Built and hosted in the European Union

The European platform for cybersecurity compliance.

NIS2, DORA, ISO 27001, NIST CSF 2.0 and CIS Controls in one workspace. Trust, made provable.

Built by practitioners: 20+ years running GRC programmes, audits and authority reports — on the other side of the table.

Compliance overview — live workspace, demo data.
FIG. 01Compliance overview — live workspace, demo data.
Your data never leaves the EU
GDPR-native
Encrypted at rest and in transit
Tamper-evident audit trail
02 — NIS2

NIS2 is not one regulation.
It's 27 national laws.

Every transposition builds on the same directive floor: the obligations of Art. 21, the classification criteria of Annexes I and II, and incident deadlines that are statutory everywhere — 24 hours, 72 hours, one month. Cautera tracks that floor.

02.1Annex I · II
Applicability wizard
A guided classification — sector, sub-sector and size thresholds under the directive. PDF report included.
02.2Art. 21
Obligations catalog
Every obligation mapped article by article. Link controls and evidence; score compliance per obligation.
02.3Art. 23
Incident workflow
Deadlines tracked from the moment of detection. Authority-ready reporting templates at every stage.
02.4DL 125/2025
Portugal: transposition included
Where a transposition goes deeper, so does Cautera. Portugal's DL 125/2025 is built in — CNCS registration checklist and CSIRT-ready incident reports.
Incident reporting — statutory deadlines · Art. 23
T+24:00
Early warning
Initial notification to the competent authority.
T+72:00
Incident notification
Detailed assessment including severity and impact.
T+1 MO
Final report
Root cause analysis and remediation measures, within one month of the incident notification.

When an incident hits, the clock is law. Cautera runs the clock. — See the NIS2 module

03 — Frameworks

Implement once.
Satisfy every framework.

Start from any framework. Map a single control implementation to every requirement it satisfies — detected automatically, verified by you.

NIS2 ART. 21(2)(d)ISO/IEC 27001 A.5.19NIST CSF GV.SCCIS CONTROL 15
See framework coverage
03.1AI Act
More than NIS2: the EU AI Act, tracked the same way
Inventory your AI systems and risk-classify them under the EU AI Act — Regulation (EU) 2024/1689 — with obligations tracked per system.
04 — AI

AI that shows its work.

Sixteen AI capabilities embedded across the platform. Three examples of what they return.

04.1Evidence
Classify evidence
Pen test report uploaded → proposed links to 5 controls across NIS2 and ISO 27001, with the mapping shown for review.
04.2Questionnaires
Answer the questionnaire
An inbound security questionnaire answered from your policies, controls and approved answer library — every draft held for your review.
04.3Remediation
Plan remediation
A 90-day NIS2 plan with 23 tasks across 4 workstreams, each with an owner and an effort estimate.
EU processing · no training on your data · every AI action loggedSee all sixteen capabilities
05 — Who built it

Built by the people who used to do this by hand.

Over 20 years leading GRC programmes across healthcare, financial services and utilities. Audits led, incidents reported to authorities, hundreds of vendors assessed. Cautera is the platform we wished we had.

About the team
06 — Where Cautera differs

Structural differences, not feature checkboxes.

06.1Jurisdiction
European-native
An EU company under EU jurisdiction — data, AI processing, support and the team, all in Europe. Not an EU region of a US platform.
06.2Art. 21 · 23
NIS2 is a module, not a mapping
An obligations catalog and a statutory incident clock — not a crosswalk bolted onto SOC 2.
06.35 frameworks
Multi-framework from day one
Built for NIS2, DORA, ISO 27001, NIST CSF and CIS together — not single-framework DNA retrofitted.
06.4Deployment
Days to deploy, not quarters
A SaaS workspace your team runs without a consulting engagement — with automated evidence collection from AWS, GCP, GitHub and Okta.

See Cautera on your frameworks.

A working session on your actual obligations — not a generic product tour.