Quanovio

NIS2 — the EU's new security lawIn force now

A new EU law says you must prove you are watching for security problems.

Not just that you are watching — that you can show it, months later, to someone who asks. Quanovio checks the systems you already use, every day, and writes down what it found in language you can hand to an inspector.

Schematic: several sources feed one unit, which sends two outputs onward. One path is marked in red.

The short versionFour questions

If you only read one part of this page.

Does this apply to me?

If you are a medium or large organisation in energy, transport, health, water, food, manufacturing, waste, post, chemicals, digital services, research or public administration, almost certainly yes. The law is called NIS2, it applies across all 27 EU countries, and it reached thousands of organisations that had never been regulated on security before. Many of them still do not know.

What happens if I cannot prove it?

Fines reach €10 million or 2% of worldwide annual turnover, whichever is larger. Directors can be held personally responsible, and regulators can suspend a manager from their duties. In practice the first thing that happens is simpler: a customer, an insurer or a bank asks for your evidence, and you do not have any.

What do I actually get?

One report, every morning. It says what is wrong, what got fixed, and what came back after being fixed. Each line is tied to the numbered part of the law it answers, so when someone asks for proof you send the report instead of starting a project.

What do I still have to do myself?

Fix the things it finds. We never touch your systems — we cannot, and that is deliberate. We tell you what is wrong and in what order to deal with it; your own people or your IT supplier do the work, and the next morning's report says whether it worked.

The idea the whole thing rests onTwo different jobs

Being secure and proving it are two different jobs.

Think of the fire extinguishers in your building. Having them is not enough. Someone signs a sheet every month to say they were checked, and that sheet is what an inspector asks for. Security now works the same way. The law does not only ask whether you are watching — it asks you to produce the record. Most organisations are doing far more than they can show.

This is what arrives each morning.

One page. Below is a real example, shortened. The number on the left is the part of the law each line answers; you do not need to understand it, but the person who inspects you will.

Compliance report · 19 September 2026 3 changes since previous collection
11.2 Recurrence

Anonymous sharing link active on restricted content

Previously remediated on 2 September. A sharing link created in March remains active on Budget-2027.xlsx, which was restricted on 28 August. The content is retrievable by any holder of the URL without authentication.

Remediation is performed by your administrators. The next collection verifies the result.

11.7 4 privileged accounts without multi-factor authentication Opened
6.x 3 critical vulnerabilities remediated and verified Verified closed
770security checks tied to the numbered points of the law
89of them that no other compliance product had mapped
0existing checks for two-step sign-in, the most common gap of all

Scope is stated explicitly.

Approximately one third of the numbered controls in CIR (EU) 2024/2690 are evidenced by telemetry. The remainder — risk methodology, supply chain assessment, cryptographic policy, training, physical security — are documentary and are reported as open, with the evidence an assessor will request. Coverage claims that exceed what a monitoring system can observe do not survive an audit.

Data exposureControls 11.2, 12.x

Who outside your organisation can open your files.

Every file and folder reachable from outside, sorted by how far it reaches. The worst kind is a link that needs no sign-in at all: anyone who has the address can open the file, nobody is recorded as having done so, and it keeps working even after you think you have locked the file down.

TENANTFinanceHRBoard papersProject archiveShared driveand all other locationsEXTERNAL ACCESSNamed identitiesoutside the tenant, enumerable148“Everyone” groupsinherited across sites31Unauthenticated linksno identity, no audit trail, no expiry639 resolve to restricted content

Control coverage

4,423 rules examined · 19 Sep 2026
RefControlDetectionsEvidenced
11.6Authentication293Yes
11.2Management of access rights127Yes
3.2Monitoring and logging119Yes
3.4Event assessment and classification92Yes
6.xVulnerability, configuration and change67Yes
11.3Privileged and administration accounts30Partial
11.5Identification and identity lifecycle21Yes
11.7Multi-factor authentication0Requires an identity source
01

Read-only access

Connectors request read scopes exclusively. A credential returned with write permission is rejected at connection time rather than retained.

02

Self-hosted or managed

Identical software, deployed in your own network or operated on your behalf within the European Union. Self-hosted deployments transmit nothing externally.

03

Remediation verification

Each finding includes a remediation plan executed by your administrators. Subsequent collections record the outcome as closed, unresolved, or recurring.

Find out where you stand.

Tell us what your organisation runs — five lines is enough — and we will tell you which parts of the law you could prove today and which you could not. Written, free, and no call required.

See your coverage