Nispo · NIS2 Compliance Management Platform

Manage NIS2 controls, evidence, suppliers and remediation in one platform. Designed for organisations operating under the Italian NIS2 framework: Legislative Decree 138/2024 and the ACN basic security measures.

Nispo · Compliance status Dashboard
Nispo dashboard (real screen, demo data): compliance percentage, documents, controls, recent activity and control status by area (Govern, Identify, Protect, Detect, Respond, Recover)

Real platform screen, with demo data

What Nispo is

  • Nispo is an Italian NIS2 compliance management platform, designed for organisations subject to NIS2 in Italy.
  • Nispo helps organisations map the NIS2 requirements and the ACN basic security measures to their own controls, collect and keep evidence, track the remediation of gaps, manage policies and suppliers, and prepare the documentation for the management body and for inspections.
  • Nispo is compliance management software (GRC focused on Italian NIS2): it is not a security scanner, an antivirus/EDR or a SIEM.
  • Nispo complements Microsoft security products rather than replacing them: Microsoft 365, Defender, Intune and Entra ID enforce technical controls; Nispo manages NIS2 compliance — requirements, accountability, evidence, suppliers, remediation and reporting — and uses Microsoft 365 as a source of evidence.
  • Nispo is developed by NisPo S.r.l., an Italian company based in Milan, which also offers cybersecurity services delivered by specialists: penetration testing, vulnerability assessment and vCISO.

What it does

01 · Controls

ACN controls mapped

A control register structured on the ACN basic security measures, with code, area, owner and status for each requirement.

Platform and features →
02 · Evidence

Evidence linked to requirements

Every piece of proof with date, source and owner. Checks on Microsoft 365, Google Workspace, AWS and Google Cloud record their result automatically.

Evidence management →
03 · Gaps

Gaps and remediation

Gaps ranked by priority; each one becomes a task with an owner, a due date and closure verification.

NIS2 gap assessment →
04 · Documents

Policies and suppliers

Versioned, approved policy templates; a supplier register with criticality, questionnaires and deadlines.

Suppliers and supply chain →
05 · Reporting

Reporting and audit preparation

Dashboard by area, reports for the management body and PDF and CSV exports for inspectors.

NIS2 compliance reporting →
Regulatory framework
Directive (EU) 2022/2555Legislative Decree 138/2024ACN Determination 379907/2025National FrameworkCSIRT Italia

The problem

The ACN measures require documentation that is updated whenever something changes and easily accessible, plus verified technical controls. With checklists, shared folders and one-off tests, every inspection starts from scratch.

Where the time goes

Five sources of friction we find in almost every company at the first assessment.

  1. 01

    Scattered evidence

    Screenshots, exports and minutes spread across inboxes and shared folders. Nobody knows which version is the right one.

  2. 02

    Controls captured once a year

    A gap analysis describes the state of a single day. System configurations change every week.

  3. 03

    Suppliers outside the perimeter

    Supply chain security is mandatory, yet questionnaires sit in email attachments with no deadlines or outcomes.

  4. 04

    Accountability that is hard to prove

    Management bodies approve the measures and are liable for them. Without a register, proving due diligence takes weeks.

  5. 05

    Measures declared, never tested

    An approved policy doesn’t tell you whether an attacker can get in. Without technical testing, measures stay on paper.

Notifying a significant incident

Deadlines towards CSIRT Italia from the moment you become aware of the incident; the final report within one month.

Awareness Early warning Notification Final report T0 24 HOURS 72 HOURS 1 MONTH
Maximum fines
Essential
€10M or 2% of worldwide turnover
Important
€7M or 1.4% of worldwide turnover
Source: Directive (EU) 2022/2555 · Legislative Decree 138/2024

How it works

Nispo automatically checks what it can read from the integrated systems — Microsoft 365, Google Workspace, AWS, Google Cloud — and organises everything else: requirements, documents, suppliers and tasks. Where a hands-on check is needed, our specialists step in.

  1. 01

    Set up

    Set your category (important or essential), scope and owners. The control register follows the ACN basic security measures.

    Onboarding · ACN measures
  2. 02

    Connect and collect

    Connect Microsoft 365, Google Workspace, AWS or Google Cloud for automated checks; for everything else, upload documents and evidence starting from the templates.

    Integrations · Dated evidence
  3. 03

    Close the gaps

    Gaps become tasks with an owner and a due date. Where needed, penetration tests and vulnerability assessments check how effective the fixes are.

    Platform + specialists
  4. 04

    Prove and maintain

    Dashboard, board reports and exports for inspections, updated with every new check, document or task.

    Reporting · Continuous compliance

↻ The cycle starts again whenever your systems, suppliers or ACN rules change. The full workflow, step by step →

Integrations

Nispo connects to Microsoft 365 / Entra ID read-only and integrates with Google Workspace, AWS and Google Cloud: control checks and the inventory update on their own. CSIRT Italia bulletins arrive in the platform.

For other systems, such as on-premise servers and network devices, controls are handled with uploaded evidence. What each integration checks →

Nispo and Microsoft 365

With Microsoft 365 Business Premium or E3/E5 you already have tools that implement many technical requirements. Nispo does not replace them: it uses them as a source of evidence and manages the rest.

Microsoft tools

  • Entra ID: MFA and conditional access
  • Intune: device management and compliance
  • Defender: endpoint and email protection
  • Purview: data protection

Nispo

  • Register of ACN requirements with owners
  • Dated evidence, including from Microsoft 365 checks
  • Approved policies, suppliers, remediation
  • Reports for the management body and for inspections

Who does what, in detail →

NIS2 in Italy

In Italy the concrete requirements are those of Legislative Decree 138/2024 and the ACN determinations. Nispo starts from there.

NIS2 in Italy and ACN measures →

  • ACN basic security measures — Annex 1 for important entities, Annex 2 for essential entities, with National Framework codes.
  • Required documentation — lists, inventories, plans, policies, procedures and registers, kept up to date and easily accessible.
  • Suppliers — risk assessment, security requirements, contracts and periodic verification, as described by ACN.
  • ACN portal — the files for the categorisation of activities and services and for relevant NIS suppliers, generated from platform data.
  • CSIRT Italia — bulletins in the platform; incident notification within 24 hours, 72 hours and one month.

Who it is for

Nispo is designed for

  • Italian organisations subject to NIS2, classified as important or essential entities.
  • Companies with at least 50 employees and at least 20 IT assets: this is the entry point of the Nispo plan (a commercial choice, not the NIS2 applicability criterion).
  • Companies without a large in-house security or compliance team: IT is a handful of people and NIS2 comes on top of day-to-day work.
  • Companies that need to put evidence, policies and accountability in order before an inspection.
  • Companies with critical ICT suppliers to inventory and assess (cloud, business software, managed services).
  • Companies that want continuous visibility on control status, not a one-off assessment.
  • Companies on Microsoft 365, Google Workspace, AWS or Google Cloud, to benefit from automated checks (the platform also works with other systems, using uploaded evidence).

Nispo is not the right choice for

  • Organisations that need several frameworks (ISO/IEC 27001, SOC 2, DORA) in the same platform: Nispo focuses on NIS2.
  • Anyone looking for a technical security tool (EDR, SIEM, vulnerability scanner): Nispo manages compliance, it does not protect endpoints.
  • Organisations operating only outside Italy: the platform is built on the Italian transposition and the ACN measures.
  • Large groups with a mature GRC programme and enterprise tools already in place.
  • Organisations below the plan’s entry point: fewer than 50 employees or fewer than 20 IT assets.
  • Anyone looking for a certification: there is no NIS2 "seal" issued by a tool, and Nispo does not certify.

Services

When the platform finds a gap, our specialists help you verify it and close it. The results flow back into the register as actions and audit evidence.

Featured · Art. 21.2(f) NIS2

Penetration testing

NIS2 requires you to assess how effective your security measures are. A penetration test does that in the most direct way: our specialists try to break in, as an attacker would, and document what works and why.

  • External perimeter, internal network and web applications
  • Active Directory and Entra ID, all the way to domain admin
  • Technical report and executive summary
  • Findings imported into the Nispo register as actions
Penetration test report 5 findings
FindingSeverityIn the register
Admin panel exposed with default credentialsExternal perimeter Critical In remediation · M. Ferri
SMB signing not required on file serversInternal network High Assigned · IT
Service account with Domain Admin privilegesActive Directory High Assigned · IT
TLS 1.0 enabled on the customer portalExternal perimeter Medium Closed · retest passed
User enumeration on the VPNExternal perimeter Medium Scheduled
Nispo services 5 actions with owner and due date

Services are also available without the platform. Request an assessment → All services →

A 30-minute demo on your Microsoft 365 tenant: we show you your real controls, evidence and gaps, and where to start.