does the simulated score work?

Every framework shares one catalogue of evidence tasks. The platform looks at the documentation you've collected for ISO 27001 and shows what it already satisfies in NIS2, even before you've actively worked on it.

Does the platform tell us whether we're in scope, or which requirements apply?

No. It stands up the frameworks and controls so you can see them clearly, and it lets you activate the national and sector rules that fit you, but the scoping decision stays yours. It doesn't interpret the law for you.

Can it help with the risk assessments NIS2 expects?

Yes. You map your critical assets, processes and vendors, then assess their risk in a NIS2 context, starting from what you've mapped rather than a blank template. The risk work links back to the controls and the evidence.

How risk assessment works in ISO 27001

What about supply-chain security and getting colleagues trained?

Both sit in the same platform. You map and assess the suppliers NIS2 puts in scope, and you run awareness training and knowledge checks on the audit engine, so you can prove your people are on board.

What supply-chain security requires

Does NIS2 in .legal keep our ISO 27001 certification separate for the auditor?

Yes. The evidence is shared underneath, but each framework keeps its own structure, so you present an ISO 27001 audit in ISO's terms and show NIS2 in NIS2's.

What an internal ISO 27001 audit covers

Does .legal write our documentation or make us compliant on its own?

No. It gives you the rails: the frameworks, the mapping, and the tools to map assets, assess risk and collect evidence. You still decide your scope and write your own documentation.

Still unsure?

Ask Johannes directly, he runs most demos personally

Book him here
+400 companies use .legal
Region Sjælland
Aarhus Universitet
aj_vaccines_logo
Realdania
Right People
IO Gates
PLO
Finans Danmark
geia-food
Evida
Klasselotteriet
NRGI1
BLUE WATER SHIPPING
Karnov
Ingvard Christensen
VP Securities
AH Industries
Lægeforeningen
InMobile
AK Nygart
DEIF
DMJX
Axel logo
qUINT Logo
KAUFMANN (1)
SMILfonden-logo
kurhotel_skodsborg
nemlig.com
Molecule Consultancy
Novicell