As of Oct 2026Compliance tool for mid-sized companies and public bodies

One question. One click. One clear status.

NIS2 and ISO 27001 – guided, clear and free of spreadsheet chaos. Plus the EU AI Act, ISO 42001 and the Cyber Resilience Act.

  • NIS2
  • ISO 27001
  • EU AI Act
  • ISO 42001
  • CRA

910assessable requirements in five frameworks

910 → 227

Assess once. Use many times.

Many requirements in NIS2, ISO 27001, ISO 42001, the AI Act and the CRA mean the same thing – access control, incident handling or supplier assessment, for example.

227 shared control points connect 454 equivalent requirements across framework boundaries.

One answer counts automatically in every framework that uses the same control point. If it applies to several frameworks, the weakest implementation prevails in case of doubt.

227 → 1

One clear status.

Overall status, trend and exactly the points that need attention now – overdue measures, due reports, open obligations. Made for management.

59%

Weighted implementation status per framework in the demo tenant

NIS260 %
ISO/IEC 2700162 %
ISO/IEC 4200160 %
EU AI Act46 %

Demo tenant “Nordwerk Energie GmbH”, fictitious data.

The path

Six phases in the PDCA cycle.

UniqSuite guides you through six phases from scope to audit, assesses each requirement only once and produces the reports management and auditors expect.

Screenshots: demo tenant “Nordwerk Energie GmbH” with fictitious data.

01Plan

Scope & Context

Company and sector, package, size – ready in three questions. Plus people and the frameworks that apply to you.

Result: Scope report

Scope & Context – screenshot
Screenshots: demo tenant “Nordwerk Energie GmbH” with fictitious data.
02Plan

Inventory

Services, assets and their dependencies in one place – the foundation for gap analysis and risks.

Result: Inventory

Inventory – screenshot
Screenshots: demo tenant “Nordwerk Energie GmbH” with fictitious data.
03Plan

Gap Analysis

One requirement per card, mandatory requirements first. Answer with one click; “not applicable” only with a justification.

Result: Implementation status per framework

Gap Analysis – screenshot
Screenshots: demo tenant “Nordwerk Energie GmbH” with fictitious data.
04Plan

Risk Analysis

Derive risks from gaps, assess them and treat them.

Result: Risk report (PDF, Word, Excel)

Risk Analysis – screenshot
Screenshots: demo tenant “Nordwerk Energie GmbH” with fictitious data.
05Do

Plan & Implementation

A Statement of Applicability and one list of measures with owners, deadlines and status. Every step forward flows automatically into the dashboard and reports.

Result: SoA, implementation and board report

Plan & Implementation – screenshot
Screenshots: demo tenant “Nordwerk Energie GmbH” with fictitious data.
06Check · Act

Audit & CI

Findings, corrective actions and their follow-up – so the cycle closes.

Result: Audit report

Audit & CI – screenshot
Screenshots: demo tenant “Nordwerk Energie GmbH” with fictitious data.

How it feels

Everything that matters. Nothing that distracts.

Gap analysis

One question per card

Mandatory requirements first. To go deeper, switch to the detail view with maturity and evidence.

Gap analysis – screenshot, demo tenant

Management dashboard

Your status on one page

Overall status, trend and the points that need attention now.

Management dashboard – screenshot, demo tenant

Incident management

Deadlines that keep running

Record an incident once. UniqSuite derives the reporting duties of your frameworks and starts the deadline timers.

Incident management – screenshot, demo tenant

Plan & implementation

Who does what by when

One list of measures with owners, deadlines and status.

Plan & implementation – screenshot, demo tenant

Supplier check

Your supply chain in view

Criticality, controls, risk score and review cycle for each supplier.

Supplier check – screenshot, demo tenant

Policies

Policies ready for approval

Templates linked to the requirements.

Policies – screenshot, demo tenant

AI governance

AI under control

An AI system register, risk classification under the EU AI Act and the mandatory documents for each role and class.

AI governance – screenshot, demo tenant

Statement of Applicability, board, risk and implementation reports as PDF, Word or Excel – at the push of a button.

Why now

The obligations already apply.

Germany’s NIS2 Implementation Act has applied since 6 December 2025 – with no general transition period. At the same time, the EU AI Act and Cyber Resilience Act deadlines are kicking in.

Reporting significant security incidents (Section 32 BSIG)

24 hEarly warningfrom awareness

72 hNotification with initial assessmentfrom awareness

1 monthFinal reportafter the notification

Record an incident once – UniqSuite derives the reporting duties and starts the deadline timers.

Timeline 2025–2028

  1. NIS2UmsuCG in force

    New BSI Act with obligations for essential and important entities.

  2. Registration deadline expired

    Three months after entry into force (Section 33 BSIG). Latecomers should register without delay.

  1. AI Act: transparency obligations

    Art. 50 applies. Prohibitions and AI literacy have applied since February 2025.

  2. CRA: reporting obligations

    Manufacturers report actively exploited vulnerabilities and severe incidents (Art. 14).

  1. AI Act: high-risk AI (Annex III)

    Postponed by Regulation (EU) 2026/1744.

  2. CRA applies in full

    Products with digital elements only with CRA-compliant CE marking.

  1. AI Act: high-risk AI in products

    Obligations for high-risk AI under Annex I.

Source: white paper “Implementing NIS2 and ISO 27001 pragmatically”, as of October 2026.

One tool, five frameworks

Today NIS2 and ISO 27001. Tomorrow AI and products.

Assessable requirements per catalogue. Choose a framework – the quick check begins.

Quick check

Where do you stand? In two minutes.

Eleven to thirteen short questions per framework. Answer Yes, Partly or No – as honestly as you can.

Your answers never leave your browser. No transfer, no storage, no tracking.

Choose a framework

Trust

Secure and traceable.

Tenant separation in the database

Row-level access rules keep every organisation’s data apart.

Two-factor sign-in

Can be made mandatory for administrators.

Daily backups

With 14-day retention.

Rule-based, not a black box

Assessments and metrics follow fixed, traceable rules – no AI decides your status.

German and English

Interface and reports.

Built by practitioners

CISO and lead auditor for ISO 27001 and 42001.

To be clear

What UniqSuite does not replace

A tool creates overview and evidence. It does not replace

  • the legal assessment of whether you are in scope,
  • management’s decisions and accountability,
  • the technical security measures themselves,
  • an independent audit or certification.
Implementing NIS2 and ISO 27001 pragmatically

White paper

Implementing NIS2 and ISO 27001 pragmatically

A guided path for mid-sized companies and public bodies – from “Are we in scope?” to evidence an auditor will accept. With the ten-measures table, reporting deadlines, management duties and a 30-day plan.

14 pages · PDF · as of October 2026

See your status.

Request access or book a short demo with your own questions.