Skip to main content
NIS2 · Directive (EU) 2022/2555

NIS2 compliance software that works with you — local, no cloud.

From scoping check to reporting duty: the NIS2-Manager is NIS2 and ISMS software that covers the Article 21 risk-management measures, runs locally on Windows and keeps your sensitive compliance data in-house.

Local · no cloud requirement · subscription from EUR 499 per year net · business (B2B)

Updated: 8 September 2026

NIS2 (EU 2022/2555)

What applies

EU
Legal basisArt. 21 + national law
Reporting24h / 72h / 1 mo
Authority / CSIRTnational
Penalty (essential)up to 10M / 2%
Built on NIS2 / IR (EU) 2024/2690 ENISA TIG VdS 10100 · mapped to ISO/IEC 27001 Local · no cloud

The NIS2-Manager is built on VdS 10100, a German information security standard aligned with ISO/IEC 27001, and maps its measures to ISO/IEC 27001 controls. It is not a certification tool for ISO/IEC 27001.

Features

Everything for NIS2 in one tool

One purchase, every building block of the duty of care — no per-module fee.

Register

Processing and asset register

Your processes, systems and suppliers captured in a structured way — the basis the duty of care rests on.
Art. 21 · measures

Measures and risk assessment

The ten Article 21 measures with a risk matrix, each measure linked to the evidence that proves it.
Art. 23 · reporting

Report assistant 24h / 72h / 1 month

Generates the early warning and the incident notification to the national CSIRT within the statutory deadlines.
Export

Reports as DOCX and PDF

All registers and documents in an audit-ready layout — ready to hand to an authority or a customer.
Inside the NIS2 Manager

What you actually get

Screenshots from the English edition with the EU country pack, filled with sample data.

NIS2 Manager requirements catalogue with sidebar filters for status and obligation level, filtered to mandatory requirements, expanded chapters showing NIS 2 and legal references for each requirement.

Filtered, not just listed

Every measure from the Implementing Regulation sits behind a filter for status and obligation level, so you work the mandatory ones first.

Preview of a completed example document template (information security policy) with header data, change history and body text, plus buttons to edit and export the document.

Documents, not blank pages

A completed example policy shows the structure, the change history and the wording you adapt, rather than a blank template to start from.

NIS2 Manager project plan with an overall progress bar and a Gantt timeline across nine ISMS build-up phases plotted against calendar weeks.

Plan, not a guess

Nine phases laid out against calendar weeks turn the duty of care into a schedule your team can actually follow.

Data sovereignty

Local instead of cloud — your data stays yours

Your register, measures and risk assessments hold the most sensitive security information in your organisation. That does not belong in a third-party cloud database.

  • Runs locally on Windows, no cloud requirement and no data leaving your control
  • Network-capable: several staff work together on the same records
  • Local AI drafting help or optional Mistral EU — your choice
  • Back-up and export in your own hands at any time
What is inside

Not an empty framework, but a populated baseline

The NIS2-Manager ships with the full structure of the directive and ready-made templates, so you do not start from zero.

NIS2 requirements
161
fully mapped
Registers
32
pre-configured
Templates
85
documents and policies
Management system

ISMS software, not a compliance checkbox

The TSMONDO NIS2 Manager does not tick one obligation off a list — it runs an information security management system. Requirements, risks, evidence, suppliers and documents live in a single data set, and that same data set answers NIS2, ISO/IEC 27001, ISO 22301 and Article 32 GDPR at the same time. You maintain one status and generate eleven reports from it, among them the statement of applicability, two standards conformity reports and the annual management review. If you start today because the law requires it, you already have the structure in place should certification follow. The application runs locally on your own machine, with no cloud and no server account.

  • Compliance report — tells you in one figure how far you have come, and in one table which chapter is holding you back.
  • ISO/IEC 27001 conformity report — shows how much of your NIS2 work already counts towards ISO/IEC 27001:2022; the status is derived from a curated mapping and is subject to expert review.
  • ISO 22301 conformity report (BCM) — the same view for business continuity, with a gap list instead of a gut feeling, likewise subject to expert review.
  • Statement of applicability (SoA) — answers, for every requirement, whether it applies to you, how far it is implemented and which document proves it.
  • GDPR Art. 32 — technical and organisational measures conformity report — gives you the answer a supervisory authority asks for: which measures are actually in place.
  • Management review (combined annual review) — replaces the slide deck that otherwise gets assembled by hand once a year.
  • Documentation evidence per obligation — shows you before the audit where a piece of evidence is missing, rather than during it.
  • Emergency plan — puts reporting deadlines, contacts and recovery order on a single sheet for the day it matters.
  • Supplier report — turns a supplier self-assessment into a traceable score with history; it does not replace a full supplier audit.
  • Project progress report (ISMS implementation) — answers the board's question about when you will be finished, in phases rather than in optimism.
  • Management report — condenses completion rate, residual risks, deadlines and open actions into the pages leadership actually reads.

What the statement of applicability does

The statement of applicability is the list that records, for every single requirement, whether it applies to you, how far it is implemented and why — it is the document that lets an auditor grasp the full scope of your management system in a few pages, and the one you would otherwise have to assemble by hand from spreadsheets.

Trust

From a specialist, built on the official texts

Not a resold platform, but the practice of a single expert — with the credentials that go with it and a basis in the source text itself.

The maker

One point of contact with the right qualifications

  • ISO 27001 Lead Auditor and Lead Implementer
  • ISACA CISM (Certified Information Security Manager)
  • Certified data protection officer and IT security officer (TÜV)
  • Member of the Alliance for Cyber Security (BSI, Germany)
The basis

On the source, not on a summary

  • Built on Implementing Regulation (EU) 2024/2690
  • Aligned with the ENISA Technical Implementation Guidance
  • The 161 requirements come from the Annex of Implementing Regulation (EU) 2024/2690 itself
References

Organisations in industry, media, healthcare, the public sector and digital platforms work with TSMONDO — on security, NIS2 and data protection.

Hammelmann GmbH
DFMG Deutsche Funkturm
top agrar
Landlust
Rimondo (LV-Digital)
Wochenblatt
henworx
O-TON
Tadima
Flow (Gruner + Jahr)
baupool
AgriDirect

Data protection · datenschutzeinfach.com

adKOMM Software
Allergopharma
avodaq
Brielmaier Motormäher
COBERA
ConSecur
DRK Kliniken Berlin
Edelrid
Fritz Hartmann
Frischezentrum Essen
Georg-Eckert-Institut
Generis
genoBIT
GEOS Germany
Heinrichs Messtechnik
Holzindustrie Templin
HöV
HORIBA Europe
Deutsche Kautionskasse
KfH
KTE Karlsruhe
Magna International
Memory PC
Mercedes-Benz Tech Innovation
Mühlenkreiskliniken
Oxford PV
Salus
Stadt Füssen
TRAPO
Universität der Bundeswehr München

Named with permission. Full list at tsmondo.de/referenzen and datenschutzeinfach.com/referenzen.

Guarantees Licence per company · monthly or annual subscription Local · no data leaving your control 12 months of updates English interface · September 2026 release Made in Germany · EU support
/
Product walkthrough

The NIS2 Manager, step by step

From the cockpit to the supplier questionnaire: a guided tour of every function. Watch the narrated video, browse online, read the PDF or download the PowerPoint for your team.

Narrated walkthrough, 10 minutes

Or browse slide by slide

Slide 1 of 22: NIS2 Manager
1 / 22NIS2 Manager

Use the arrow keys once the viewer has focus. On a phone, swipe.

Pricing

One licence per company, staggered by size

The price is set by the number of employees at the licensed company — across every site, with unlimited users throughout your company and no extra charge per seat. A German GmbH & Co. KG counts as one company; subsidiaries and sister companies within a group each need their own licence. All prices are net, plus VAT where applicable; the reverse charge procedure applies for businesses in other EU member states with a valid VAT identification number.

−20% Launch offer

Launch offer until : 20% off the first year (annual plan) or the first three months (monthly plan). Enter code START20 at checkout — or apply the offer for an automatic discount.

Price band

Band 1 · up to 49 employees

EUR 49 net per month · or EUR 499 net per year

  • One licence for your whole company, every site, unlimited users
  • All program versions released during the term included
  • Annual plan: renews for twelve months, cancellable in text form with one month's notice to the end of the term
  • Monthly plan: renews every month, cancellable with effect from the end of the current month
Price band

Band 2 · 50-249 employees

EUR 99 net per month · or EUR 999 net per year

  • One licence for your whole company, every site, unlimited users
  • All program versions released during the term included
  • Annual plan: renews for twelve months, cancellable in text form with one month's notice to the end of the term
  • Monthly plan: renews every month, cancellable with effect from the end of the current month
Price band

Band 3 · 250-999 employees

EUR 199 net per month · or EUR 1,990 net per year

  • One licence for your whole company, every site, unlimited users
  • All program versions released during the term included
  • Annual plan: renews for twelve months, cancellable in text form with one month's notice to the end of the term
  • Monthly plan: renews every month, cancellable with effect from the end of the current month
Price band

Band 4 · 1,000-4,999 employees

EUR 299 net per month · or EUR 2,990 net per year

  • One licence for your whole company, every site, unlimited users
  • All program versions released during the term included
  • Annual plan: renews for twelve months, cancellable in text form with one month's notice to the end of the term
  • Monthly plan: renews every month, cancellable with effect from the end of the current month

5,000 employees or more: a tailored quote after a short call.

Request a quote
Try it first

Request the free demo by email

A portable ZIP for Windows, English interface — no account, no installation, nothing sent to us beyond the email below. The current full version and your licence key arrive by email once you buy a licence above.

Enter your email address — the download link arrives right away, along with appointment booking and the next steps.

This offer is addressed exclusively to businesses; there is no right of withdrawal. Payment runs through Stripe (SEPA direct debit or card) and the invoice arrives by email. Our terms and conditions apply.

Frequently asked

Short and concrete

Does the NIS2-Manager run locally or in the cloud?

Fully local on Windows. No cloud requirement, no data leaving your control.

Does the software cover the NIS2 duty of care?

Yes. The structure is built on Article 21 NIS2 and Implementing Regulation (EU) 2024/2690.

Does the report assistant support the incident notification?

Yes, with the 24-hour, 72-hour and one-month deadlines and the national reporting channels (CSIRT / authority).

What does it cost?

The price depends on the number of employees at the company: four bands at EUR 49, 99, 199 or 299 net per month, or EUR 499, 999, 1,990 or 2,990 net per year. From 5,000 employees, we provide a tailored quote.

What language is the software in?

The interface and all reports are in English (current release, September 2026). Sample data in some registers may still be in German.

Ready for NIS2

See the NIS2 software, or first determine free of charge whether your organisation falls under NIS2.

Further reading

Know where you stand first

The directive

NIS2 explained

What the directive requires, who is in scope and which deadlines apply — with the sources.
Thirteen questions, one per measure area, plus the NIS2 checklist as a PDF. Anonymous, in your own browser.
By country

National laws

The binding text is national: Netherlands, Austria, Belgium.
Consulting on NIS2 implementation: view of a monitor displaying the NIS2-Manager software with implementation roadmap and overview.

The developer behind NIS2-Manager

Thorsten Schmitz-Hübsch is founder of TSMONDO UG and developed NIS2-Manager himself. As an external CISO and information security officer, he currently guides several organizations through their NIS2 implementation based on ISO 27001. The software originates from this hands-on experience and real client mandates.