Kaamos

Framework reference

NIS2 for EU B2B software companies.

NIS2 applies to many EU digital, ICT, financial, healthcare, infrastructure, and public-sector organizations once size and sector thresholds are met. For B2B software companies, it usually matters when the company serves regulated sectors, reaches 50+ employees, or becomes part of critical customer supply chains.

Kaamos support
Supported in Kaamos
Category
Binding EU regulations
Obligation
Binding
Last updated

The obligation, in the act's words

Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems…

Article 21(1), Directive (EU) 2022/2555 (NIS2)

The measures have to be proportionate to the risk in the systems you run, which is a judgement you can only defend from an inventory of what you actually have.

Who it applies to

  • EU digital providers, ICT service management providers, and critical-sector suppliers.
  • Important entities at 50+ employees or EUR 10M+ turnover, depending on sector.
  • Companies pulled into customer supply-chain requirements even before direct legal applicability.

What you need to do

  • Risk management, incident handling, business continuity, supply-chain security, and management accountability.
  • Security governance that can be shown to customers, auditors, and national authorities.
  • Evidence that controls are current, not just documented once.

How Kaamos helps

  • Maps NIS2 work to assets, vendors, risks, and live control evidence.
  • Turns customer pressure into a prioritized roadmap instead of a spreadsheet.
  • Keeps management-facing risk and compliance status current.

Sources

Company profiles this applies to

Supported in Kaamos

Manage NIS2 controls, owners and evidence in Kaamos. Talk to us about the framework scope and connected systems you need.