Skip to Content
  •  +49 (861) 88 00 32 00
COD powered by extocode GmbH
  • 0
  • Sign in
  • Contact Us
  • Home
  • COD Overview
    Platform
    OverviewFeaturesIntegrationsPricing
    Operations & Network
    MonitoringNetworkNetwork Access Control (NAC)Captive PortalFirewall
    Security & Resilience
    Governance, Risk & ComplianceVulnerabilities (VAS)BackupHypervisorOTPAutomation
    Solutions & More
    NIS2 & CompliancecodPassLive demoReferencesDownloadsFAQ
  • Pricing
  • News
  • FAQ
  • About us
    • About us
    • Careers
    • References
  • Contact
COD powered by extocode GmbH
  • 0
    • Home
    • COD Overview
    • Pricing
    • News
    • FAQ
    • About us
      • About us
      • Careers
      • References
    • Contact
  •  +49 (861) 88 00 32 00
  • Sign in
  • Contact Us

NIS2 meets your reality - not your binders

The GRC module (Governance, Risk & Compliance) of COD (Central Operations Dashboard) implements the requirements of the NIS2 directive (the EU directive on network and information security) as a management system on living data, with risk management, asset transparency and complete auditability.

NIS2 demands what most compliance tools only claim: risk management that is actually practiced, complete asset transparency and gapless auditability. COD, with its GRC module, closes the gap between what is running and what is documented, because your compliance works on the same living data as your operations.

Request a live demoDownload datasheet

NIS2 meets your reality - not your binders

Why classic GRC tools fail at NIS2

Most GRC tools act as if your infrastructure stood still: filled in once, half-heartedly maintained, with a status from months ago. But NIS2 does not ask about your last audit - it asks about your current risk.

  • Static asset lists go out of date faster than you can maintain them
  • Risk assessments without a live link to reality are worthless in an emergency
  • Manual bridges between operations and documentation cost time and create gaps

What NIS2 requires - and how COD solves it

NIS2 places concrete requirements on risk management, transparency and evidence. COD maps every one of them onto a shared, living data basis.

Note: COD does not replace legal advice. We provide the tool that makes your NIS2 measures technically implementable and demonstrable.

  • Asset transparency: COD-Network automatically detects every IP-addressable device - from IT through network to OT - as a foundation instead of manual lists
  • Risk management: asset-based, versioned risk assessment with BSI 200-3 defaults - on the concrete asset including live status, not on a “component in general”
  • Auditability: a tamper-proof, append-only audit log records every change - who, when, what, where, why
  • Measures & policies: versioned policies, linked directly to controls, with a workflow from draft to archived

The GRC module: multiple standards, one system

Whether information security, quality or business continuity - the GRC module covers the leading standards on a shared data basis, without duplicate data maintenance.

  • ISO 27001 - information security including all 93 Annex A controls
  • ISO 9001 - quality management
  • ISO 22301 - business continuity management
  • BSI 200-3 - risk-based methodology per IT-Grundschutz

Manage controls - not just check them off

NIS2 maturity means knowing at any time where you stand. The GRC module makes your implementation status visible - per control, not just as a checkmark.

  • All 93 ISO 27001 Annex A controls included, grouped into four themes
  • Per control: applicability, implementation status (implemented / partial / planned / not implemented), notes and linked policies
  • Progress shown visually in the dashboard - readiness at a glance

On-premises - KRITIS-ready, with current content

In the KRITIS environment in particular, “no data in the cloud” is often a requirement, not a preference. COD runs fully on-premises and still keeps its content up to date.

  • Fully deployable on-premises - full control of your data
  • Compliance data in a cleanly separated, dedicated PostgreSQL database
  • Provide template updates (new ISO controls, an updated BSI catalog) centrally and roll them in under control

Frequently asked questions

Does COD make my organization NIS2-compliant?

COD provides the technical building blocks that NIS2 requires - asset transparency, asset-based risk management and complete auditability. The specific legal assessment of your obligations remains with you or your legal counsel; COD does not replace legal advice.

Do we have to put data in the cloud?

No. COD is fully deployable on-premises and KRITIS-ready. Compliance data resides in a dedicated PostgreSQL database under your full control.

Why “on living data”?

The GRC module works on the same assets that COD-Network automatically detects and maintains. Your risk assessment refers to the concrete asset including live status - not to an outdated list.

See all questions in the FAQ →

Request a NIS2 readiness demo

We'll show you COD and the GRC module hands-on in your own environment, with no sales pressure and no commitment. Alternatively, download the GRC datasheet with all the facts on standards, controls and the audit log in compact form as a PDF.

Request a live demoDownload datasheet

Folgen Sie uns
​
  • COD Overview
  • Features
  • Pricing
  • Integrations
  • NIS2
  • codPass
  • References
  • Downloads
  • FAQ
  • Contact

Kotzinger Straße 21 • 83278 Traunstein • Deutschland

  • ​+49 (861) 88 00 32 00
  • ​info@extoco.de
Datenschutz Impressum ​
Copyright © extocode GmbH
English (US) Français Deutsch Español Türkçe

We use cookies to provide you a better user experience on this website. Privacy Policy

Decline Accept