NIS2 meets your reality - not your binders
The GRC module (Governance, Risk & Compliance) of COD (Central Operations Dashboard) implements the requirements of the NIS2 directive (the EU directive on network and information security) as a management system on living data, with risk management, asset transparency and complete auditability.
NIS2 demands what most compliance tools only claim: risk management that is actually practiced, complete asset transparency and gapless auditability. COD, with its GRC module, closes the gap between what is running and what is documented, because your compliance works on the same living data as your operations.
Why classic GRC tools fail at NIS2
Most GRC tools act as if your infrastructure stood still: filled in once, half-heartedly maintained, with a status from months ago. But NIS2 does not ask about your last audit - it asks about your current risk.
- Static asset lists go out of date faster than you can maintain them
- Risk assessments without a live link to reality are worthless in an emergency
- Manual bridges between operations and documentation cost time and create gaps
What NIS2 requires - and how COD solves it
NIS2 places concrete requirements on risk management, transparency and evidence. COD maps every one of them onto a shared, living data basis.
Note: COD does not replace legal advice. We provide the tool that makes your NIS2 measures technically implementable and demonstrable.
- Asset transparency: COD-Network automatically detects every IP-addressable device - from IT through network to OT - as a foundation instead of manual lists
- Risk management: asset-based, versioned risk assessment with BSI 200-3 defaults - on the concrete asset including live status, not on a “component in general”
- Auditability: a tamper-proof, append-only audit log records every change - who, when, what, where, why
- Measures & policies: versioned policies, linked directly to controls, with a workflow from draft to archived
The GRC module: multiple standards, one system
Whether information security, quality or business continuity - the GRC module covers the leading standards on a shared data basis, without duplicate data maintenance.
- ISO 27001 - information security including all 93 Annex A controls
- ISO 9001 - quality management
- ISO 22301 - business continuity management
- BSI 200-3 - risk-based methodology per IT-Grundschutz
Manage controls - not just check them off
NIS2 maturity means knowing at any time where you stand. The GRC module makes your implementation status visible - per control, not just as a checkmark.
- All 93 ISO 27001 Annex A controls included, grouped into four themes
- Per control: applicability, implementation status (implemented / partial / planned / not implemented), notes and linked policies
- Progress shown visually in the dashboard - readiness at a glance
On-premises - KRITIS-ready, with current content
In the KRITIS environment in particular, “no data in the cloud” is often a requirement, not a preference. COD runs fully on-premises and still keeps its content up to date.
- Fully deployable on-premises - full control of your data
- Compliance data in a cleanly separated, dedicated PostgreSQL database
- Provide template updates (new ISO controls, an updated BSI catalog) centrally and roll them in under control
Frequently asked questions
Request a NIS2 readiness demo
We'll show you COD and the GRC module hands-on in your own environment, with no sales pressure and no commitment. Alternatively, download the GRC datasheet with all the facts on standards, controls and the audit log in compact form as a PDF.