Gap analysis
One question per card
Mandatory requirements first. To go deeper, switch to the detail view with maturity and evidence.

As of Oct 2026Compliance tool for mid-sized companies and public bodies
NIS2 and ISO 27001 – guided, clear and free of spreadsheet chaos. Plus the EU AI Act, ISO 42001 and the Cyber Resilience Act.
910assessable requirements in five frameworks
910 → 227
Many requirements in NIS2, ISO 27001, ISO 42001, the AI Act and the CRA mean the same thing – access control, incident handling or supplier assessment, for example.
227 shared control points connect 454 equivalent requirements across framework boundaries.
One answer counts automatically in every framework that uses the same control point. If it applies to several frameworks, the weakest implementation prevails in case of doubt.
227 → 1
Overall status, trend and exactly the points that need attention now – overdue measures, due reports, open obligations. Made for management.
59%
Weighted implementation status per framework in the demo tenant
Demo tenant “Nordwerk Energie GmbH”, fictitious data.
The path
UniqSuite guides you through six phases from scope to audit, assesses each requirement only once and produces the reports management and auditors expect.
Screenshots: demo tenant “Nordwerk Energie GmbH” with fictitious data.
Company and sector, package, size – ready in three questions. Plus people and the frameworks that apply to you.
Result: Scope report

Services, assets and their dependencies in one place – the foundation for gap analysis and risks.
Result: Inventory

One requirement per card, mandatory requirements first. Answer with one click; “not applicable” only with a justification.
Result: Implementation status per framework

Derive risks from gaps, assess them and treat them.
Result: Risk report (PDF, Word, Excel)

A Statement of Applicability and one list of measures with owners, deadlines and status. Every step forward flows automatically into the dashboard and reports.
Result: SoA, implementation and board report

Findings, corrective actions and their follow-up – so the cycle closes.
Result: Audit report

How it feels
Gap analysis
Mandatory requirements first. To go deeper, switch to the detail view with maturity and evidence.

Management dashboard
Overall status, trend and the points that need attention now.

Incident management
Record an incident once. UniqSuite derives the reporting duties of your frameworks and starts the deadline timers.

Plan & implementation
One list of measures with owners, deadlines and status.

Supplier check
Criticality, controls, risk score and review cycle for each supplier.

Policies
Templates linked to the requirements.

AI governance
An AI system register, risk classification under the EU AI Act and the mandatory documents for each role and class.

Statement of Applicability, board, risk and implementation reports as PDF, Word or Excel – at the push of a button.
Why now
Germany’s NIS2 Implementation Act has applied since 6 December 2025 – with no general transition period. At the same time, the EU AI Act and Cyber Resilience Act deadlines are kicking in.
24 hEarly warningfrom awareness
72 hNotification with initial assessmentfrom awareness
1 monthFinal reportafter the notification
Record an incident once – UniqSuite derives the reporting duties and starts the deadline timers.
New BSI Act with obligations for essential and important entities.
Three months after entry into force (Section 33 BSIG). Latecomers should register without delay.
Art. 50 applies. Prohibitions and AI literacy have applied since February 2025.
Manufacturers report actively exploited vulnerabilities and severe incidents (Art. 14).
Postponed by Regulation (EU) 2026/1744.
Products with digital elements only with CRA-compliant CE marking.
Obligations for high-risk AI under Annex I.
Source: white paper “Implementing NIS2 and ISO 27001 pragmatically”, as of October 2026.
One tool, five frameworks
Assessable requirements per catalogue. Choose a framework – the quick check begins.
Quick check
Eleven to thirteen short questions per framework. Answer Yes, Partly or No – as honestly as you can.
Your answers never leave your browser. No transfer, no storage, no tracking.
Trust
Row-level access rules keep every organisation’s data apart.
Can be made mandatory for administrators.
With 14-day retention.
Assessments and metrics follow fixed, traceable rules – no AI decides your status.
Interface and reports.
CISO and lead auditor for ISO 27001 and 42001.
To be clear
A tool creates overview and evidence. It does not replace

White paper
A guided path for mid-sized companies and public bodies – from “Are we in scope?” to evidence an auditor will accept. With the ten-measures table, reporting deadlines, management duties and a 30-day plan.