26 July 2026What is NIS2, and who does it apply to?

First product · in development

Compliance, on the layer where your data comes together.

The first product we are releasing on our connecting layer: one European control set covering every national obligation. Novaro Compliance determines which laws and standards apply to your organisation, per EU country, and translates them into concrete controls, tasks, evidence and a dashboard the board understands.

First NIS2, ISO 27001 and the GDPR. Then DORA and the AI Act. SOC 2 and NIST we are exploring.

Why compliance is the first product

Compliance has become a moving target. NIS2, DORA, ISO 27001, GDPR and the AI Act each set their own requirements, and every EU country implements them differently, with its own reporting deadlines, regulators and sanction ceilings.

Most organisations fight this with spreadsheets, scattered documents and a yearly audit panic. Existing tooling is American, expensive, or treats every framework as a separate project.

We are building it the other way around: describe your organisation once, maintain one control set. The platform continuously translates that into every standard and every country that applies to you.

That compliance comes first is a choice, not an order things happened to fall into. A standard forces exactly what the layer has to be able to do anyway: establish, for every value, where it came from and when. What holds up here in front of an auditor holds up afterwards under everything else that comes to sit on the same layer.

How it works

  1. 01

    Profile

    Describe your organisation once: country, sector, size, services, suppliers and systems.

  2. 02

    Applicability

    The platform automatically determines which legislation and standards apply, including entity class and national specifics.

  3. 03

    Baseline

    A maturity scan per control (0–5) shows where you stand, and what an auditor would see.

  4. 04

    Roadmap & tasks

    Open controls become tasks with owners and deadlines, prioritised by risk and fine exposure.

  5. 05

    Demonstrably compliant

    Evidence collects itself in the evidence library; audit readiness visibly grows. Continuously, not once a year.

What makes the platform unique

Automatic applicability

Country, sector, size and services automatically determine which laws and regulations apply, including each EU country's national specifics.

One control, every framework

Cross-framework mapping: an implemented measure immediately counts towards every standard it appears in.

From baseline to audit-ready

Maturity scan per control, an automatic roadmap with owners and deadlines, and audit readiness you can watch grow.

Evidence in one place

An evidence library with connections to your environment (Microsoft 365, Azure, AWS and more). Evidence collects itself.

Illustration from the product: the same security measure, now under the GDPR. The text of the standard with the FACT stamp, what has to happen, who owns it and which evidence an auditor accepts.

The standardFACT

GDPR, article 32(1) · regulation (EU) 2016/679

Appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including the ability to ensure the ongoing confidentiality, integrity and availability of processing systems.

What you do
Choose measures on the basis of that same risk analysis
Who
Role: information security owner
Evidence that counts
That same adopted analysis, here linked to the processing activities
The same measure as under NIS2, now seen from the GDPR

One platform, a tailored view for every role

Board

Compliance score, fine exposure and heatmap, in board language.

Compliance officer

Controls, policies, audits and improvement actions in one workflow.

CISO

Security controls, risks and incidents linked to the standards.

IT manager

Assets, patching, backups and monitoring as living evidence.

HR & procurement

Training, screening and supplier assessments on schedule.

Auditor

Read-only access to evidence and reports: audits without folder chaos.

Frequently asked questions about the platform

What is Novaro Compliance?

The first product we are releasing on our connecting layer. Novaro Compliance automatically determines which laws and regulations apply to your organisation, per EU country, and translates that into concrete controls, tasks and evidence. One implemented measure immediately counts towards every standard it appears in. The platform is in active development.

Who is it for?

Initially for Dutch and European B2B organisations of roughly 20 to 250 employees, with role-based views for the board, compliance officers, CISOs, IT managers, HR/procurement and auditors.

Which laws and standards does it support?

NIS2, DORA, ISO 27001, the GDPR and the AI Act are on the roadmap as fully mapped frameworks; the first release focuses on NIS2, ISO 27001 and the GDPR.

Can an auditor get access to the platform too?

Yes. Auditors get a read-only role with access to evidence and reports, so audits happen without folder chaos.

Where is my data stored, and how is it secured?

The environment runs on European infrastructure (an EU-based VPS). Every client organisation is separated from the others at the database level (row-level security per tenant). Login goes through Novaro's own identity environment, with encrypted connections and secured sessions, and no third-party social login.

Does Novaro staff have access to my data?

Only on explicit request, temporarily, with a reason and an end date, and always logged under the name of the employee involved. No permanent or unlogged access.

Can I use the platform already?

It is being built with a select group of launching partners. Interested as a future user, auditor or partner? Get in touch.

In development, with launching partners.

The platform is in active development and is being built with a select group of launching partners: organisations that help shape the workflows and go live first. Interested as a future user, auditor or partner?

Become a launching partner

No obligations: just a front-row seat at launch and influence on the roadmap.