NIS2 servicesPL

Monitoring, incidents and evidence for NIS2

Wazuh + OpenProject at a fixed monthly subscription, hosted on our servers in Poland.

8 / 10
Coverage of Article 21 measures
Management gets evidence of oversight and reduced personal risk.
IT knows what to do and by when.
Auditors get a record of actions.
Book a free assessment
What you get

Four things an inspection asks for

01

System monitoring

Wazuh collects logs from servers, workstations and the cloud, detecting events and configuration issues.

02

An alert handling process

Every alert becomes an OpenProject task with an owner and a deadline.

03

Deadlines and accountability

See who is responsible and what is overdue. The legislation requires management to exercise this oversight.

04

An inspection report

A record of actions and decisions ready for audits and CSIRT notifications.

NIS2 explained

NIS2 makes management accountable for cybersecurity

A policy on paper is not enough. Inspectors ask for evidence that systems and incident handling work. Security management system implementation: by 3 April 2027. Entry in the register of entities: by 3 October 2026.

What you need

Monitoring, incident response, accountable people, deadlines, reports and a record of what happened, who acted and when.

What is at stake

Fines of up to EUR 10 million or 2% of turnover for essential entities, up to EUR 7 million or 1.4% for important entities, and personal accountability for management.

How we work

We collect alerts, assign tasks and maintain an audit trail of actions.

NIS2 covers 18 economic sectors. As a general rule, thresholds start at approximately 50 employees and EUR 10 million in turnover; IT and security service providers may be covered from approximately 10 employees.

Risk

The most common problem is missing evidence

Saying “we have procedures” is not enough. Inspectors ask what was done and when.

01

Alert

The system detects an event.

24 hours — early warning
02

Response

A task gets an owner and a deadline.

72 hours — incident notification
03

Evidence

Actions and decisions are recorded.

1 month — final report

Wazuh + OpenProject tracks these three deadlines and records what was done.

The solution

A simple workflow in Wazuh + OpenProject

From detecting an event to a record that stands up to an audit.

Detection

Wazuh collects logs and detects issues.

Task

OpenProject creates a task, an owner and a deadline.

Action

The team responds and decisions are recorded.

Evidence

A report ready for audits and CSIRT notifications.

Wazuh (GPLv2) and OpenProject (GPLv3) have no licence fees. Billing is fixed monthly, regardless of log volume.

Mapping

Which tool covers each Article 21 requirement

Measure letters refer to Directive (EU) 2022/2555.

abc def ghij
01Incident handling — (b)Wazuh: log analysis + Active Response
02Vulnerabilities — (e)Wazuh: Vulnerability Detector (CVE)
03Risk and cryptography — (a), (h)Wazuh: SCA — configuration and TLS auditing
04Access control — (i)Wazuh: FIM who-data — who changed what
05Deadlines, tasks and evidenceOpenProject: task owners and history

Together, 8 of the 10 Article 21 measures. Supply chain management and training remain the client’s processes; we provide the technical data to support them.

What we show auditors

The report answers five questions

One report that management, IT and inspectors can understand.

01What happened?alert, time, system
02Who was responsible?task owner
03What was done?record of actions and decisions
04What is the status?open, in progress, closed
05How do we prevent a recurrence?remediation, checks, lessons learned

These five answers are often missing during an audit. Our report is built from task histories, without collecting data manually.

Implementation

We start with a pilot

First we deploy the core on a few systems, then add more sources.

1. Pilot

A few systems, basic alerts and the first report.

2. Fine-tuning

Alert thresholds, responsibilities, deadlines and reports.

3. Expansion

More data sources and complete NIS2 documentation.

The pilot shows real progress, without committing to a full rollout or investing in hardware on your side.

Service model

We run the service; you own the data

The solution runs on NIS2SOFT servers in Poland. Logs stay in the country. We take care of maintenance, updates and rule tuning.

Subscription fixed monthly cost Servers in Poland logs stay in the country No hardware required on the client’s side Managed maintenance and tuning by NIS2SOFT
Next steps

The technical layer of NIS2 as an ongoing NIS2SOFT service

The next step is a free assessment of your entity and a pilot plan.

Book a call with NIS2SOFT
info@nis2soft.com  ·  www.nis2soft.com