Predefined NIS2 framework, in layers
A base package built on the Article 21 measures, with NIS2-loven, the energy order (bek. 260), CER and telecoms security activated alongside for the rules that apply to you.
Most teams already do the security work for ISO 27001. Switch NIS2 on in .legal and see how much of it you've already done, then close the gap on the rules that actually apply to your sector.
Unlimited users • Free onboarding and support • No commitment
Anders Krogh is CISO at Meridian Nordic. As an energy company they're an NIS2 essential entity, and they already run an ISO 27001-certified ISMS in .legal with good progress behind them. When NIS2 landed, Anders didn't start a new project. He switched on the NIS2 framework for energy, and .legal showed him he was already about 80% of the way there, purely from the evidence the ISO work had produced. From there it was a matter of seeing the gap and closing it, not building everything again.
A running head start
Switch NIS2 on and the ISO 27001 evidence you've already collected counts straight away.
The directive plus your sector
A base NIS2 package, plus the national and sector rules that actually apply to you.
One place for the work
Assets, vendors, risks, policies and controls sit in a single platform, not five tools.
A status you can show
Live progress per framework, so you give the board a real answer instead of a guess.
This is how most teams actually work, so it's how .legal works too. The base NIS2 package is built on the Article 21 measures, which line up closely with ISO 27001. Do the security work once, and the platform shows you the NIS2 payoff as you go.
The EU directive is only half the picture. What you actually have to meet is the national and sector rules on top of it, and that's exactly where teams lose the overview.
Knowing you "have to do NIS2" isn't the same as knowing what to do. The controls give you both the plan and the overview, so the work stops being a vague worry.
A big organisation means a lot to keep track of: many assets, many suppliers, a lot of moving parts. NIS2 wants them mapped and assessed, and in .legal that happens next to the controls, not in a separate spreadsheet.
Management gets asked about NIS2 too, and they can be held accountable, so the pressure lands on you. It's a lot easier when the status is real and always to hand.
.legal stands up the frameworks, the controls and the tools so the whole picture is easy to see and act on. It doesn't decide your compliance for you.
A base package built on the Article 21 measures, with NIS2-loven, the energy order (bek. 260), CER and telecoms security activated alongside for the rules that apply to you.
Activate NIS2 and a simulated score shows how far your ISO 27001 evidence already takes you, before you do anything new.
Map the critical assets and the suppliers NIS2 puts in scope, in the same place as the controls they feed.
Assess assets, processes and vendors against NIS2's expectations, starting from what you've mapped rather than a blank template.
Hold your IT-security and cyber policies, and log incidents, against the controls that require them.
Reach every colleague with training and knowledge checks on the audit engine, and prove they completed it.
The directive, the national rules, and the ISO work they build on.
NIS2
A base package on the directive's Article 21 measures, with the Danish national and sector rules (NIS2-loven, the energy order, CER, telecoms security) activated alongside.
ISO 27001
The Annex A controls the base NIS2 package builds on, predefined and mapped to the same evidence, so the ISO work you've done shows up as NIS2 readiness.
Run your ISMS, meet NIS2 and ISO 27001, and see your readiness across both from one shared set of evidence.
Explore Information Security ManagementMap and assess the suppliers NIS2 puts in scope, and run awareness training on the audit engine.
Explore Vendor ManagementRun several frameworks side by side — the NIS2 directive, ISO 27001 and NIS2 – Energy — each keeping its own structure over one shared set of evidence.
Explore Frameworkscompanies
users
contracts
processing activities
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Yes, a lot. The base NIS2 package is built on the Article 21 measures, which overlap heavily with ISO 27001. Switch NIS2 on and a simulated score shows how far your ISO evidence already gets you, before you do anything new.
What ISO 27001 certification involvesYes. A base package mirrors the directive for broad EU coverage, and you activate the Danish frameworks alongside it: NIS2-loven, the energy executive order (bekendtgørelse 260), CER and the telecoms security act. Other national frameworks can be added on request.
What the CER directive coversEvery framework shares one catalogue of evidence tasks. The platform looks at the documentation you've collected for ISO 27001 and shows what it already satisfies in NIS2, even before you've actively worked on it.
No. It stands up the frameworks and controls so you can see them clearly, and it lets you activate the national and sector rules that fit you, but the scoping decision stays yours. It doesn't interpret the law for you.
Yes. You map your critical assets, processes and vendors, then assess their risk in a NIS2 context, starting from what you've mapped rather than a blank template. The risk work links back to the controls and the evidence.
How risk assessment works in ISO 27001Both sit in the same platform. You map and assess the suppliers NIS2 puts in scope, and you run awareness training and knowledge checks on the audit engine, so you can prove your people are on board.
What supply-chain security requiresYes. The evidence is shared underneath, but each framework keeps its own structure, so you present an ISO 27001 audit in ISO's terms and show NIS2 in NIS2's.
What an internal ISO 27001 audit coversNo. It gives you the rails: the frameworks, the mapping, and the tools to map assets, assess risk and collect evidence. You still decide your scope and write your own documentation.
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.